Back to skill

Security audit

Slack Toolkit Free

Security checks for vulnerabilities and agentic risk

Overview

This Slack skill is purpose-aligned, but it should be reviewed because it can read, post, edit, delete, and pin workspace messages while using broad scopes and mutable install commands without strong guardrails.

Install only after reviewing the actual package source or pinning trusted versions, give the Slack bot the minimum scopes needed, keep the token isolated, and require explicit user confirmation before sending, editing, deleting, or pinning messages.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:135
Finding

Execution of an Unpinned npm Installer from a Mutable Release Channel

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:135
Vulnerability Type: Unpinned third-party installer and mutable dependency resolution
Risk Level: High

Vulnerable Code Snippet:

bash
npx skillhub@latest install slack-toolkit-free

Technical Analysis

The documented installation procedure uses npx to download and execute the mutable latest release of the external skillhub npm package. No exact version, integrity hash, lockfile, or provenance verification is specified.

The effective code executed by this command can therefore change after the Skill has been reviewed. The project contains only SKILL.md and does not include the installer or Slack toolkit implementation, so the behavior of the downloaded code cannot be verified through this repository.

This creates a supply-chain risk if the package publisher account, registry package, transitive dependency, or release process is compromised. npm package lifecycle scripts or the invoked CLI can execute code under the privileges of the user running the installation.

Attack Path

  1. An attacker compromises the skillhub package, its publisher account, a transitive dependency, or the mutable release distributed as latest.
  2. A user follows the documented installation instructions.
  3. npx resolves and downloads the attacker-controlled release.
  4. npm executes applicable lifecycle scripts and the downloaded CLI with the invoking user's privileges.
  5. Malicious code can access files and environment variables available to that user.
  6. If SLACK_BOT_TOKEN is present in the environment or a readable .env file, the code may steal it and use its granted Slack permissions.

Impact Assessment

Successful exploitation could result in arbitrary code execution under the local account that runs the installation command. The accessible scope may include:

  • Files readable or writable by the invoking user.
  • Environment variables an ...[truncated 570 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace @latest with an exact, reviewed version, for example skillhub@X.Y.Z.
  • Verify the selected package version's provenance, publisher, signatures, and registry metadata before documenting it.
  • Use integrity verification or an approved lockfile where the installation workflow supports it.
  • Avoid automatically executing npm lifecycle scripts unless they are required and have been reviewed.
  • Prefer installing from a controlled internal registry or an immutable, verified artifact.
  • Include the auditable implementation in the project or link to an immutable source revision so behavior can be reviewed.
  • Run installation in a restricted environment without Slack tokens or unrelated credentials.
  • Configure Slack tokens according to least privilege and rotate them immediately if installer compromise is suspected.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:321
Finding

Unpinned Python Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:321
Vulnerability Type: Unpinned third-party Python dependency
Risk Level: Medium

Vulnerable Code Snippet:

text
| requests | Python library | Recommended | `pip install requests` |

Technical Analysis

The dependency instructions install requests without an exact version or integrity hash. Consequently, installation resolves whichever compatible release is available from the configured Python package index at execution time. This prevents reproducible dependency resolution and allows the installed code to change after the Skill has been audited.

Although requests is a well-known package and is identified only as recommended, an unpinned installation remains exposed to registry, publisher, package-index configuration, and dependency-chain compromise. The command also does not constrain the package source or verify artifact hashes.

Attack Path

  1. An attacker compromises a relevant package release, dependency, publisher account, or package index used by the target environment.
  2. Alternatively, the target environment is configured to use an attacker-controlled or untrusted Python package index.
  3. A user follows the documented pip install requests instruction.
  4. pip resolves and installs the compromised or unexpectedly changed package version.
  5. Malicious package code executes when imported or otherwise invoked by the Slack integration.
  6. The code can access the process environment, local files, network, and any Slack credentials available to the running process.

Impact Assessment

If a malicious package is resolved and subsequently loaded, it may execute code with the privileges of the Python process. Potentially exposed resources include local application data, environment variables, and SLACK_BOT_TOKEN. Theft of that token could permit operations allowed by its Slack scopes.

The dependency is described as recommended r ...[truncated 225 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin requests to an exact version that has been reviewed and tested.
  • Record transitive dependencies in a lockfile generated by a trusted dependency-management tool.
  • Require package hashes, such as through a hash-locked requirements file and pip --require-hashes.
  • Explicitly use an approved package index over TLS and prevent fallback to untrusted indexes.
  • Scan pinned packages for known vulnerabilities and update them through a controlled review process.
  • Install dependencies in an isolated virtual environment with minimal filesystem and credential access.
  • Do not expose SLACK_BOT_TOKEN during dependency installation, and grant the token only the Slack scopes needed for enabled features.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

配置Bot Token

bash
# 在 .env 文件中配置
SLACK_BOT_TOKEN=xoxb-your-bot-token-here

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises high-impact operations—sending, editing, deleting, and reading Slack messages—without clear safety guidance, consent requirements, or warnings about workspace impact and sensitive data exposure. In this context, omission of such controls is dangerous because the skill interfaces with live organizational communication channels using a bot token.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are overly broad, including generic communication and integration needs, which can cause the agent to invoke this skill for ordinary conversation tasks. Because the skill can send, edit, delete, and read Slack messages, accidental invocation may lead to unintended actions against real workspace data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The installation command uses npx skillhub@latest install slack-toolkit-free, which pulls and executes the latest remote package without pinning an exact version. This creates a supply-chain risk: if the upstream package is compromised or changed unexpectedly, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

整个技能描述、使用说明和示例说明均以中文呈现,且未说明这是面向中文用户的可选本地化版本,也未提供用户语言选择。按照语言/locale 政策,若技能实际上限定特定语言,应有明确的 opt-in 或合理说明。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.