Back to skill

Security audit

slack-workspace-free

Security checks for vulnerabilities and agentic risk

Overview

This Slack helper is not clearly malicious, but it asks for broader local and third-party authority than its basic Slack purpose needs.

Review this carefully before installing. Use it only with a Slack workspace and channels where automated posting is acceptable, verify the ClawLink plugin identity and requested OAuth scopes, and revoke the OAuth grant if no longer needed. Avoid running the agent as administrator and require a manual check of the channel ID and message text before any post.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:54
Finding

Unpinned Third-Party Plugin Handles Slack OAuth Access

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:25
Finding

Excessive Local Tool Permissions and Unsafe Privilege-Elevation Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest markets the skill as a limited Slack workspace integration, but declares broad read/write/exec tool access. Excess capability relative to the stated purpose violates least privilege and creates a larger attack surface if the skill is invoked with adversarial input or misunderstood by an agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes sending Slack messages but does not clearly emphasize that this is an external write action visible to workspace members. Without an explicit warning, an agent may post sensitive, incorrect, or premature content to a real channel, causing confidentiality or operational issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The operational instructions include a concrete send-message command but omit a direct caution to verify the recipient channel and message content first. This increases the risk of accidental posting to the wrong channel or publishing sensitive information, particularly because channel IDs are manually supplied.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly promotes file read/write handling even though the skill's stated purpose is Slack workspace messaging and listing. Unjustified file capabilities can lead users or agents to expose local data or modify files without expecting that behavior from a Slack-focused skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a narrowly scoped Slack workspace helper, but later sections advertise unrelated file handling and generic command-execution workflows. That scope drift can mislead an agent or operator into granting or using broader capabilities than necessary, increasing the chance of unintended file access or command execution under the guise of a Slack-only skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest display name, summary, and description are presented in Chinese, and the rest of the skill documentation is also effectively Chinese-only. This imposes a specific language/locale without any opt-in, language-selection guidance, or documented reason for the restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.