Back to skill

Security audit

Slack Workspace Manager Free

Security checks for vulnerabilities and agentic risk

Overview

This Slack management skill is not plainly malicious, but it combines mutable install-time code, Slack OAuth access, and workspace-changing commands with scoping and disclosure gaps users should review carefully.

Install only if you trust the publisher and are comfortable granting this tool Slack OAuth access to post messages, manage channels, handle files and reminders, and query user data. Prefer a pinned installer/version, review the Slack OAuth scopes before authorizing, confirm where tokens are stored, and require explicit confirmation before any Slack write, delete, channel change, file upload, or history read.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:155
Finding

Execution of Unpinned npm Packages During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:155
Vulnerability Type: Supply-chain risk from mutable, unpinned npm dependencies
Risk Level: Medium

Vulnerable Code Snippet:

bash
# Install the tool
npx skillhub@latest install slack-workspace-manager-free

Technical Analysis

The installation procedure invokes skillhub@latest through npx. The latest tag is mutable, so the executed package version can change after this skill has been reviewed. The command also does not specify an integrity hash, lockfile, trusted package digest, or reviewed version of slack-workspace-manager-free.

npx can download and execute package-controlled code. Consequently, the effective installation logic is supplied by an external package registry at execution time rather than being fully represented by the audited project. A compromised maintainer account, registry package, release process, or malicious future version could therefore cause arbitrary code to run under the invoking user's privileges.

This finding is limited to the unsafe dependency-installation instruction. The audit did not establish that the current external packages are malicious because their source code and registry artifacts were not included in the project.

Attack Path

  1. An attacker compromises the skillhub package, its publisher, or its release pipeline, or causes a malicious release to receive the mutable latest tag.
  2. A user or Agent follows the documented installation procedure.
  3. npx retrieves the attacker-controlled package version from the configured npm registry.
  4. Package-controlled code executes with the privileges and environment of the user running the Agent.
  5. The code could read accessible local files, alter installed components, or tamper with the Slack-management CLI.
  6. If the compromised component remains involved when the user completes Slack OAuth authorization, it could attempt to access the result ...[truncated 787 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace skillhub@latest with an exact, reviewed version, and pin the installed skill to an exact version as well.
  2. Commit and enforce a lockfile where the installation model supports one.
  3. Verify package integrity using registry integrity metadata, cryptographic hashes, signatures, or provenance attestations.
  4. Use an approved registry or internal mirror and restrict installation to allowlisted package names, versions, and publishers.
  5. Review downloaded package contents and lifecycle scripts before execution. Disable lifecycle scripts where they are unnecessary.
  6. Run installation in a sandbox or least-privileged environment without unrelated credentials or sensitive files.
  7. Separate installation from Slack authorization so install-time processes cannot access OAuth credentials.
  8. Document the expected package source, exact version, checksums, required Slack scopes, and secure token-storage mechanism.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
75% confidence
Finding

该技能描述及全文均以中文呈现,并在面向多平台 Agent 的通用技能上下文中未说明是否支持按用户偏好切换语言。对于跨语言用户环境,这种默认单一语言输出可能构成语言/locale 约束,但文件中没有提供显式的用户选择或 opt-in 说明。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document claims all write operations require user confirmation, yet the command examples show direct execution with no explicit preview/confirm step. In an agent setting, this discrepancy can normalize unsafe invocation patterns and increase the chance of unintended Slack writes, deletions, or channel changes being carried out without meaningful human confirmation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger condition is broad enough to match generic project management, planning, progress tracking, and team collaboration requests. In an agent ecosystem, overly broad activation can cause this skill to be selected in situations where the user did not specifically intend Slack-side actions, increasing the risk of unnecessary data access or accidental workspace modifications.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to run npx skillhub@latest install ..., which fetches and executes code from the registry without pinning an exact trusted version. If the upstream package is compromised or a breaking/malicious release is published, users may execute unexpected code during installation, which is especially risky because this skill allows exec and is intended to manage OAuth-connected Slack operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

SKILL.md 在常用操作示例中包含 get-history 和 get-thread,表示该技能实际还支持读取频道历史消息与线程回复内容。Manifest description 与“核心能力”部分仅声明消息发送、频道管理、文件处理、提醒创建和用户查询,没有说明消息内容读取能力,这会让技能实际数据访问范围超出其对外描述。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.