Back to skill

Security audit

Slack Workspace Manager

Security checks for vulnerabilities and agentic risk

Overview

This Slack admin skill is not clearly malicious, but it should be reviewed because it combines powerful Slack administration actions with loose routing, mismatched examples, and a mutable installer command.

Review before installing. Use only with a least-privilege Slack admin token, pin and verify the installer package instead of using `latest`, require dry-run and explicit confirmation for bulk/delete/archive/member changes, and do not let general project-planning requests invoke this skill automatically.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:195
Finding

Execution of an Unpinned Third-Party Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:195
Vulnerability Type: Supply-chain risk from a mutable dependency
Risk Level: Medium

Vulnerable Code Snippet:

bash
npx skillhub@latest install slack-workspace-manager-pro

Technical Analysis

The installation instruction uses npx to retrieve and execute the mutable latest version of the third-party skillhub package. No exact version, lockfile, package integrity hash, trusted publisher verification procedure, or reviewed local implementation is provided.

Because latest can point to a different artifact after this skill has been audited, the code ultimately executed by this command is not fixed by the reviewed project. The repository contains only SKILL.md; consequently, neither the installer implementation nor the installed Slack management skill can be inspected here. This creates a supply-chain trust gap rather than proof that the current upstream package is malicious.

Attack Path

  1. An attacker compromises the package publisher account, registry distribution path, or a future release assigned to the latest tag.
  2. The attacker publishes or substitutes a modified skillhub package containing malicious installer or lifecycle behavior.
  3. A user follows the documented installation command.
  4. npx downloads the package currently referenced by latest and executes its CLI, potentially including package lifecycle behavior.
  5. The malicious package runs under the invoking user's local permissions and may install altered skill content or modify accessible resources.

Impact Assessment

Successful exploitation could grant an attacker the same local privileges as the user executing npx. Depending on that user's environment and accessible credentials, this could permit reading or modifying files, accessing environment variables or Agent configuration, executing additional processes, and installing malicious skill instructions. ...[truncated 425 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version.
  2. Record the dependency in a lockfile and verify registry-provided integrity metadata.
  3. Where practical, publish and verify a cryptographic checksum or signature for the approved package artifact.
  4. Document the expected registry and verified publisher identity to reduce dependency-confusion and package-substitution risks.
  5. Review the package's source, lifecycle scripts, transitive dependencies, and installer behavior before approving it.
  6. Disable package lifecycle scripts where compatible with the installation process.
  7. Execute installation in a restricted environment with minimal filesystem, credential, and network access.
  8. Include or vendor the actual skill implementation in the audited project so its behavior remains within the review boundary.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger/use conditions are overly broad and overlap with ordinary project management and collaboration requests, making it easier for an agent to select this skill in situations where administrative Slack changes were not intended. Because the skill advertises enterprise admin, audit, and batch-operation features, overbroad routing materially raises the risk of accidental privileged execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L011 明确写明“支持中文交互”,结合整体文案未提供其他语言选项,形成了对交互语言的单一强制倾向。根据语言/locale 政策,若无用户选择或明确的区域性合理说明,不应默认强制特定语言。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document presents create/edit/delete and bulk Slack administration capabilities without a prominent, up-front risk warning. In the context of enterprise Slack and batch operations, insufficient warning can lead users or agents to perform destructive or wide-impact actions without understanding consequences such as mass invitations, archival, deletions, or permission changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The installation instruction uses npx skillhub@latest, which fetches and executes whatever version is current at install time. In an agent skill that already declares exec capability, this creates a supply-chain risk: a compromised or breaking upstream release could be executed without review, leading to arbitrary code execution or unexpected behavior during installation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented input/output contract describes a generic grading/audit scorer instead of Slack administration actions, which misrepresents what the skill actually does. For a skill with administrative and batch-operation capabilities, this ambiguity can cause an agent or operator to invoke the skill under the wrong assumptions, potentially triggering privileged actions while expecting a harmless analysis response.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The examples show code-review-like grades and compliance scores even though the skill is described as a Slack workspace manager. This inconsistency increases the chance of unsafe invocation, mistaken trust boundaries, or agent misrouting, especially because the skill can create, edit, delete, and bulk-manage enterprise Slack resources.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.