slack-bot-builder
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements handlers for external Slack messages and incident data which are interpolated into responses, creating a surface for indirect prompt injection.
- Ingestion points: Data enters via the
handle_hellomessage handler and thebuild_notification_blocksfunction inSKILL.md. - Boundary markers: No explicit delimiters or instructions are used to separate untrusted user input from system instructions.
- Capability inventory: The templates use
say()andclient.views_open()to interact with the workspace. - Sanitization: The snippets demonstrate direct interpolation of variable content into UI blocks without explicit validation or escaping.
Audit Metadata