slack-bot-builder

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements handlers for external Slack messages and incident data which are interpolated into responses, creating a surface for indirect prompt injection.
  • Ingestion points: Data enters via the handle_hello message handler and the build_notification_blocks function in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are used to separate untrusted user input from system instructions.
  • Capability inventory: The templates use say() and client.views_open() to interact with the workspace.
  • Sanitization: The snippets demonstrate direct interpolation of variable content into UI blocks without explicit validation or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — slack-bot-builder