connector-slack

Fail

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation provides standard installation commands for required Motoko packages (mops add slack-client@0.1.0 and mops add caffeineai-authorization@1.0.1). These are legitimate dependency management operations.
  • [EXTERNAL_DOWNLOADS]: The skill fetches dependencies from the Mops package registry. All external links point to official Slack documentation (api.slack.com) or the Mops registry (mops.one), which are trusted sources for this context.
  • [CREDENTIALS_SAFE]: The skill handles Slack API tokens (xoxb-, xoxp-) securely. It explicitly instructs the developer to gate token storage behind an admin permission check (AccessControl.hasPermission(..., #admin)), ensures tokens are never returned to the frontend, and passes them via Authorization: Bearer headers rather than URL parameters to prevent logging leaks.
  • [DATA_EXFILTRATION]: While the skill communicates with Slack, this is the core intended purpose. The implementation uses non-replicated outcalls, ensuring sensitive headers are handled by individual nodes rather than the entire subnet during consensus, which is a standard security practice for IC outcalls.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 7, 2026, 06:50 PM
Security Audit — agent-trust-hub — connector-slack