connector-slack
Fail
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation provides standard installation commands for required Motoko packages (
mops add slack-client@0.1.0andmops add caffeineai-authorization@1.0.1). These are legitimate dependency management operations. - [EXTERNAL_DOWNLOADS]: The skill fetches dependencies from the Mops package registry. All external links point to official Slack documentation (api.slack.com) or the Mops registry (mops.one), which are trusted sources for this context.
- [CREDENTIALS_SAFE]: The skill handles Slack API tokens (
xoxb-,xoxp-) securely. It explicitly instructs the developer to gate token storage behind an admin permission check (AccessControl.hasPermission(..., #admin)), ensures tokens are never returned to the frontend, and passes them viaAuthorization: Bearerheaders rather than URL parameters to prevent logging leaks. - [DATA_EXFILTRATION]: While the skill communicates with Slack, this is the core intended purpose. The implementation uses non-replicated outcalls, ensuring sensitive headers are handled by individual nodes rather than the entire subnet during consensus, which is a standard security practice for IC outcalls.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata