slack-user-cli
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s Slack read/write scope matches its purpose, but it depends on a non-verifiable local CLI that ingests powerful Slack session credentials and can perform public posting, DMing, uploads, and edits. Data flow seems aimed at Slack rather than a third-party proxy, so this is not confirmed malware, but the credential model and unverifiable executable make it high risk.
Confidence: 90%Severity: 84%
Audit Metadata