remote-from-slack
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use
npx ai-devkit@latest, which fetches a package from the public npm registry at runtime. - [REMOTE_CODE_EXECUTION]: Running
npx ai-devkit@latestexecutes remote code from the npm registry. The lack of version pinning increases the risk of executing unauthorized code if the package is compromised. - [COMMAND_EXECUTION]: The workflow relies on executing several shell commands (
ai-devkit status,channel list,agent list,channel start) to manage agent bridges. - [PRIVILEGE_ESCALATION]: The instructions explicitly request the agent to run commands outside of filesystem sandboxes to inspect host-level state, which attempts to circumvent security boundaries.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from tool outputs (
agent listandchannel list). If these sources contain malicious strings from external environments like Slack, they could influence the agent's behavior. - Ingestion points:
ai-devkit status --json,ai-devkit channel list, andai-devkit agent list --jsoninSKILL.md. - Boundary markers: Absent.
- Capability inventory: Host-level state inspection and background process management via
ai-devkitshell commands inSKILL.md. - Sanitization: Absent.
Audit Metadata