remote-from-slack

Warn

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to use npx ai-devkit@latest, which fetches a package from the public npm registry at runtime.
  • [REMOTE_CODE_EXECUTION]: Running npx ai-devkit@latest executes remote code from the npm registry. The lack of version pinning increases the risk of executing unauthorized code if the package is compromised.
  • [COMMAND_EXECUTION]: The workflow relies on executing several shell commands (ai-devkit status, channel list, agent list, channel start) to manage agent bridges.
  • [PRIVILEGE_ESCALATION]: The instructions explicitly request the agent to run commands outside of filesystem sandboxes to inspect host-level state, which attempts to circumvent security boundaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from tool outputs (agent list and channel list). If these sources contain malicious strings from external environments like Slack, they could influence the agent's behavior.
  • Ingestion points: ai-devkit status --json, ai-devkit channel list, and ai-devkit agent list --json in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Host-level state inspection and background process management via ai-devkit shell commands in SKILL.md.
  • Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 7, 2026, 02:03 AM
Security Audit — agent-trust-hub — remote-from-slack