slack-posting

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interaction with Slack workspaces involves processing untrusted external data such as message bodies and channel metadata. Evidence: The contract.md file mandates the use of tags and instructs the agent to ignore commands embedded in Slack messages. Mitigations: All posts require human approval, and the agent is explicitly prohibited from auto-approving actions.
  • [COMMAND_EXECUTION]: The skill uses the agent-slack CLI tool to execute its primary functions. Evidence: SKILL.md contains multiple examples of shell commands like agent-slack draft create and agent-slack post send.
  • [EXTERNAL_DOWNLOADS]: The skill depends on the @agentcomms/slack package from the NPM registry. Evidence: The SKILL.md frontmatter specifies a compatibility version and contract.md refers to running the tool via npx.
  • [PRIVILEGE_ESCALATION]: The skill provides a command to manually expand the file access scope beyond the default home directory. Evidence: The agentcomms attach roots add command is documented as a user-only action that the agent cannot perform or approve itself.
  • [NO_CODE]: The skill consists primarily of documentation and configuration without accompanying executable script files. Evidence: The skill contents are limited to SKILL.md, contract.md, and fit.json.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:34 AM
Security Audit — agent-trust-hub — slack-posting