slack-posting
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interaction with Slack workspaces involves processing untrusted external data such as message bodies and channel metadata. Evidence: The contract.md file mandates the use of tags and instructs the agent to ignore commands embedded in Slack messages. Mitigations: All posts require human approval, and the agent is explicitly prohibited from auto-approving actions.
- [COMMAND_EXECUTION]: The skill uses the agent-slack CLI tool to execute its primary functions. Evidence: SKILL.md contains multiple examples of shell commands like agent-slack draft create and agent-slack post send.
- [EXTERNAL_DOWNLOADS]: The skill depends on the @agentcomms/slack package from the NPM registry. Evidence: The SKILL.md frontmatter specifies a compatibility version and contract.md refers to running the tool via npx.
- [PRIVILEGE_ESCALATION]: The skill provides a command to manually expand the file access scope beyond the default home directory. Evidence: The agentcomms attach roots add command is documented as a user-only action that the agent cannot perform or approve itself.
- [NO_CODE]: The skill consists primarily of documentation and configuration without accompanying executable script files. Evidence: The skill contents are limited to SKILL.md, contract.md, and fit.json.
Audit Metadata