slack-reading
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Slack messages, creating an attack surface for indirect prompt injection.
- Ingestion points: Slack channels, threads, and search results via the
agent-slacktool. - Boundary markers: The skill requires untrusted content to be wrapped in
<untrusted-content>tags as defined in SKILL.md and references/contract.md. - Capability inventory: The agent can read communications and download files to the local disk.
- Sanitization: Implements filename sanitization to remove control characters and appends
.downloadto scripts or executable files to prevent accidental execution. - [COMMAND_EXECUTION]: The skill utilizes the
agent-slackCLI to interact with Slack workspaces and perform read/download operations. - [EXTERNAL_DOWNLOADS]: The skill downloads files from Slack workspaces. It includes specific logic to prevent saving files into sensitive system or configuration directories (e.g.,
~/.ssh,.git,.env) and warns the user about macro-capable files.
Audit Metadata