slack-reading

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Slack messages, creating an attack surface for indirect prompt injection.
  • Ingestion points: Slack channels, threads, and search results via the agent-slack tool.
  • Boundary markers: The skill requires untrusted content to be wrapped in <untrusted-content> tags as defined in SKILL.md and references/contract.md.
  • Capability inventory: The agent can read communications and download files to the local disk.
  • Sanitization: Implements filename sanitization to remove control characters and appends .download to scripts or executable files to prevent accidental execution.
  • [COMMAND_EXECUTION]: The skill utilizes the agent-slack CLI to interact with Slack workspaces and perform read/download operations.
  • [EXTERNAL_DOWNLOADS]: The skill downloads files from Slack workspaces. It includes specific logic to prevent saving files into sensitive system or configuration directories (e.g., ~/.ssh, .git, .env) and warns the user about macro-capable files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — slack-reading