slack-setup
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements robust defenses against indirect prompt injection. It explicitly instructs the agent to treat all Slack-sourced content (messages, names, metadata) as data rather than instructions, wrapping them in
<untrusted-content>tags. It also defines specific flags (mismatch,unrenderable) to detect potential injection attempts. - [CREDENTIALS_UNSAFE]: The skill follows security best practices for credential handling. It uses PKCE for OAuth, avoids storing client secrets, and explicitly warns against asking users to paste sensitive tokens (like
SLACK_APP_CONFIG_TOKEN) into the chat transcript. - [EXTERNAL_DOWNLOADS]: The skill references the
@agentcomms/slackand@agentcomms/corepackages. These are the primary tools intended for the skill's purpose and are used via standard package management commands for configuration and approval processes. - [COMMAND_EXECUTION]: The skill provides CLI commands for the user to run in their terminal to perform sensitive operations (like approving changes or creating apps), ensuring a human-in-the-loop for high-risk actions.
Audit Metadata