slack-setup

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements robust defenses against indirect prompt injection. It explicitly instructs the agent to treat all Slack-sourced content (messages, names, metadata) as data rather than instructions, wrapping them in <untrusted-content> tags. It also defines specific flags (mismatch, unrenderable) to detect potential injection attempts.
  • [CREDENTIALS_UNSAFE]: The skill follows security best practices for credential handling. It uses PKCE for OAuth, avoids storing client secrets, and explicitly warns against asking users to paste sensitive tokens (like SLACK_APP_CONFIG_TOKEN) into the chat transcript.
  • [EXTERNAL_DOWNLOADS]: The skill references the @agentcomms/slack and @agentcomms/core packages. These are the primary tools intended for the skill's purpose and are used via standard package management commands for configuration and approval processes.
  • [COMMAND_EXECUTION]: The skill provides CLI commands for the user to run in their terminal to perform sensitive operations (like approving changes or creating apps), ensuring a human-in-the-loop for high-risk actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — slack-setup