cyrus-setup-slack

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands including grep, printf, and echo to interact with local configuration files located at ~/.cyrus/.env to check for and set environment variables.
  • [DATA_EXFILTRATION]: The skill accesses sensitive file paths (~/.cyrus/.env) to manage application secrets. It mitigates risk through explicit instructions forbidding the agent from reading secret values into the conversation context or scraping them from web pages, directing the user to manually manage the transfer of credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the conversation context.
  • Ingestion points: Variables AGENT_NAME and AGENT_DESCRIPTION are pulled from the conversation context and interpolated into a Slack manifest JSON.
  • Boundary markers: The content is delimited by JSON object structure, but no specific escaping or "ignore instructions" warnings are applied to the interpolated variables.
  • Capability inventory: The skill utilizes agent-browser for navigation and interaction, shell commands for file modification, and browser-based JavaScript execution.
  • Sanitization: There is no evidence of explicit sanitization or validation for the AGENT_NAME or AGENT_DESCRIPTION fields before interpolation.
  • [DYNAMIC_EXECUTION]: The skill utilizes browser automation tools (agent-browser and claude-in-chrome) to interact with the Slack API. Specifically, it uses agent-browser eval to execute a JavaScript snippet that programmatically sets the value of a text area in the browser to paste the generated manifest JSON.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:15 AM
Security Audit — agent-trust-hub — cyrus-setup-slack