slack
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill captures sensitive workspace information and saves it to local files, creating a potential for data exposure.\n
- Evidence: Commands such as
agent-browser snapshot --json > output.jsonandagent-browser screenshot slack-unreads.pnginSKILL.mdstore data on the local filesystem.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Slack messages which could contain malicious instructions.\n - Ingestion points:
agent-browser snapshotandagent-browser get textinSKILL.mdandreferences/slack-tasks.md.\n - Boundary markers: The instructions lack delimiters or specific directives to ignore instructions embedded within the Slack messages being processed.\n
- Capability inventory: The skill uses
agent-browserto perform actions like clicking, filling forms, and taking screenshots within a browser session.\n - Sanitization: There is no evidence of filtering or sanitizing the content retrieved from Slack before it is used to influence the agent's behavior.
Audit Metadata