slack-webhooks

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's implementation examples reference dependency versions that are currently non-existent or futuristic relative to stable releases on official registries (NPM/PyPI).
  • Evidence: fastapi>=0.136.1 and pytest>=9.0.3 in Python requirements; next@^16.2.6, typescript@^6.0.3, vitest@^4.1.5, and jest@^30.4.2 in Node.js package manifests.
  • Risk: Referencing non-existent high version numbers can be a prerequisite for dependency confusion attacks. If an attacker registers these specific high versions on a public registry, users following these examples might inadvertently install malicious code.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the Slack Events API, which serves as a vector for untrusted data to enter the agent's context.
  • Ingestion points: The /webhooks/slack POST endpoints defined in the Express, FastAPI, and Next.js implementation examples.
  • Boundary markers: The skill follows industry best practices by requiring HMAC-SHA256 signature verification using the Slack signing secret and implementing a 5-minute replay protection check to ensure data authenticity and freshness.
  • Capability inventory: The examples demonstrate processing various event types (e.g., app_mention, message, reaction_added), though the logic provided is limited to logging and placeholders for further action.
  • Sanitization: The implementation uses standard JSON parsing and validates request headers before processing the payload.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:08 AM
Security Audit — agent-trust-hub — slack-webhooks