slack-webhooks
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's implementation examples reference dependency versions that are currently non-existent or futuristic relative to stable releases on official registries (NPM/PyPI).
- Evidence:
fastapi>=0.136.1andpytest>=9.0.3in Python requirements;next@^16.2.6,typescript@^6.0.3,vitest@^4.1.5, andjest@^30.4.2in Node.js package manifests. - Risk: Referencing non-existent high version numbers can be a prerequisite for dependency confusion attacks. If an attacker registers these specific high versions on a public registry, users following these examples might inadvertently install malicious code.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the Slack Events API, which serves as a vector for untrusted data to enter the agent's context.
- Ingestion points: The
/webhooks/slackPOST endpoints defined in the Express, FastAPI, and Next.js implementation examples. - Boundary markers: The skill follows industry best practices by requiring HMAC-SHA256 signature verification using the Slack signing secret and implementing a 5-minute replay protection check to ensure data authenticity and freshness.
- Capability inventory: The examples demonstrate processing various event types (e.g.,
app_mention,message,reaction_added), though the logic provided is limited to logging and placeholders for further action. - Sanitization: The implementation uses standard JSON parsing and validates request headers before processing the payload.
Audit Metadata