slack-bot-builder
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements handlers that ingest untrusted external data from Slack messages and external incident reports, which are then interpolated into UI components.
- Ingestion points: Slack message handlers (
@app.message) and theincidentdictionary in thebuild_notification_blocksfunction (SKILL.md). - Boundary markers: Absent. The skill does not use delimiters or warnings to isolate untrusted user content from the application's logic.
- Capability inventory: The code uses the
say()method andclient.views_open()to transmit data back to Slack workspaces (SKILL.md). - Sanitization: While the code includes basic string truncation for the description field, it does not demonstrate escaping or sanitization of Markdown or control characters.
- [SAFE]: The skill follows recommended security practices by using environment variables (
os.environ) for managing sensitive credentials likeSLACK_BOT_TOKENandSLACK_SIGNING_SECRET. - [SAFE]: The code references established, well-known libraries from Slack (
slack-boltandslack-sdk) for its core functionality.
Audit Metadata