slack-bot-builder

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements handlers that ingest untrusted external data from Slack messages and external incident reports, which are then interpolated into UI components.
  • Ingestion points: Slack message handlers (@app.message) and the incident dictionary in the build_notification_blocks function (SKILL.md).
  • Boundary markers: Absent. The skill does not use delimiters or warnings to isolate untrusted user content from the application's logic.
  • Capability inventory: The code uses the say() method and client.views_open() to transmit data back to Slack workspaces (SKILL.md).
  • Sanitization: While the code includes basic string truncation for the description field, it does not demonstrate escaping or sanitization of Markdown or control characters.
  • [SAFE]: The skill follows recommended security practices by using environment variables (os.environ) for managing sensitive credentials like SLACK_BOT_TOKEN and SLACK_SIGNING_SECRET.
  • [SAFE]: The code references established, well-known libraries from Slack (slack-bolt and slack-sdk) for its core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — slack-bot-builder