access

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses a sensitive configuration file located at ~/.claude/channels/slack/access.json.
  • This file contains pairing codes, user allowlists, and internal access policies. Access is restricted to the terminal operator and is essential for the skill's primary function.
  • [COMMAND_EXECUTION]: The skill uses shell commands via the Bash tool to manage the filesystem.
  • It utilizes Bash(mv:*) to perform atomic updates to the access configuration, preventing race conditions or partial writes.
  • It utilizes Bash(chmod:*) to ensure the configuration file maintains secure permissions (0600).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied input through the $ARGUMENTS variable to execute subcommands.
  • Ingestion points: Arguments passed to the /slack-channel:access command in SKILL.md.
  • Boundary markers: The skill includes a dedicated references/security-boundary.md file which explicitly instructs the agent to verify that requests originate from the trusted terminal operator and to refuse ambiguous inputs.
  • Capability inventory: The skill has Read, Write, and restricted Bash capabilities to modify local configuration files.
  • Sanitization: The instructions require validation of input modes (e.g., policy types) and verification of pairing code validity/expiration before modification.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and configuration schemas hosted on the author's GitHub repository.
  • It links to github.com/jeremylongshore/claude-code-slack-channel for authoritative references on the access-control contract and quick start guides.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 11:06 AM
Security Audit — agent-trust-hub — access