egghead-slack

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill monitors Slack messages and threads to trigger automated behaviors, which creates an entry point for untrusted content to influence agent actions.
  • Ingestion points: Passive monitoring of Slack channels, thread context retrieval via the jc-slack tool, and history backfill operations (SKILL.md).
  • Boundary markers: The skill mentions a 'validation contract' and a 'deterministic participation path' but lacks explicit prompt delimiters or 'ignore' instructions for the LLM processing the triage.
  • Capability inventory: The skill utilizes the jc-slack CLI for Slack interactions and has the ability to launch 'Herdr/Pi' worktrees in resolved project repositories (SKILL.md).
  • Sanitization: The skill implements strong mitigations, including requiring manual approval for replies ('approval-bound confirmation command') and ensuring the gateway transport rewrites worker receipts before delivery.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — egghead-slack