egghead-slack
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill monitors Slack messages and threads to trigger automated behaviors, which creates an entry point for untrusted content to influence agent actions.
- Ingestion points: Passive monitoring of Slack channels, thread context retrieval via the jc-slack tool, and history backfill operations (SKILL.md).
- Boundary markers: The skill mentions a 'validation contract' and a 'deterministic participation path' but lacks explicit prompt delimiters or 'ignore' instructions for the LLM processing the triage.
- Capability inventory: The skill utilizes the jc-slack CLI for Slack interactions and has the ability to launch 'Herdr/Pi' worktrees in resolved project repositories (SKILL.md).
- Sanitization: The skill implements strong mitigations, including requiring manual approval for replies ('approval-bound confirmation command') and ensuring the gateway transport rewrites worker receipts before delivery.
Audit Metadata