agent-slack
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
SKILL.mdfile recommends installing the CLI binary by piping an external script directly to the shell viacurl -fsSL https://raw.githubusercontent.com/stablyai/agent-slack/main/install.sh | sh. This technique circumvents conventional package manager integrity checks and allows arbitrary code execution from a non-whitelisted remote repository. - [CREDENTIALS_UNSAFE]: The documentation outlines commands such as
agent-slack auth import-chromeandagent-slack auth import-firefoxthat retrieve highly sensitive authentication secrets (like session tokens and cookies) directly from local browser databases. It also provides examples for manually exporting plaintext browser tokens (SLACK_TOKEN="xoxc-...") and cookies (SLACK_COOKIE_D="xoxd-..."). - [COMMAND_EXECUTION]: The instruction file exposes multiple shell commands that execute complex local system operations, such as accessing data paths (
~/.agent-slack/tmp/downloads/) and launching web browsers for interactive message drafting via an editor.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/stablyai/agent-slack/main/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata