ce-slack-research
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed to search Slack using an authenticated MCP server to provide organizational context. Accessing this data is the primary and stated purpose of the skill.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of Slack messages. It includes a robust 'Untrusted Input Handling' section that directs the agent to ignore potential injection attempts, extract only factual claims, and prevent message content from influencing agent behavior. This effectively mitigates the risks associated with processing third-party chat data.
- [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill accesses potentially sensitive organizational data in Slack, it includes privacy-preserving constraints such as explicitly excluding Direct Messages (DMs) and focusing only on public and private channels as authorized by the user. There is no evidence of data being sent to unauthorized external domains.
Audit Metadata