slack-todo-extractor

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes potentially untrusted content from Slack messages through an LLM to determine task status. This constitutes an indirect prompt injection surface.
  • Ingestion points: Slack message bodies and thread replies are read from local markdown files within the slack-sync/data/ directory.
  • Boundary markers: No specific delimiters or boundary instructions are used to isolate message content in the prompt context.
  • Capability inventory: The LLM output is used only for data classification and is not passed to any execution tools or shell commands.
  • Sanitization: No sanitization is performed on the message content before it is processed by the LLM.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the Google GenAI SDK to communicate with the Gemini API for advanced task determination.
  • [COMMAND_EXECUTION]: The skill provides scripts that read local file system data to process Slack history, which is consistent with its stated purpose of extracting tasks from synced data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — slack-todo-extractor