slack-unanswered

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to use shell commands like grep, cat, and python to search through local message archives and execute automation scripts.
  • [REMOTE_CODE_EXECUTION]: The skill triggers the execution of a local Python script data/slack-sync/scripts/reply_slack.py to interact with the Slack API for sending message replies.
  • [PROMPT_INJECTION]: The skill processes untrusted Slack messages to generate reply drafts, which constitutes an indirect prompt injection attack surface. * Ingestion points: Slack message archives stored in markdown files within the slack-sync/data/ directory. * Boundary markers: The agent uses structured markdown headers to parse messages but lacks specific instructions to ignore adversarial content within the message text. * Capability inventory: Access to local message files and the ability to post to Slack via an API script. * Sanitization: The skill does not explicitly describe sanitization of Slack message content before reply generation.
  • [CREDENTIALS_UNSAFE]: The documentation references the SLACK_USER_TOKEN and provides guidance on setting it up via environment variables or secrets for API authentication.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — slack-unanswered