slack-unanswered
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to use shell commands like
grep,cat, andpythonto search through local message archives and execute automation scripts. - [REMOTE_CODE_EXECUTION]: The skill triggers the execution of a local Python script
data/slack-sync/scripts/reply_slack.pyto interact with the Slack API for sending message replies. - [PROMPT_INJECTION]: The skill processes untrusted Slack messages to generate reply drafts, which constitutes an indirect prompt injection attack surface. * Ingestion points: Slack message archives stored in markdown files within the
slack-sync/data/directory. * Boundary markers: The agent uses structured markdown headers to parse messages but lacks specific instructions to ignore adversarial content within the message text. * Capability inventory: Access to local message files and the ability to post to Slack via an API script. * Sanitization: The skill does not explicitly describe sanitization of Slack message content before reply generation. - [CREDENTIALS_UNSAFE]: The documentation references the
SLACK_USER_TOKENand provides guidance on setting it up via environment variables or secrets for API authentication.
Audit Metadata