detect-slack-external-channel-add
Installation
SKILL.md
detect-slack-external-channel-add
Attack pattern
Slack Enterprise Grid lets administrators connect external workspaces via shared channels or guest invitations. When a user from an external workspace is added to an internal Slack channel that carries sensitive content (security, exec, finance, legal, engineering-leads), the cross-tenant membership creates a DLP exposure and an insider-threat surface — the external account can read every subsequent message, file share, and attachment in the channel until the membership is revoked.
On the wire the pattern is: