slack-agent-flow
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly aligned with its stated Slack-agent provisioning purpose, and its install steps mostly reference same-project assets and standard local tooling rather than clear third-party payloads. However, it requires powerful Slack provisioning credentials, persists many bot tokens in .env, modifies both host and container runtime surfaces, and can autonomously create Slack apps/rooms/messages. The undocumented managed-broker path also leaves some data-flow uncertainty. This looks more like a high-impact integration skill than outright malware, but its scope and credential sensitivity make it medium-high risk.
Confidence: 79%Severity: 68%
Audit Metadata