slack-channel-monitor
Fail
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: HIGHINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPERSISTENCECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an automation that monitors Slack channels and forwards incoming messages into new agent conversations. This creates a surface for indirect prompt injection where malicious instructions in a Slack message could influence the behavior of the spawned agent.
- Ingestion points: Slack message text and thread history are retrieved in
scripts/main.pyusing theconversations.history,search.messages, andconversations.repliesendpoints. - Boundary markers: The generated prompt in
scripts/main.pyuses markdown delimiters (--- Background context ---) and explicit instructions to the agent to distinguish between the 'User request' and the 'Background context'. - Capability inventory: The automation script configures new conversations to have access to
terminalandfile_editortools, and forwards user secrets viaLookupSecretreferences. - Sanitization: No sanitization or filtering of Slack message content is implemented before it is interpolated into the agent prompt.
- [DYNAMIC_EXECUTION]: The setup workflow requires the agent to read a template script (
scripts/main.py), programmatically replace configuration constants such asTRIGGER_PHRASEandCHANNEL_IDS, and write the modified script to a file for execution. - [PERSISTENCE]: The skill creates a long-running automation using a
crontrigger (* * * * *), ensuring the monitoring script executes repeatedly every minute. - [COMMAND_EXECUTION]: Setup instructions in
SKILL.mdandreferences/windows.mdutilize shell commands likecurl,tar, andpython3to validate credentials, resolve channel identifiers, and package the automation. - [EXTERNAL_DOWNLOADS]: The automation interacts with the Slack API (
slack.com) to fetch messages and post responses. These interactions target a well-known service and are legitimate for the skill's purpose. - [REMOTE_CODE_EXECUTION]: Automated scans flagged the use of
curl ... | python3inSKILL.md. Analysis confirms this is a false positive for remote code execution; the pattern uses a static string to parse JSON output from the Slack API and does not execute arbitrary remote code.
Recommendations
- HIGH: Downloads and executes remote code from: https://slack.com/api/auth.test - DO NOT USE without thorough review
Audit Metadata