slack-channel-monitor

Fail

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: HIGHINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPERSISTENCECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an automation that monitors Slack channels and forwards incoming messages into new agent conversations. This creates a surface for indirect prompt injection where malicious instructions in a Slack message could influence the behavior of the spawned agent.
  • Ingestion points: Slack message text and thread history are retrieved in scripts/main.py using the conversations.history, search.messages, and conversations.replies endpoints.
  • Boundary markers: The generated prompt in scripts/main.py uses markdown delimiters (--- Background context ---) and explicit instructions to the agent to distinguish between the 'User request' and the 'Background context'.
  • Capability inventory: The automation script configures new conversations to have access to terminal and file_editor tools, and forwards user secrets via LookupSecret references.
  • Sanitization: No sanitization or filtering of Slack message content is implemented before it is interpolated into the agent prompt.
  • [DYNAMIC_EXECUTION]: The setup workflow requires the agent to read a template script (scripts/main.py), programmatically replace configuration constants such as TRIGGER_PHRASE and CHANNEL_IDS, and write the modified script to a file for execution.
  • [PERSISTENCE]: The skill creates a long-running automation using a cron trigger (* * * * *), ensuring the monitoring script executes repeatedly every minute.
  • [COMMAND_EXECUTION]: Setup instructions in SKILL.md and references/windows.md utilize shell commands like curl, tar, and python3 to validate credentials, resolve channel identifiers, and package the automation.
  • [EXTERNAL_DOWNLOADS]: The automation interacts with the Slack API (slack.com) to fetch messages and post responses. These interactions target a well-known service and are legitimate for the skill's purpose.
  • [REMOTE_CODE_EXECUTION]: Automated scans flagged the use of curl ... | python3 in SKILL.md. Analysis confirms this is a false positive for remote code execution; the pattern uses a static string to parse JSON output from the Slack API and does not execute arbitrary remote code.
Recommendations
  • HIGH: Downloads and executes remote code from: https://slack.com/api/auth.test - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — slack-channel-monitor