slack-standup-digest
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it retrieves and processes messages from external Slack channels to generate summaries.
- Ingestion points: Messages are fetched from user-specified Slack channels (e.g., #engineering, #frontend) via the Slack MCP (SKILL.md).
- Boundary markers: The instructions do not specify any markers or delimiters to separate the ingested message content from the system instructions in the digest prompt (SKILL.md).
- Capability inventory: The skill has the ability to post content back to Slack channels and register recurring tasks on the automation backend (SKILL.md).
- Sanitization: There are no documented steps for sanitizing, filtering, or validating the content of the Slack messages before they are processed by the LLM (SKILL.md).
- [COMMAND_EXECUTION]: The skill involves executing shell commands to interact with the platform's automation API. These operations target vendor-owned infrastructure.
- Evidence: The setup workflow uses
curlto send POST requests to the${OPENHANDS_HOST}endpoint using the$OPENHANDS_AUTOMATION_API_KEY(SKILL.md).
Audit Metadata