slack-standup-digest

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it retrieves and processes messages from external Slack channels to generate summaries.
  • Ingestion points: Messages are fetched from user-specified Slack channels (e.g., #engineering, #frontend) via the Slack MCP (SKILL.md).
  • Boundary markers: The instructions do not specify any markers or delimiters to separate the ingested message content from the system instructions in the digest prompt (SKILL.md).
  • Capability inventory: The skill has the ability to post content back to Slack channels and register recurring tasks on the automation backend (SKILL.md).
  • Sanitization: There are no documented steps for sanitizing, filtering, or validating the content of the Slack messages before they are processed by the LLM (SKILL.md).
  • [COMMAND_EXECUTION]: The skill involves executing shell commands to interact with the platform's automation API. These operations target vendor-owned infrastructure.
  • Evidence: The setup workflow uses curl to send POST requests to the ${OPENHANDS_HOST} endpoint using the $OPENHANDS_AUTOMATION_API_KEY (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:07 PM
Security Audit — agent-trust-hub — slack-standup-digest