skills/paperclipai/paperclip/slack/Gen Agent Trust Hub

slack

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an interface for Slack, ingesting messages, file content, and canvas data from external participants. It correctly identifies this as untrusted material and provides specific instructions to ignore any commands or permission changes found within that data.
  • [COMMAND_EXECUTION]: The skill describes how to interface with the Paperclip API via HTTP POST requests in CLI or sandbox environments. These operations use vendor-provided environment variables (e.g., $PAPERCLIP_API_URL, $PAPERCLIP_API_KEY) and represent standard functionality for the paperclipai platform.
  • [SAFE]: The skill provides clear guidance on credential management, instructing the agent never to print credentials or request tokens as arguments. It also implements idempotency requirements for write operations to ensure reliable interaction with the Slack API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 02:23 AM
Security Audit — agent-trust-hub — slack