slack-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external Slack events, which constitutes a surface for indirect prompt injection attacks where malicious users could attempt to influence the agent's behavior via message content.
  • Ingestion points: Untrusted data enters the context through event handlers in references/EXAMPLES.md that process command, event, message, and interaction payloads from the Slack API.
  • Boundary markers: The provided implementation examples do not include explicit delimiters or instructions for the agent to ignore potentially malicious content embedded within the Slack messages it reads.
  • Capability inventory: The skill demonstrates capabilities for sending messages, opening UI modals, and interacting with the Slack API, which could be misused if the agent obeys instructions hidden in incoming Slack data.
  • Sanitization: The code examples show direct interpolation of user-supplied data (such as user IDs and message text) into responses and database operations without demonstrating specific sanitization or validation steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — slack-expert