slack-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external Slack events, which constitutes a surface for indirect prompt injection attacks where malicious users could attempt to influence the agent's behavior via message content.
- Ingestion points: Untrusted data enters the context through event handlers in
references/EXAMPLES.mdthat processcommand,event,message, andinteractionpayloads from the Slack API. - Boundary markers: The provided implementation examples do not include explicit delimiters or instructions for the agent to ignore potentially malicious content embedded within the Slack messages it reads.
- Capability inventory: The skill demonstrates capabilities for sending messages, opening UI modals, and interacting with the Slack API, which could be misused if the agent obeys instructions hidden in incoming Slack data.
- Sanitization: The code examples show direct interpolation of user-supplied data (such as user IDs and message text) into responses and database operations without demonstrating specific sanitization or validation steps.
Audit Metadata