slack-automation
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation for Slack automation through the Rube MCP server. All tools and URLs mentioned (rube.app, composio.dev) are associated with the established Composio integration platform and serve the skill's primary purpose.
- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by enabling the agent to ingest and act upon Slack message content. • Ingestion points: Data enters the context via tools like SLACK_SEARCH_MESSAGES, SLACK_FETCH_MESSAGE_THREAD_FROM_A_CONVERSATION, and SLACK_FETCH_CONVERSATION_HISTORY. • Boundary markers: No instructions for using delimiters or boundary markers to isolate retrieved content are provided. • Capability inventory: The skill provides write access via tools like SLACK_SEND_MESSAGE, SLACK_SCHEDULE_MESSAGE, and channel management functionality. • Sanitization: No content validation or sanitization logic is specified in the skill instructions.
Audit Metadata