slack-search

Warn

Audited by Snyk on Aug 21, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In the slack-search runtime workflow, the agent ingests outsider-authored Slack message/file text by first using search tools (e.g., slack_search_public / slack_search_public_and_private) and then reading results in context via slack_read_thread, slack_read_channel, and slack_read_file, where the searched/returned content originates from workspace users.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 21, 2026, 07:04 PM
Issues
1
Security Audit — snyk — slack-search