slack

Warn

Audited by Socket on May 19, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

BENIGN with elevated operational risk. The capabilities largely match a Slack integration skill and use official Slack/PyPI tooling, but the Session Bridge and launcher create medium-high security risk because untrusted Slack content can drive a tool-enabled agent that posts publicly and stores workspace data locally.

Confidence: 87%Severity: 66%
AnomalyLOW
daemon/launchd/install.sh

This fragment is a macOS LaunchAgent installer/manager that enables persistence by copying and loading a plist. It does not itself contain obvious malicious behaviors like network exfiltration, obfuscation, or credential theft, but it explicitly expects real Slack tokens to be present in the plist and delegates all runtime behavior to the omitted plist/daemon. Overall risk is driven by the supply-chain trustworthiness of the bundled plist/daemon and the sensitivity of secrets embedded in that plist.

Confidence: 62%Severity: 56%
Audit Metadata
Analyzed At
May 19, 2026, 04:47 PM
Package URL
pkg:socket/skills-sh/tdimino%2Fclaude-code-minoan%2Fslack%2F@7f805fc1224b66635887482dafe2fa6d723e968d
Security Audit — socket — slack