slack-qa-investigate

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from multiple sources, which could contain malicious instructions meant to influence the agent's behavior.
  • Ingestion points: SKILL.md instructs the agent to read repository files, follow links within documentation to fetch external pages (docs, wikis), and perform web searches for external libraries and APIs.
  • Boundary markers: The skill contains explicit instructions for a "Read-Only Mode (STRICT)" and a list of "Prohibited Actions" (in SKILL.md) that explicitly forbid modifying files or running commands with side effects.
  • Capability inventory: The agent uses tools for file reading, semantic search, grep, safe shell commands, and web search.
  • Sanitization: The instructions do not specify explicit data sanitization or escaping mechanisms for the content retrieved from external URLs or codebase files.
  • [EXTERNAL_DOWNLOADS]: The README.md file provides setup instructions involving a repository from a third-party service.
  • Evidence: The documentation suggests that the agent Clone https://github.com/warpdotdev/oz-slack-q-and-a-bot to proceed with setup. This resource belongs to the vendor associated with the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:30 PM
Security Audit — agent-trust-hub — slack-qa-investigate