wk-slack
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses established Slack MCP tools for messaging and reading channel/user data. All tool use follows the principle of least privilege within the communication domain.
- [SAFE]: The instructions emphasize safety by mandating a human-in-the-loop review process ('HARD RULE — always show the composed message to the user before posting').
- [SAFE]: A privacy filter is explicitly defined for standup snippets to ensure that sensitive data like HR information, candidate PII, and personal communications are excluded from public channel posts.
- [SAFE]: The skill documents standard web clipboard APIs (
ClipboardItem) and provide fallbacks for older browser environments. No suspicious obfuscation or remote code execution patterns were found.
Audit Metadata