Slack workspace access. Surfaces new messages, active threads, and channel activity. Can also send messages and replies.
84
84%
Does it follow best practices?
Impact
Pending
No eval scenarios have been run
Advisory
Suggest reviewing before use
Security
1 medium severity finding. This skill can be installed but you should review these findings before use.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Third-party content exposure detected (high risk: 1.00). The skill explicitly fetches and reads user-generated Slack messages and threads from the user's Slack workspace via the included slack-cli (see SKILL.md check-in workflow and references/cli-commands.md and references/analysing-discussions.md), so untrusted third-party content is ingested and used to drive summarization and follow-up actions.