Slack workspace access. Surfaces new messages, active threads, and channel activity. Can also send messages and replies.
67
84%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The skill explicitly fetches and reads user-generated Slack messages and threads from the user's Slack workspace via the included slack-cli (see SKILL.md check-in workflow and references/cli-commands.md and references/analysing-discussions.md), so untrusted third-party content is ingested and used to drive summarization and follow-up actions.