skills/firecrawl/openclaw/slack/Gen Agent Trust Hub

slack

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface for indirect prompt injection because it allows the agent to ingest untrusted data from Slack messages.
  • Ingestion points: The readMessages action defined in SKILL.md allows retrieval of message content from Slack channels.
  • Boundary markers: There are no boundary markers or instructions to treat external message content as untrusted data.
  • Capability inventory: The skill includes high-impact capabilities such as sendMessage, editMessage, deleteMessage, and pinMessage, which could be exploited if the agent follows malicious instructions found in messages.
  • Sanitization: The documentation does not specify any sanitization, filtering, or validation of incoming message content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:54 PM
Security Audit — agent-trust-hub — slack