slack

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the @membranehq/cli package via npm to facilitate communication with the Slack API. This is a vendor-owned resource for the 'membranedev' author.
  • [COMMAND_EXECUTION]: The skill utilizes the membrane CLI to execute various integration tasks, including membrane action run and membrane request. These are the primary mechanisms for the skill's functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data originating from Slack conversations.
  • Ingestion points: Data is ingested through actions like get-conversation-history, list-conversations, and search-messages in SKILL.md.
  • Boundary markers: None detected; external message content is processed directly.
  • Capability inventory: The skill has the ability to post messages, delete files, and make arbitrary API requests via the membrane request command.
  • Sanitization: No explicit sanitization or validation of the retrieved message content is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 10:00 AM