skills/openclaw/skills/slack/Gen Agent Trust Hub

slack

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill directs traffic to gateway.maton.ai and ctrl.maton.ai to provide managed OAuth access to Slack. This is documented functionality for the service integration and does not constitute unauthorized exfiltration.
  • [COMMAND_EXECUTION]: Documentation includes Python and shell code blocks that utilize the requests library to demonstrate API interaction. These are standard implementation examples for developers.
  • [PROMPT_INJECTION]: The skill facilitates reading untrusted data from Slack messages and search results, which represents an indirect prompt injection surface. \n
  • Ingestion points: SKILL.md (conversations.history, search.messages) \n
  • Boundary markers: Absent \n
  • Capability inventory: SKILL.md (network requests, script execution) \n
  • Sanitization: Absent
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 12:50 PM