add-slack

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (Slack channel integration and setup) is plausible, but the actual footprint raises security concerns. It relies on pulling and merging code from an external repository (transitive installation), collects and stores Slack tokens, and forwards those credentials to a third-party codepath. These patterns create credential exposure risk and supply-chain risk beyond what is typical for a self-contained integration. While not conclusively malicious, the combination of external code, credential handling, and environment persistence warrants a suspicious risk posture and requires strict controls: code provenance verification, pinned dependencies, secrets-management practices, and explicit per-action user approvals for external code integration.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fadd-slack%2F@eb57b1059ec8a2127dbcd1465f7211fb444e94fb