slack

Fail

Audited by Socket on Mar 14, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The basic Slack API scripts align with the stated purpose, but the Session Bridge materially expands scope: it depends on an unverifiable personal-repo daemon, forwards Slack tokens to that external code, and allows untrusted Slack messages to drive the current agent session with full tool access. The main risk is not confirmed malware, but disproportionate trust, credential forwarding, transitive dependency/skill trust, and high prompt-injection/autonomy exposure.

Confidence: 89%Severity: 88%
Audit Metadata
Analyzed At
Mar 14, 2026, 02:32 PM
Package URL
pkg:socket/skills-sh/tdimino%2Fclaude-code-minoan%2Fslack%2F@9de21dd779dcae0dc2cfeff3bda4833614ebae8b