slack

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align with a local Slack emulator, and the outbound webhook behavior is expected for event simulation. The main concern is install trust: the skill asks the agent to execute an external `npx emulate` CLI without enough evidence that the package is the official, verifiable distribution for this skill, which raises supply-chain risk. Overall this looks more like a plausible dev tool with unverifiable dependency provenance than overtly malicious behavior.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 10:43 AM
Package URL
pkg:socket/skills-sh/vercel-labs%2Femulate%2Fslack%2F@17cea57cb7039bffe6dae222d86446cc5f16c008