Back to skill

Security audit

Slack助手

Security checks for vulnerabilities and agentic risk

Overview

This Slack helper is mostly a coherent Slack integration, but it gives an agent broad Slack posting, history, channel-management, webhook, and local-file upload capabilities without enough scoping or safety checks.

Install only if you are prepared to tightly limit the Slack app scopes, store tokens and webhook URLs as secrets, require explicit confirmation before posting or uploading, restrict file uploads to approved paths, and avoid enabling message history/search across sensitive channels unless users understand the privacy implications.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:130
Finding

Unrestricted Local File Upload to Slack

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 130-138
Vulnerability Type: Arbitrary local file disclosure through an external service
Risk Level: High

python
def upload_file(self, channel_id: str, filepath: str, title: str = ""):
    """上传文件到频道"""
    with open(filepath, "rb") as f:
        resp = self.client.files_upload_v2(
            channel=channel_id,
            file=f,
            title=title or os.path.basename(filepath)
        )
    return resp["file"]["permalink"]

Technical Analysis

The upload function accepts a caller-controlled filepath, opens that path without validation, and transmits the file to Slack. It does not restrict access to an approved directory, reject absolute paths or traversal sequences, detect symbolic links, screen sensitive filenames, enforce size limits, or request confirmation before transmission.

Uploading files is part of the declared functionality, but unrestricted access to the host filesystem is broader than necessary. In an agent context, prompt injection or an incorrect user request could cause the helper to upload credentials, environment files, private keys, application configuration, source code, or sensitive logs.

Attack Path

  1. An attacker supplies an instruction through user input or other untrusted content that influences the filepath and destination channel.
  2. The instruction selects a sensitive path such as .env, a credential file, an SSH key, or a private application log.
  3. The function opens the selected file with open(filepath, "rb").
  4. files_upload_v2 transmits the complete file to the chosen Slack channel.
  5. Anyone with access to that channel or the resulting Slack file can retrieve the exposed information.

Impact Assessment

Exploitation can disclose any file readable by the process running the Skill. The effective scope therefore inherits the host process's filesystem privileges. Exposed crede ...[truncated 256 chars]

Remediation
View remediation

Remediation Suggestions

  • Restrict uploads to a dedicated, explicitly configured export directory.
  • Canonicalize the requested path with realpath or Path.resolve() and verify that it remains beneath the approved directory.
  • Reject absolute paths, traversal outside the approved root, symbolic links, device files, sockets, and other non-regular files.
  • Deny sensitive filename and directory patterns such as .env, credential stores, private keys, browser profiles, and cloud configuration.
  • Enforce file-type and size limits before opening or transmitting content.
  • Require explicit user confirmation that displays the resolved source path and destination channel.
  • Apply destination-channel allowlists where practical.
  • Run the Skill under a dedicated account with minimal filesystem permissions.
  • Record security-safe audit metadata without logging file contents or credentials.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:117
Finding

Caller-Controlled Webhook Destination Enables Data Exfiltration and Server-Side Requests

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 117-126
Vulnerability Type: Unvalidated outbound network destination
Risk Level: High

python
import requests
import json

def send_via_webhook(webhook_url: str, text: str):
    """通过Incoming Webhook发送消息"""
    payload = {"text": text}
    resp = requests.post(webhook_url, json=payload)
    return resp.status_code == 200

# 创建Webhook: Slack API → Incoming Webhooks → Add New Webhook
send_via_webhook("https://hooks.slack.com/services/T00/B00/xxxxx",
                 "Deployment complete: v2.3.1 is live!")

Technical Analysis

send_via_webhook sends caller-provided text to a caller-provided URL without validating the scheme, hostname, port, resolved address, or redirect destination. Although the example uses hooks.slack.com, the implementation does not enforce that destination.

This permits sensitive data to be posted to an attacker-controlled server. It may also permit server-side requests to internal services or loopback endpoints reachable from the Skill's execution environment. The request has no explicit timeout, so an unresponsive endpoint can also block execution. Redirect behavior is not constrained, allowing an initially acceptable-looking URL to redirect elsewhere.

Attack Path

  1. An attacker causes the Skill to call send_via_webhook with a URL under the attacker's control, or with an internal-service URL.
  2. Sensitive conversation content, credentials, operational data, or other private information is supplied as text.
  3. requests.post sends the JSON payload to the supplied destination.
  4. For an attacker-controlled destination, the attacker records and uses the disclosed content.
  5. For an internal destination, the request may interact with services that are not externally reachable, subject to their accepted methods and authentication requirements.
  6. If redirects are returned, the request may follow them to ...[truncated 549 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not accept arbitrary webhook URLs during normal Skill execution.
  • Store approved webhook endpoints in trusted configuration and reference them by a non-secret identifier.
  • Parse URLs and require HTTPS with the exact approved hostname, such as hooks.slack.com.
  • Reject embedded credentials, unexpected ports, IP-literal hosts, loopback addresses, link-local addresses, and private network ranges.
  • Disable redirects or validate every redirect target against the same allowlist.
  • Set explicit connection and read timeouts and enforce response-size limits.
  • Require confirmation before sending content classified as sensitive.
  • Avoid logging full webhook URLs because Slack webhook paths function as credentials.
  • Apply outbound firewall or proxy rules that limit the process to required Slack API endpoints.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned and Inconsistent Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 17
Vulnerability Type: Unpinned package installation and inaccurate dependency declaration
Risk Level: Medium

bash
pip install slack-sdk aiohttp

Technical Analysis

The installation instruction retrieves mutable package versions without pins or integrity hashes. As a result, installations performed at different times may receive different code, including incompatible, vulnerable, or compromised future releases.

The document installs aiohttp even though the shown implementation does not use it, increasing supply-chain exposure beyond the minimum dependencies required for the declared examples. Conversely, the webhook example imports requests, but that package is not declared in the installation command or metadata. This mismatch makes dependency resolution dependent on the surrounding environment and reduces reproducibility.

No evidence shows that the named packages are malicious or sourced from an untrusted repository. The risk arises from unconstrained future resolution and unnecessary dependency installation rather than a confirmed malicious package.

Attack Path

  1. A user follows the documented pip install command.
  2. Package resolution selects the latest versions available from the configured Python package index at installation time.
  3. If a selected release is compromised, malicious installation or runtime code executes with the privileges of the user performing the installation.
  4. Alternatively, an incompatible or vulnerable release introduces exploitable behavior into the Skill's environment.
  5. The unnecessary aiohttp dependency expands this exposure without supporting the documented implementation.

Impact Assessment

A compromised dependency can potentially execute code with the installing or runtime user's permissions, allowing access to files, environment variables, network credentials, and other resources availab ...[truncated 189 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove aiohttp unless it is required by an implemented and reviewed feature.
  • Explicitly declare requests if the webhook example remains in use.
  • Pin reviewed package versions in a requirements or lock file.
  • Use integrity hashes, such as pip's --require-hashes, for reproducible installations.
  • Install from an approved package index and prevent dependency resolution from untrusted extra indexes.
  • Run dependency vulnerability and license scanning in CI.
  • Review and update pinned versions through a controlled maintenance process.
  • Install dependencies in an isolated virtual environment under a non-privileged account.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description is written in Chinese and presents the skill as a Chinese-language assistant without indicating language choice or an opt-in mechanism. The policy requires flagging language or locale constraints when the skill forces a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation words are extremely broad, including generic terms like '消息', '通知', and '团队', which are likely to appear in ordinary conversation. In an agent setting, this can cause unintended invocation of Slack-capable actions, increasing the chance of accidental message sending, history retrieval, or channel operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
## 获取Token

1. 访问 https://api.slack.com/apps
2. 创建新App → 选择 "From scratch"
3. 添加 Bot Token Scopes: `chat:write`, `channels:read`, `channels:history`
4. 安装App到工作区,复制 Bot User OAuth Token

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented scopes only mention chat:write, channels:read, and channels:history, but the examples also create channels, invite users, search messages, and upload files. This mismatch can cause operators to grant broader permissions than they understand or deploy a skill that fails unpredictably and is then over-permissioned to 'make it work'.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes message search and channel history retrieval without warning that it can surface potentially sensitive internal communications. In a conversational agent context, users may trigger these functions without realizing they are retrieving private or regulated content from Slack.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This function performs an external HTTP POST to a Slack webhook, which is a real data egress path. In context, that behavior is expected for a Slack integration, but it becomes security-relevant because the skill can transmit arbitrary content outside the local environment and the webhook URL is a secret credential.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
def send_via_webhook(webhook_url: str, text: str):
    """通过Incoming Webhook发送消息"""
    payload = {"text": text}
    resp = requests.post(webhook_url, json=payload)
    return resp.status_code == 200

# 创建Webhook: Slack API → Incoming Webhooks → Add New Webhook

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file upload capability can transmit arbitrary local files to Slack, but the description does not warn about data exfiltration risks. In an agent environment, this is more dangerous because a user prompt or indirect instruction could cause sensitive local files, logs, or credentials to be uploaded externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The outbound Slack posting examples do not clearly warn that content will be transmitted to an external third-party service. While sending messages is the intended function, lack of notice can lead to accidental disclosure of internal or sensitive information through routine use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The heading Webhook方式(无需Bot Token) and function docstring imply a lower-privilege or token-free mode, but the code still sends authenticated messages using a secret Slack Incoming Webhook credential. This is not truly unauthenticated behavior, and the wording can mislead users about the trust and secret-handling implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.