Back to skill

Security audit

slack-memory

Security checks across malware telemetry and agentic risk

Overview

This Slack memory skill is purpose-aligned, but it asks agents to persist and search broad Slack workspace content through an external API without clear consent, channel limits, retention, or deletion guidance.

Install only if your workspace explicitly approves sending selected Slack content to BlueColumn. Treat it as an external persistent memory system: limit use to approved channels and non-sensitive summaries, avoid credentials/customer/personnel data, and confirm retention and deletion controls before relying on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation description is broad enough that an agent could use this skill during ordinary Slack interactions without a clear necessity check. Because the skill is designed to persist workspace conversations externally, overbroad triggering increases the chance of unnecessary collection and transmission of sensitive Slack content.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill explicitly instructs the agent to capture, store, and search Slack channel and thread content via an external API, but it provides no privacy warning, consent flow, or data-handling restrictions. In context, this is particularly dangerous because Slack often contains confidential business discussions, personnel matters, credentials, customer data, and other sensitive information that could be exfiltrated or retained outside the workspace without users realizing it.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.