Slack Backup

Security checks across malware telemetry and agentic risk

Overview

This Slack backup skill has a plausible purpose, but it can copy potentially sensitive Slack files to disk and depends on unreviewed helper code outside the submitted artifact.

Review the missing shared Slack helper files before installing or running this skill. Confirm which Slack token, workspace, and channel it will access, and treat ~/.openclaw/doc/backup as a persistent folder that may contain sensitive Slack files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger description uses very broad, everyday phrases like "back up the file from Slack" and "save the Slack file locally," which increases the chance of accidental invocation from ordinary conversation. Because this skill performs a real side effect—downloading Slack files to local storage—misfires could cause unintended copying of potentially sensitive data without clear user confirmation.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill description does not prominently warn that it downloads Slack-hosted files and stores copies under a local backup directory. Users may not realize that invoking the skill creates persistent local copies of potentially confidential Slack content, which raises privacy, data retention, and accidental disclosure risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal