Back to skill

Security audit

Daxiang Slack

Security checks for vulnerabilities and agentic risk

Overview

This Slack skill can automate a logged-in Slack session and save private workspace content locally without clear privacy, scoping, or confirmation limits.

Review this before installing in any real workspace. Use it only for Slack accounts and conversations you are authorized to access, avoid broad exports of DMs or private channels, prefer summaries over raw screenshots/JSON, delete local captures after use, and pin or vet the `agent-browser` tool before relying on the `npx` path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The manifest references npx agent-browser without a fixed version, creating a supply-chain risk at the skill definition boundary. Because this skill is designed to automate a logged-in Slack session, compromise of the fetched tool could expose sensitive workspace data, messages, screenshots, and session context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger language is very broad and can cause the skill to activate for many generic requests involving Slack, search, extraction, or messaging. In practice, overbroad activation increases the chance that browser automation is used unnecessarily on a live Slack session, which can lead to unintended access, data capture, or message-sending in response to ambiguous prompts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill allows invoking npx agent-browser:* without pinning an exact package version, which means the code fetched and executed can change over time. If the package is updated maliciously, compromised in the supply chain, or replaced through dependency confusion or publishing compromise, the skill could execute attacker-controlled code with the agent's privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation repeatedly instructs the agent to extract Slack data, save JSON snapshots, and write screenshots to local files without any privacy warning, minimization guidance, or retention controls. Since Slack often contains confidential business communications, credentials, customer data, and personal information, this encourages persistent local capture of sensitive content beyond the user's immediate need.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document broadly recommends evidence capture across unread activity, DMs, channels, pins, and reactions, normalizing the creation of screenshots and snapshots of Slack content without any mention of confidentiality, workspace permissions, or handling restrictions. Since Slack routinely contains confidential internal discussions, customer data, and personal information, this omission is a genuine security/privacy weakness rather than a harmless documentation choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section explicitly instructs capturing screenshots and snapshots of Slack conversations that can contain message bodies, usernames, timestamps, reactions, and other potentially sensitive business or personal information. In the context of a browser-automation skill for Slack, this creates a real privacy and data-handling risk because it encourages broad collection of communications data without any minimization, consent, or permission checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide directs the agent to extract structured user and conversation data such as who said what, when, and reactions, which amounts to systematic collection of potentially sensitive workplace communications and personal data. Because the skill is specifically designed to automate Slack access, the lack of privacy warnings, authorization checks, and data-scope limits makes misuse or over-collection materially more dangerous in this context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template explicitly instructs users to paste raw Slack snapshot output and JSON exports, and elsewhere includes message previews, participant names, channels, and screenshots. In the context of a Slack automation skill, this creates a substantial risk of collecting and persisting sensitive workplace data such as private messages, internal project details, credentials, or regulated information into reports that may be stored, shared, or sent outside Slack.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.