Slack Hub Skill

Security checks across malware telemetry and agentic risk

Overview

This Slack skill mostly matches its stated purpose, but it can search workspace content, post messages, and list private channel metadata under a bot token with limited user-control safeguards.

Install only if you are comfortable giving the skill a Slack bot token that can act in your workspace. Use the narrowest Slack scopes possible, avoid tokens with unnecessary private-channel or broad search access, and require users or workflows to confirm destination, message text, and search intent before invoking it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
75% confidence
Finding
The skill exposes search and channel-listing capabilities over a workspace using the ambient bot token without any access control, approval prompt, or auditing. In an agent-skill context, this increases the risk of unauthorized reconnaissance and bulk access to workspace metadata or message content if the skill is invoked by an untrusted workflow or overly broad user request.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal