Back to skill

Security audit

Slack

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed Slack MCP connector, with expected Slack token use and write capability, but users should note the unpinned mcporter install dependency.

Install only if you are comfortable giving the agent Slack access under the configured OAuth grant. Use the least-privileged Slack authorization available, review messages or canvas edits before sending, revoke the Slack grant when done, and prefer a pinned or integrity-controlled mcporter install path if your environment supports it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Executable npm Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13–19
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

yaml
install:
  - id: node
    kind: node
    package: mcporter
    bins:
      - mcporter
    label: Install mcporter (node)

Technical Analysis

The installation metadata specifies the executable npm package mcporter without an exact version or integrity constraint. Consequently, installation may resolve to a mutable future package release that was not represented by the audited project files.

Although SKILL.md links to documentation for mcporter version v0.11.1, that documentation link does not constrain dependency resolution. The installed package could therefore differ from the reviewed version. Because mcporter is executed as part of the skill and receives access to the configured Slack bearer token, compromise of its package, publisher account, or dependency chain could result in arbitrary code execution under the installer or agent runtime account.

Attack Path

  1. An attacker compromises the mcporter npm package, its publisher account, or a transitive dependency used by a newly published release.
  2. The attacker publishes a malicious or backdoored package version.
  3. A user installs this skill after that release becomes the version selected by npm.
  4. The unpinned package declaration resolves to and installs the attacker-controlled release.
  5. Malicious lifecycle or runtime code executes with the privileges of the installation or agent process.
  6. The code may access MAVERICK_SLACK_MCP_ACCESS_TOKEN, other environment variables, local data available to that process, and the network.
  7. The stolen Slack token may be used within the permissions of its OAuth grant to access or alter Slack workspace data.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user or service acco ...[truncated 458 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin mcporter to an audited exact version rather than using an unconstrained package name, for example mcporter@0.11.1 if that version has been reviewed and is compatible.
  • Use a lockfile and verify package integrity hashes where the skill installation mechanism supports them.
  • Install dependencies from the expected npm registry through an approved, integrity-enforcing package pipeline.
  • Disable npm lifecycle scripts unless they are explicitly required and have been reviewed.
  • Review both direct and transitive dependencies before upgrading the pinned version.
  • Run the client with least privilege and expose only the environment variables required for operation.
  • Restrict outbound network access to approved endpoints where practical.
  • Rotate and revoke the Slack token promptly if dependency compromise is suspected.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
This skill expects `MAVERICK_SLACK_MCP_ACCESS_TOKEN` to be set in the agent runtime environment. mcporter sends it as `Authorization: Bearer <value>` on every request.

Slack uses a long-lived, non-rotating OAuth access token when token rotation is off for the app. If calls fail with auth errors, the token is invalid, revoked, or no longer covers the requested scopes - reconnect Slack and re-set `MAVERICK_SLACK_MCP_ACCESS_TOKEN`. There is no automatic refresh; bearer tokens are static.

Reconnect Slack if the grant is revoked, the app is uninstalled from the workspace, the granting user is deactivated, or Slack scopes change and require a new grant.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

The output includes the server's Instructions: field, if published, and a JSON Schema for every tool's parameters. Treat this as the authoritative reference for the rest of the session.

Step 2 - Call any tool from the catalog using the form maverick-slack-mcp.<tool>:

sh
mcporter --config {baseDir}/mcporter.json call maverick-slack-mcp.<tool> <arg>=<value> ...

Static analysis

No suspicious patterns detected.