Back to skill

Security audit

Slack Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This Slack skill is mostly coherent, but it asks for message-reading and deletion authority without clear safeguards and has trigger wording that extends beyond Slack.

Review the Slack scopes before installing. Use the narrowest Bot Token scopes needed, avoid granting history/delete permissions unless necessary, and require explicit confirmation before deleting, editing, exporting, or reading sensitive workspace messages. Treat the broad email/SMS trigger text as out of scope for this Slack-only skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger conditions are overly broad and include unrelated communication tasks like email/SMS/communication integration, which can cause the skill to activate outside its intended Slack-only scope. In an agent environment, ambiguous activation increases the chance of unintended Slack actions such as sending, reading, editing, or deleting messages based on loosely related user prompts.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill advertises message deletion and message reading without prominent warnings, consent checks, or privacy guidance, even though these operations can expose private workplace communications or destroy records. In a tool-enabled agent, lack of safeguards makes accidental or socially engineered misuse more likely, especially for read/export behavior and irreversible deletions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.