Back to skill

Security audit

Slack Workspace Manager Free

Security checks across malware telemetry and agentic risk

Overview

This Slack manager is mostly coherent, but it asks for live Slack read/write access with broad activation language and unclear enforcement of confirmations before workspace-changing actions.

Review the Slack OAuth scopes carefully before installing. Use it only for explicit Slack management tasks, verify any message, file upload, channel change, reminder, update, or deletion before execution, and confirm how the underlying CLI stores and revokes OAuth tokens.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Low
Confidence
83% confidence
Finding
The skill promises that all write operations require user confirmation, but the provided command flows show direct execution without an explicit confirmation gate. In an agent context with exec enabled and real Slack write scopes, this mismatch can lead to unintended message posting, channel creation, or reminder creation if the agent follows examples literally.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger condition is overly broad for a skill that can read from and write to a live Slack workspace. Broad activation criteria increase the chance an agent invokes this skill for generic collaboration requests and performs unintended workspace actions or accesses Slack data when a safer non-tool response would suffice.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.