Back to skill

Security audit

Slack Workspace Manager

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly about Slack administration, but its broad routing language and unrelated scoring-style interface are too ambiguous for a tool that advertises high-impact workspace changes.

Install only if you are a Slack workspace or Enterprise Grid administrator and intend to use it for explicit admin tasks. Review each requested action before execution, use least-privilege Slack tokens, require dry-run and confirmation for bulk or destructive changes, and avoid routing ordinary project-management or review tasks to this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The documented input/output contract describes a generic scoring or review workflow rather than Slack workspace administration, which is a strong sign the skill's declared behavior does not match its actual interface. In an agent setting, this kind of semantic mismatch can cause the model or operator to invoke the skill under the wrong assumptions, leading to unintended execution paths, misuse of privileged Slack operations, or incorrect handling of sensitive enterprise data.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The top-level description says the skill should be used for project management, task planning, and team collaboration rather than narrowly scoped Slack administration. That broad and misleading positioning increases the chance that an agent routes arbitrary business tasks into a skill that has exec, write, and administrative Slack capabilities, creating unnecessary exposure to privileged actions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
An overly broad invocation phrase tied to common project-management needs makes the skill much easier to trigger unintentionally in normal conversation. Because this skill advertises administrative and bulk-operation capabilities, loose routing language can expand the attack surface by causing accidental selection for requests unrelated to Slack administration.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The markdown lists destructive or high-impact Slack operations such as deleting Canvas documents, ending calls, bulk archiving, and membership changes without consistently attaching upfront confirmation, dry-run, or authorization requirements at the point those actions are introduced. In a skill that may be agent-invoked, insufficient warning and gating can lead to accidental destructive actions in a live enterprise workspace.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.