Back to skill

Security audit

Slack Automator

Security checks for vulnerabilities and agentic risk

Overview

This Slack webhook skill is mostly purpose-aligned, but it has serious unsafe input handling and local data storage issues that users should review before installing.

Install only if you are comfortable reviewing or fixing the script first. Treat the Slack webhook URL as a password, restrict access to ~/.slack-automator, avoid storing sensitive messages in history/templates/schedules, and do not let untrusted text drive this skill's command arguments until the heredoc injection and template path traversal issues are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
<key> <value> local file="$1" key="$2" value="$3" python3 <<PYEOF import json try: with open("$file") as f: data = json.load(f) except Exception: data = {} data["$key"] = """$value""" with open("$file", "w") as f: json.dump(data, f, indent=2) PYEOF } _build_payload() { # Build JSON payload safely using python3 heredoc # Usage: _build_payload <text> [channel] local text="$1" local channel="${2:-}" python3 <<PYEOF import json, sys payload = {} payload["text"] = ...[truncated 3520 chars]:27
Finding

Arbitrary Python Code Execution Through Unquoted Heredoc Interpolation

Content
View full analysis
local file="$1" key="$2" value="$3" python3 < [channel] local text="$1" local channel="${2:-}" python3 < [channel] local action="$1" message="$2" status="$3" channel="${4:-}" python3 <
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/script.sh:350
Finding

Template Name Path Traversal Permits Arbitrary Text File Read and Write

Content
View full analysis
" echo "" echo "Example:" echo " slack-automator template save deploy \"🚀 Deployed *{{service}}* to production.\"" return 1 fi local name="$1" shift local message="$*" echo "$message" > "$TEMPLATES_DIR/${name}.txt" echo "✅ Template '$name' saved." _record_history "template-save" "Saved template: $name" "ok" ;; use) if [ $# -lt 1 ]; then echo "Usage: slack-automator template use [var=value ...]" echo "" echo "Example:" echo " slack-automator template use deploy service=api-server" return 1 fi local name="$1" shift local tpl_file="$TEMPLATES_DIR/${name}.txt" if [ ! -f "$tpl_file" ]; then echo "Error: Template '$name' not found." echo "Available templates:" cmd_template list return 1 fi local message message=$(cat "$tpl_file") ``` The retrieved content is subsequently transmitted: ```bash local payload payload=$(_build_payload "$message") echo "Sending template '$name'..." if _send_to_slack "$payload"; then echo "✅ Template message sent." _record_history "template-use" "$message" "ok" else echo "❌ Failed to send template message." _record_history "template-use" "$message" "failed" return 1 fi ``` ### Technical Analysis The template name is directly concatenated into a filesystem path without validation or canonical containment checks. A name containing `../` components can escape `~/.slack-automator/templates`. The `.txt` suffix limits direct traversal targets to names ending in `.txt`, but it does not eliminate the vulnerability. The `save` operation can overwrite writable ...[truncated 1374 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:9
Finding

Slack Webhook Credential and Message Data Are Created Without Restrictive Permissions

Content
View full analysis
"$CONFIG_FILE" [ -f "$HISTORY_FILE" ] || echo '[]' > "$HISTORY_FILE" [ -f "$SCHEDULE_FILE" ] || echo '[]' > "$SCHEDULE_FILE" } ``` The webhook bearer credential is then written to the configuration file: ```bash _json_set "$CONFIG_FILE" "webhook_url" "$url" echo "✅ Webhook URL saved." ``` ### Technical Analysis The script does not set a restrictive `umask`, request explicit directory modes, or enforce file permissions after creation. File and directory accessibility therefore depends on the caller's inherited `umask`. Under common permissive defaults, the data directory may be created as mode `0755` and JSON files as mode `0644`. This can make them readable by other local users. The configuration contains a Slack Incoming Webhook URL, which acts as a bearer credential. The history and schedule files can also contain potentially sensitive message content. Although webhook displays are partially masked in some commands, filesystem permission controls are still required because the complete URL remains in `config.json`. ### Attack Path 1. A user invokes the Skill under an environment with a permissive `umask`. 2. `_init` creates the application directory and JSON files without explicit restrictive modes. 3. Another local account checks the directory and file permissions. 4. If permissions permit, that account reads `config.json` and obtains the complete Slack webhook URL. 5. The local a ...[truncated 631 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documentation overstates functionality such as search, channel sync, chat monitoring, Block Kit support, and true scheduling, while the described implementation only covers basic webhook posting and local storage. Security-wise, behavior mismatches are dangerous because users may rely on controls or operational behavior that do not actually exist, causing unintended data exposure, missed monitoring, or unsafe deployment assumptions.

Content

No source excerpt is available for this finding.

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
#!/usr/bin/env bash
# Slack Automator — Send messages to Slack via Incoming Webhooks
# Powered by BytesAgain | bytesagain.com | hello@bytesagain.com
set -euo pipefail

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · scripts/script.sh (reported line 2)May include surrounding context.

sh
#!/usr/bin/env bash
# Slack Automator — Send messages to Slack via Incoming Webhooks
# Powered by BytesAgain | bytesagain.com | hello@bytesagain.com
set -euo pipefail

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · scripts/script.sh (reported line 716)May include surrounding context.

sh
#!/usr/bin/env bash
# Slack Automator — Send messages to Slack via Incoming Webhooks
# Powered by BytesAgain | bytesagain.com | hello@bytesagain.com
set -euo pipefail

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises behaviors that require shell, file read, and file write capabilities, but it does not declare any tool scope or permission boundaries. This creates an unsafe trust gap: an agent or user may invoke the skill without understanding that it can persist data locally and transmit content externally via shell-driven HTTP requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
### How to Get a Slack Webhook URL

1. Go to [https://api.slack.com/apps](https://api.slack.com/apps)
2. Click **Create New App** → **From scratch**
3. Name it (e.g., "Automator") and select your workspace
4. In the left sidebar, click **Incoming Webhooks**

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
### How to Get a Slack Webhook URL

1. Go to [https://api.slack.com/apps](https://api.slack.com/apps)
2. Click **Create New App** → **From scratch**
3. Name it (e.g., "Automator") and select your workspace
4. In the left sidebar, click **Incoming Webhooks**
5. Toggle **Activate Incoming Webhooks** to **On**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to store a full Slack Incoming Webhook URL locally in a config file, but does not prominently warn that the URL is a bearer secret that allows message posting to the workspace/channel. If the local file is exposed through weak permissions, backups, logs, or multi-user systems, an attacker could abuse the webhook for spam, phishing, or deceptive internal notifications.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill promotes retaining complete message history and exporting it, which can accumulate sensitive business content, alerts, channel targets, and user-supplied text over time. Persistent local storage increases the blast radius of host compromise, accidental sharing, or unauthorized access to the user's home directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The export feature writes message history to files without warning that those exports may contain sensitive message content, channels, timestamps, and operational metadata. Exported files are easy to copy, sync, or mishandle, which broadens exposure beyond the original Slack destination and local runtime context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes broader Slack automation capabilities including channel syncing, chat monitoring, search, and Block Kit usage. In this file, the implemented behavior is limited to sending simple webhook payloads containing text/channel fields plus local template/history/schedule management; there is no Slack API search, monitoring, channel synchronization, or Block Kit payload construction.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/script.sh (reported line 115)May include surrounding context.

sh
webhook_url=$(_get_webhook_url) || return 1

    local http_code
    http_code=$(curl -s -o /dev/null -w "%{http_code}" \
        -X POST \
        -H 'Content-type: application/json' \
        --data "$payload" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script persists the Slack webhook URL to disk in plaintext under the user's home directory without an explicit warning. Slack webhook URLs are bearer-style secrets; if the local account, backups, or dotfiles are exposed, an attacker can post arbitrary messages into the connected workspace/channel.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The top-level documentation presents a webhook-based sender, which implies a narrow integration model. However, the config command exposes settings like default_channel, username, and icon_emoji without any code path using them, creating intent/documentation drift about what the tool actually supports.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The schedule add command persists message text and schedule metadata into ~/.slack-automator/schedule.json. Although this is part of the feature, there is no user-facing disclosure near the command that scheduled message contents will remain stored on disk, which may matter if users place sensitive content in messages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The template save command writes the full message content to ~/.slack-automator/templates/.txt. The operation is user-initiated, but there is no disclosure that template text is being stored on disk and may later expose sensitive content if users save secrets in templates.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest frames the skill as Slack automation for messaging, channels, search, and notifications. The code also maintains local message history, computes usage statistics, and exports records to JSON/CSV/TXT files, which are additional data-management capabilities outside the described Slack operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The generic config setter can persist arbitrary values, including secrets, to a plaintext JSON file without warning. In the context of this tool, users are explicitly encouraged to store webhook-related settings, so undisclosed plaintext persistence materially increases the chance of credential leakage from local compromise, backups, or shared environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.