Security audit
Slack
Security checks across malware telemetry and agentic risk
Overview
This Slack skill clearly describes a managed Slack API integration and includes appropriate user approval and credential-handling safeguards.
Before installing, understand that this skill can access and modify Slack data through a connected account. Use OAuth where possible, connect only the needed workspace/account, verify the target connection before writes, and require explicit confirmation before messages, channel changes, file operations, or deletions.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
