Back to skill

Security audit

Slack

Security checks for vulnerabilities and agentic risk

Overview

This Slack skill clearly documents Slack bot actions and does not show hidden code, installation behavior, persistence, or unrelated data handling.

Install only if you want Clawdbot to act in Slack with its configured bot permissions. Be careful with send, edit, delete, pin, and unpin actions because they can affect shared channels, and request member info only when it is needed for the task.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill exposes memberInfo retrieval without any privacy or data-minimization guidance. This can encourage unnecessary lookup or disclosure of user profile information, especially if the agent is induced to enumerate users or reveal metadata that was not required for the task.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill exposes memberInfo retrieval without any privacy or data-minimization guidance. This can encourage unnecessary lookup or disclosure of user profile information, especially if the agent is induced to enumerate users or reveal metadata that was not required for the task.

Static analysis

No suspicious patterns detected.