logo

Claude Code + Slack: How an AI Agent Integration Becomes a Compromise Path

ID: 192208ff-2c72-58d9-9b3f-816be86ed3d3

STIX ID: report--192208ff-2c72-58d9-9b3f-816be86ed3d3

Feed Name: Mitiga

Threat Score
70/100

Date Published: 2026-07-16

Date Updated: 2026-07-29

...
...

This report demonstrates a proof-of-concept attack where a malicious Claude Code "skill" is used to hijack a trusted Slack integration, send phishing links across channels and DMs, and potentially behave like an AI-driven worm that exfiltrates data and propagates through connected integrations. The write-up covers skill manipulation techniques (guidelines, Definition of Done, fallback behavior), an execution timeline, detection gaps (Slack audit logs, EDR/SIEM limitations), and practical defenses including logging, least-privilege MCP scopes, human review policies, and sandboxing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.