PromptArmor reports that instructions posted in a public Slack channel could be pulled into Slack AI answers for other users, enabling phishing links and leakage of data from private channels the attacker cannot read. The firm notes Slack's 2024-08-14 change to ingest files widened the surface, and that Slack described the underlying public-channel search as intended behavior.
Why it matters
Workplace assistants that search across permission boundaries can be turned against the users they serve.
Key facts
As stated in the sources, with where to find them.
- Slack expanded Slack AI to ingest files from channels and DMs on 2024-08-14, per PromptArmor.Section on file ingestion
- Slack's response to the report characterized public-channel visibility as intended behavior.Disclosure section
Findings that cite this record
No tracked finding cites this record yet.
Sources
Related records
Nov 20, 2025
Sep 25, 2025
Oct 8, 2025
Aug 20, 2025
Aug 6, 2025
Jul 8, 2025