Anthropic’s Claude Tag Slack integration vulnerable to bot‑triggered actions
Cybersecurity firm Tego AI, based in Tel Aviv, disclosed a security weakness in Anthropic’s Claude Tag, the native Slack integration for the Claude AI model. The research showed that messages containing the literal text “@Claude” can activate Claude Tag without a proper Slack mention, allowing bot‑generated content, webhooks or other automated feeds to issue instructions to the AI.
In a proof‑of‑concept, Tego AI demonstrated that a bot‑generated message could cause Claude Tag to retrieve internal information, post it in Slack, and then delete the original resource via the organization’s configured connection. The findings raise concerns about untrusted content acting as an indirect instruction channel, expanded impact through connected applications, and limited visibility in Slack’s compliance logs.
Tego AI recommends applying least‑privilege permissions to Claude Tag connections, using read‑only access, avoiding channels that ingest untrusted content, restricting administrative access, retaining relevant logs, and adding independent runtime authorization for sensitive actions. Anthropic classified the disclosure as informative and disputed that the default configuration would trigger sessions from literal “@Claude” messages.
Tal Melamed, CTO and Co‑Founder of Tego AI, said, “Our research raises a fundamental question for every organization deploying enterprise AI agents: who is actually authorized to instruct the agent?”