Slack LLM Agent Bot with Safe Function Calling Prompt
Design a Slack bot backed by an LLM that uses tool/function calling to run real operational actions, with guardrails, confirmation steps, and scoped permissions.
- Target user
- Engineers building an AI agent that takes actions from Slack
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are an applied-AI engineer who has shipped LLM agents into Slack that can query systems and trigger actions without becoming a confused-deputy or a prompt-injection victim. I will provide: - The model/provider and SDK in use - The set of operational actions the agent should be able to take (read and write) - Who can invoke the bot and in which channels - Our risk tolerance for autonomous (no-confirm) actions Your job: 1. **Tool design** — define each callable function with a strict JSON schema, a clear description, and an explicit risk tier (read-only / reversible-write / destructive). Show how to split one fuzzy tool into several narrow, auditable ones. 2. **Trigger surface** — @-mention, slash command, or message in a designated channel; capture `user.id`, `channel.id`, `thread_ts` and thread the entire conversation so context (and audit) stays in one place. 3. **Permission mapping** — map the Slack user to an internal identity and authorize each tool call against THAT identity's RBAC, not the bot's powers. The bot must never let a user do via the LLM what they can't do directly. 4. **Confirmation flow** — for any write/destructive tool, the model proposes, the bot renders a Block Kit confirmation with the exact parameters, and only an explicit button click executes. No model-only execution of destructive actions. 5. **Prompt-injection defense** — treat message text, fetched docs, and tool outputs as untrusted; never let retrieved content silently change which tool runs or escalate scope; strip/escape control instructions. 6. **Rate, cost & loop control** — cap tool-call iterations per request, cap tokens/cost per user per day, and detect runaway tool loops. 7. **Observability** — log every prompt, tool call, parameters, and result with a trace ID; redact secrets; surface a `/agent audit` view. Output: (a) tool registry with schemas + risk tiers, (b) the agent loop pseudocode with authorization + confirmation gates, (c) Block Kit confirmation card, (d) prompt-injection test cases, (e) cost/loop guardrail config. Bias toward: human-in-the-loop for writes, per-user RBAC over bot omnipotence, and treating all text as untrusted.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Slack LLM Bot Conversation Memory & Context Design Prompt
Design how a Slack AI bot tracks conversation state across threads, channels, and DMs — what to remember, how to scope it, when to forget, and how to keep context windows small without losing relevance.
-
Slack AI Assistant App with assistant.threads API Prompt
Design a native Slack AI assistant using the assistant.threads surface — suggested prompts, status indicators, threaded context, and a streaming LLM backend that respects channel permissions.
-
Slack AI Thread Summarization & Channel Digest Prompt
Build an AI-powered summarizer that condenses long Slack threads and busy channels into actionable digests with decisions, action items, and owners — without leaking sensitive context to the model.
-
Slack App Cold-Start & 3-Second Ack Latency Optimization Prompt
Diagnose and fix Slack app latency that breaks the 3-second ack budget — serverless cold starts, sync work in handlers, and defer-then-followup patterns.
More Slack prompts & error guides
Browse every Slack prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.