Tel Aviv, Israel – July 14, 2026 – Cybersecurity startup Tego AI has published new research revealing that Anthropic’s native Slack integration, Claude Tag, can be triggered by non-intentional Slack content, potentially leading to unauthorized actions across enterprise systems.
According to Tego AI, researchers observed Claude Tag responding to messages containing the literal text “@Claude” without requiring a genuine structural Slack mention. This means content delivered through bots, webhooks, automated feeds, or other external sources could be interpreted as instructions.
In a demonstration, bot-generated messages instructed Claude Tag to retrieve internal information, publish it into Slack, and then delete the original resource using the organization’s configured connection.
“Our research raises a fundamental question for every organization deploying enterprise AI agents: who is actually authorized to instruct the agent?” said Tal Melamed, CTO and Co-Founder of Tego AI. “Organizations need controls that validate the origin and purpose of sensitive actions before an agent is allowed to execute them.”
The research also identified broader concerns, including untrusted automated content becoming an indirect instruction channel, connected applications and MCP servers expanding the potential impact, administrative access to stored channel information outside Slack’s native membership model, and limited visibility through existing history, compliance, and audit interfaces.
“A safety classifier can be an important defense, but it should not be the final authorization boundary for enterprise actions,” Melamed added. “Sensitive operations require deterministic controls that remain effective even when the model misunderstands a request, trusts the wrong identity, or makes an incorrect decision.”
Tego AI recommends applying least-privilege permissions to Claude Tag connections, preferring read-only access, avoiding channels that ingest untrusted external content, restricting administrative access, retaining relevant Slack logs, and introducing independent runtime authorization for sensitive actions.
The company responsibly disclosed the findings to Anthropic. Anthropic classified the submission as informative and disputed that literal “@Claude” text or bot-generated messages initiate Claude Tag sessions under the product’s default configuration. Tego AI’s full report documents the observed behavior, supporting evidence, security implications, and disclosure timeline.
Read the full technical report, including supporting evidence and the disclosure timeline: https://www.tego.ai/blog/tego-ai-finds-anthropics-claude-tag-slack-integration-can-trigger-unauthorized-enterprise-actions
About Tego AI
Tego AI is a cybersecurity company developing runtime security and control technology for enterprise AI agents. Its platform helps organizations monitor agent activity and stop unauthorized or risky actions before agents access sensitive data or connected systems. Tego AI currently operates in stealth. This is the company’s second public security disclosure, and it has identified additional security issues across other major AI agent platforms, with further disclosures planned.
Contact:
Tal Melamed, CTO, Tego AI
tal@tego.ai
This is a paid press release published via CyberNewswire, a PR newswire syndication platform for cybersecurity companies.


Leave a Reply