SlackBLOCK
A Slack MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A MCP(Model Context Protocol) server for accessing Slack API. This server allows AI assistants to interact with the Slack API through a standardized interface.
Transport Support
This server supports both traditional and modern MCP transport methods:
- Stdio Transport (default): Process-based communication for local integration
- Streamable HTTP Transport: HTTP-based communication for web applications and remote clients
Features
Available tools:
slack_list_channels- List public channels in the workspace with paginationslack_post_message- Post a new message to a Slack channelslack_reply_to_thread- Reply to a specific message thread in Slackslack_add_reaction- Add a reaction emoji to a messageslack_get_channel_history- Get recent messages from a channelslack_get_thread_replies- Get all replies in a message threadslack_get_users- Retrieve basic profile information of all users in the workspaceslack_get_user_profiles- Get multiple users' profile information in bulk (efficient for batch operations)slack_search_messages- Search for messages in the workspace with powerful filters:- Basic query search
- Location filters:
in_channel - User filters:
from_user,with - Date filters:
before(YYYY-MM-DD),after(YYYY-MM-DD),on(YYYY-MM-DD),during(e.g., "July", "2023") - Content filters:
has(emoji reactions),is(saved/thread) - Sorting options by relevance score or timestamp
Quick Start
Installation
npm install @ubie-oss/slack-mcp-server
NOTE: Its now hosted in GitHub Registry so you need your PAT.
Configuration
You need to set the following environment variables:
SLACK_BOT_TOKEN: Slack Bot User OAuth TokenSLACK_USER_TOKEN: Slack User OAuth Token (required for some features like message search)SLACK_SAFE_SEARCH(optional): When set totrue, automatically
fed758e6db47OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add slack-mcp-server --env EXMAPLES_SLACK_BOT_TOKEN=${EXMAPLES_SLACK_BOT_TOKEN} --env EXMAPLES_SLACK_USER_TOKEN=${EXMAPLES_SLACK_USER_TOKEN} --env SLACK_BOT_TOKEN=${SLACK_BOT_TOKEN} --env SLACK_USER_TOKEN=${SLACK_USER_TOKEN} -- npx -y @ubie-oss/[email protected]{
"mcpServers": {
"slack-mcp-server": {
"command": "npx",
"args": [
"-y",
"@ubie-oss/[email protected]"
],
"env": {
"EXMAPLES_SLACK_BOT_TOKEN": "${EXMAPLES_SLACK_BOT_TOKEN}",
"EXMAPLES_SLACK_USER_TOKEN": "${EXMAPLES_SLACK_USER_TOKEN}",
"SLACK_BOT_TOKEN": "${SLACK_BOT_TOKEN}",
"SLACK_USER_TOKEN": "${SLACK_USER_TOKEN}"
}
}
}
}Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
slack_add_reaction | write | Add a reaction emoji to a message |
slack_get_thread_replies | read | Get all replies in a message thread |
slack_get_user_profiles | read | Get multiple users profile information in bulk |
slack_get_users | read | Retrieve basic profile information of all users in the workspace |
slack_list_channels | read | List public channels in the workspace with pagination |
slack_post_message | write | Post a new message to a Slack channel |
slack_reply_to_thread | read | Reply to a specific message thread in Slack |
slack_search_channels | read | Search for channels by partial name match. Use this when you need to find channels containing specific keywords in their names. Returns up to the specified limit of matching channels. |
slack_search_users | read | Search for users by partial name match across username, display name, and real name. Use this when you need to find users containing specific keywords in their names. Returns up to the specified limit of matching users. |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (8)
EXMAPLES_SLACK_BOT_TOKEN=xoxb-your-slack-token-here
EXMAPLES_SLACK_USER_TOKEN=xoxp-your-slack-token-here
SLACK_BOT_TOKEN=xoxb-your-bot-token
SLACK_USER_TOKEN=xoxp-your-user-token
SLACK_BOT_TOKEN=xoxb-your-bot-token
.env.sample
.node-version
@modelcontextprotocol/sdk, @slack/web-api, @types/node, dotenv, express, typescript, zod, zod-to-json-schema
Gates applied: critical_finding, no_behavioural_pass.
fed758e6db47full audit observations/trust-audit/mcp-server/ubie-oss__slack-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | fed758e6db47 | BLOCK | D | 66 | first audit |
Questions
What is the Slack MCP server?
A Slack MCP server
What tools does Slack expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Slack safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Slack need?
It reads EXMAPLES_SLACK_BOT_TOKEN, EXMAPLES_SLACK_USER_TOKEN, SLACK_BOT_TOKEN and SLACK_USER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Slack run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @ubie-oss/slack-mcp-server at 0.1.4.
How current is this page?
The grade is for one exact copy of the source (fed758e6db47), read on 2026-10-07. The repository is watched and re-audited when it changes.