Slack Mcp Claude Auth — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Slack Mcp Claude Auth (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Local stdio MCP proxy for the official Slack MCP endpoint.
Intended to be used with the Pi Coding Agent and the pi-mcp-adapter extension installed. Only for MacOS. It uses Claude's official Slack plugin for authorisation flow so one doesn't need to create its own Slack application with its own client ID.
At first launch and if refresh token is expired, an authorisation to the officila Slack plugin is needed via the Claude CLI. No Slack tokens are stored or shared anywhere. If token is refreshed, it's stored into the same keychain record like it would be done via official Claude's Slack plugin.
npm install
npm run buildAdd to ~/.pi/agent/mcp.json:
{
"mcpServers": {
"slack": {
"command": "node",
"args": ["/Users/k.babaev/Sources/_index-only/slack-mcp-claude-auth/dist/index.js"],
"lifecycle": "lazy"
}
}
}Then reload Pi and refresh metadata:
/reload
/mcp reconnect slackIf direct tools are disabled, use proxy:
mcp({ server: "slack" })
mcp({ search: "slack thread" })
mcp({ tool: "slack_read_thread", args: "{...}" })The wrapper implements MCP tools/list by calling official Slack MCP tools/list. Tool schemas, descriptions, and names come from Slack, not from this repo.
Tool list cache:
SLACK_MCP_TOOL_LIST_CACHE_MS=86400000)~/.cache/slack-mcp-claude-auth/tools.jsonSLACK_MCP_TOOL_LIST_CACHE_MS=0 to disable wrapper cacheTool names:
slack_search_users, slack_read_thread, etc.pi-mcp-adapter also prefixes tools with server name slack_slack_ prefix before exposing tools, so Pi names become slack_search_users, not slack_slack_search_usersSLACK_MCP_STRIP_REDUNDANT_TOOL_PREFIX=0If pi-mcp-adapter direct tools are enabled, adapter may also cache metadata; run /mcp reconnect slack and /reload after Slack changes tools or after changing prefix behavior.
Credentials are read from macOS Keychain item:
Claude Code-credentialsmcpOAuth["plugin:slack:slack|38801a7d845718b3"]Defaults match current Claude Code Slack MCP auth:
SLACK_MCP_CLIENT_ID=1601185624273.8899143856786
SLACK_MCP_CLAUDE_CRED_KEY=plugin:slack:slack|38801a7d845718b3
SLACK_MCP_URL=https://mcp.slack.com/mcpOn token refresh, wrapper writes refreshed access/refresh token back into the same Claude Code keychain JSON by default. Disable with:
SLACK_MCP_WRITEBACK=0Slack token refresh HTTP 400: invalid_grantClaude Code keychain refresh token is stale/invalid. Re-authorize Slack in Claude Code CLI, then retry /mcp reconnect slack in Pi.
| Variable | Default |
|---|---|
SLACK_MCP_URL | https://mcp.slack.com/mcp |
SLACK_TOKEN_ENDPOINT | https://slack.com/api/oauth.v2.user.access |
SLACK_MCP_CLIENT_ID | Claude Code Slack client id |
SLACK_MCP_CLAUDE_CRED_KEY | Claude Code Slack MCP credential key |
SLACK_MCP_KEYCHAIN_SERVICE | Claude Code-credentials |
SLACK_MCP_KEYCHAIN_ACCOUNT | current macOS username |
SLACK_MCP_REFRESH_BUFFER_MS | 300000 |
SLACK_MCP_SESSION_TTL_MS | 79200000 |
SLACK_MCP_TOOL_LIST_CACHE_MS | 86400000 |
SLACK_MCP_TOOL_LIST_CACHE_PATH | ~/.cache/slack-mcp-claude-auth/tools.json |
SLACK_MCP_STRIP_REDUNDANT_TOOL_PREFIX | 1 |
SLACK_MCP_WRITEBACK | 1 |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.