slack-mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited slack-mcp (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server that enables AI assistants to interact with Slack workspaces. This server provides a bridge between AI tools and Slack, allowing you to read messages, post content, and manage Slack channels programmatically through MCP-compatible clients.
This MCP server transforms your Slack workspace into an AI-accessible environment. It provides 21+ tools for comprehensive Slack interaction:
Message & Thread Operations
Channel Management
Reactions & Users
Utility
This repo ships as a Claude Code plugin with a guided setup skill. Claude will walk you through the entire process — no manual config editing required.
Run the setup script. It handles everything — venv, Playwright, token extraction, wrapper script, and Claude Code registration. The only interaction required is logging in to Slack when the browser opens, and entering an optional channel ID for server logs, if desired.
python3 <(curl -fsSL https://raw.githubusercontent.com/redhat-community-ai-tools/slack-mcp/main/scripts/setup-slack-mcp.py)Or clone the repo first and run it locally:
git clone https://github.com/redhat-community-ai-tools/slack-mcp
python3 slack-mcp/scripts/setup-slack-mcp.pyOptions:
| Flag | Description |
|---|---|
--logs-channel DXXXXXXXXX | Slack channel ID for server logs (optional; logs go to stderr if omitted) |
--workspace https://myco.slack.com | Specific Slack workspace to open |
--refresh-tokens | Re-extract tokens when they expire (skips all other steps) |
--skip-verify | Skip the post-setup smoke test |
When tokens expire, just run:
python3 slack-mcp/scripts/setup-slack-mcp.py --refresh-tokensIf you have the Slack desktop app installed, you can refresh tokens without opening a browser:
slack-mcp/scripts/slack-refresh-tokens --validateThis reads tokens directly from the desktop app's local storage on disk — no DevTools, no Playwright, no manual steps. Requires the Slack app to be signed in.
| Flag | Description |
|---|---|
--validate | Verify tokens against Slack's API after extraction |
--env | Print tokens as env vars to stdout (for piping into other tools) |
--output FILE | Write tokens to a custom path (default: ~/.local/share/slack-mcp/tokens.env) |
Requirements: python3, python3-cryptography, secret-tool (libsecret/gnome-keyring), curl, jq
This is useful for CI hooks or session startup scripts that need to silently refresh tokens before launching the MCP server.
For better security, use a Slack App bot token (xoxb-) instead of browser session tokens. Bot tokens provide:
channels:read, channels:history, channels:manage, groups:read, groups:history, groups:write, chat:write, reactions:read, reactions:write, search:read, users:read, commands, mpim:writexoxb-...)Set SLACK_BOT_TOKEN instead of SLACK_XOXC_TOKEN/SLACK_XOXD_TOKEN:
{
"mcpServers": {
"slack": {
"command": "podman",
"args": [
"run", "-i", "--rm",
"-e", "SLACK_BOT_TOKEN",
"-e", "LOGS_CHANNEL_ID",
"quay.io/redhat-ai-tools/slack-mcp"
],
"env": {
"SLACK_BOT_TOKEN": "xoxb-...",
"LOGS_CHANNEL_ID": "C7000000"
}
}
}
}LOGS_CHANNEL_ID is optional. When omitted, tool activity is written to stderr instead of posted to Slack.
If both SLACK_BOT_TOKEN and SLACK_XOXC_TOKEN/SLACK_XOXD_TOKEN are set, the bot token takes precedence.
For agents or automation that should browse and search Slack without posting, reacting, running commands, or joining channels, enable read-only mode.
SLACK_MCP_READ_ONLY to a truthy value (1, true, yes, or on, case-insensitive).--read-only when starting slack_mcp_server.py (equivalent to setting the variable).In read-only mode, tools that mutate Slack state (post_message, send_dm, post_command, add_reaction, join_channel) raise a clear error. Read tools (history, search, threads, whoami, channel listing, cache refresh helpers, and so on) behave as usual. Tool activity that would normally be mirrored to LOGS_CHANNEL_ID is written to stderr instead.
On startup, the server logs a line to stderr when read-only mode is active.
For Podman or Docker, add -e SLACK_MCP_READ_ONLY=true (and the matching key in env) when you want the container to run read-only.
You can run the slack-mcp server in a container using Podman or Docker:
Example configuration for running with Podman:
{
"mcpServers": {
"slack": {
"command": "podman",
"args": [
"run",
"-i",
"--rm",
"-e", "SLACK_XOXC_TOKEN",
"-e", "SLACK_XOXD_TOKEN",
"-e", "MCP_TRANSPORT",
"-e", "LOGS_CHANNEL_ID",
"quay.io/redhat-ai-tools/slack-mcp"
],
"env": {
"SLACK_XOXC_TOKEN": "xoxc-...",
"SLACK_XOXD_TOKEN": "xoxd-...",
"MCP_TRANSPORT": "stdio",
"LOGS_CHANNEL_ID": "C7000000"
}
}
}
}LOGS_CHANNEL_ID is optional. When omitted, tool activity is written to stderr instead of posted to Slack.
By default, tool activity is written to stderr (visible in your terminal or process logs). To mirror activity to a Slack channel instead, set LOGS_CHANNEL_ID to any channel the bot or session user has access to — a self-DM or a DM with Slackbot works well for personal use.
LOGS_CHANNEL_ID=C7000000In read-only mode, LOGS_CHANNEL_ID is ignored and all activity is always written to stderr.
To run the server with a non-stdio transport (such as SSE), set the MCP_TRANSPORT environment variable to a value other than stdio (e.g., sse).
Example configuration to connect to a non-stdio MCP server:
{
"mcpServers": {
"slack": {
"url": "https://slack-mcp.example.com/sse",
"headers": {
"X-Slack-Web-Token": "xoxc-...",
"X-Slack-Cookie-Token": "xoxd-..."
}
}
}
}Extract your Slack XOXC and XOXD tokens easily using browser extensions or Selenium automation: https://github.com/maorfr/slack-token-extractor.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.