
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
@flinkhouse/server-slack
Advanced tools
MCP Server for the Slack API, enabling Claude to interact with Slack workspaces.
slack_list_channels
limit (number, default: 100, max: 200): Maximum number of channels to returncursor (string): Pagination cursor for next pageslack_post_message
channel_id (string): The ID of the channel to post totext (string): The message text to postslack_reply_to_thread
channel_id (string): The channel containing the threadthread_ts (string): Timestamp of the parent messagetext (string): The reply textslack_add_reaction
channel_id (string): The channel containing the messagetimestamp (string): Message timestamp to react toreaction (string): Emoji name without colonsslack_get_channel_history
channel_id (string): The channel IDlimit (number, default: 10): Number of messages to retrieveslack_get_thread_replies
channel_id (string): The channel containing the threadthread_ts (string): Timestamp of the parent messageslack_get_users
cursor (string): Pagination cursor for next pagelimit (number, default: 100, max: 200): Maximum users to returnslack_get_user_profile
user_id (string): The user's IDCreate a Slack App:
Configure Bot Token Scopes: Navigate to "OAuth & Permissions" and add these scopes:
channels:history - View messages and other content in public channelschannels:read - View basic channel informationchat:write - Send messages as the appreactions:write - Add emoji reactions to messagesusers:read - View users and their basic informationInstall App to Workspace:
xoxb-Get your Team ID (starts with a T) by following this guidance
Add the following to your claude_desktop_config.json:
{
"mcpServers": {
"slack": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-slack"
],
"env": {
"SLACK_BOT_TOKEN": "xoxb-your-bot-token",
"SLACK_TEAM_ID": "T01234567"
}
}
}
}
{
"mcpServers": {
"slack": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"SLACK_BOT_TOKEN",
"-e",
"SLACK_TEAM_ID",
"mcp/slack"
],
"env": {
"SLACK_BOT_TOKEN": "xoxb-your-bot-token",
"SLACK_TEAM_ID": "T01234567"
}
}
}
}
If you encounter permission errors, verify that:
Docker build:
docker build -t mcp/slack -f src/slack/Dockerfile .
This MCP server is licensed under the MIT License. This means you are free to use, modify, and distribute the software, subject to the terms and conditions of the MIT License. For more details, please see the LICENSE file in the project repository.
FAQs
MCP server for interacting with Slack
We found that @flinkhouse/server-slack demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.