New Your team’s decisions, in one playbook every coding agent works from. Never answer your agent twice

Slack

Official
REPOmodelcontextprotocol/server-slackNPM@modelcontextprotocol/server-slack
FRisk gradecritical blast radius
Last checked 112 days ago·seed·Watched hourly for changes
Auth postureNot probedno remote endpoint probed yet
Tools83 Write · 5 Read
Worst categoryWritegrade tracks the peak, not the average
Capability mix
Write 3Read 5
What it can reach
Ingests untrusted inputTouches secretsReaches networkRuns codeTouches filesChanges permissionsSends external commsPersistsDeletes dataMoves money
Exfiltration pathReads content an attacker can plant and can send data outward — a prompt-injection-to-exfiltration route.
Change history
No change history on record for this server. Watched servers surface a diff within the hour.
Recommended policy
Read-only toolsallow
Full policy breakdown with enforcement rules →

The upstream implementation is archived but remains widely installed. The classifications and policies here still apply to deployed copies.

This record as markdown: /tools/slack.md — append .md to any tool or server page.

DIRECT INSTALL npx -y @modelcontextprotocol/server-slack

Installed this way, nothing enforces the recommended policy above — calls run exactly as the agent makes them.

// LOOK UP ANOTHER SERVER

Every MCP server has a record like this.

Type a name, get the same breakdown: verified identity, auth posture, risk grade, capabilities, recommended policy.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.