# slack_reply_to_thread

Reply to a specific message thread in Slack

Agent View of the PolicyLayer registry record for `slack_reply_to_thread`. HTML page: https://policylayer.com/tools/slack/slack-reply-to-thread

## Facts

- Tool: `slack_reply_to_thread`
- Server: Slack (`@modelcontextprotocol/server-slack`) — https://policylayer.com/tools/slack.md
- Install: `npx -y @modelcontextprotocol/server-slack`
- Homepage: https://github.com/modelcontextprotocol/server-slack
- Risk category: Write (Medium risk)
- Registry record: grade F, identity verified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "slack_reply_to_thread",
    "arguments": {}
  }
}
```

## Why slack_reply_to_thread is rated Medium

The tool creates new data (a message) in Slack, which is reversible (messages can be edited or deleted). This is a Write category operation. Severity is medium because while message creation has limited blast radius compared to destructive operations, an AI agent could spam threads, post inappropriate content, or disrupt team communication at scale.

From the tool's own definition: "Tool description states it 'Reply to a specific message thread in Slack', which creates/adds a new message to Slack."

## Use case

AI agents use slack_reply_to_thread to create or update resources in Slack, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Slack environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Slack:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "slack_reply_to_thread": {
      "limits": [
        {
          "counter": "slack_reply_to_thread_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Slack (7)

- `slack_get_channel_history` — Read — https://policylayer.com/tools/slack/slack-get-channel-history.md
- `slack_get_thread_replies` — Read — https://policylayer.com/tools/slack/slack-get-thread-replies.md
- `slack_get_user_profile` — Read — https://policylayer.com/tools/slack/slack-get-user-profile.md
- `slack_get_users` — Read — https://policylayer.com/tools/slack/slack-get-users.md
- `slack_list_channels` — Read — https://policylayer.com/tools/slack/slack-list-channels.md
- `slack_add_reaction` — Write — https://policylayer.com/tools/slack/slack-add-reaction.md
- `slack_post_message` — Write — https://policylayer.com/tools/slack/slack-post-message.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=slack · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/slack
