Agent skill

Slack

by magnus919 in magnus919/agent-skills

Operate Slack workspaces from a terminal or agent: list channels, read messages, follow threads, search message history, list files, and verify inbound webhook signatures — with a bundled slack-cli…

MITAuto-check passedBackend & APIs

Install Slack

skills CLI
$ npx skills add magnus919/agent-skills --skill slack -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills slack --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/slack .claude/skills/slack && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
slack
GitHub stars
115
Token cost
~2.4k tokens
SKILL.md length
1,046 words
Files
7 (incl. scripts, references)
Skills in repo
131
Repo updated
First seen
Licence
MIT

At a glance

Operate Slack workspaces from a terminal or agent: list channels, read messages, follow threads, search message history, list files, and verify inbound webhook signatures — with a bundled slack-cli…

  • Works in 5 steps: Read-only discovery before any mutation.… → Confirm the target, scope, and rollback… → Respect bounded reads. Slack paginates;… → …
  • An agent needs to read
  • SKILL.md covers Operating contract, The slack-cli script, Operating loop and Messages, channels, threads, plus 7 more sections
  • Runs Python scripts from its folder; needs SLACK_WEBHOOK_SECRET

What it does

Slack is an agent skill from magnus919/agent-skills. Operate Slack workspaces from a terminal or agent: list channels, read messages, follow threads, search message history, list files, and verify inbound webhook signatures — with a bundled slack-cli script that is read-only by default and gates every send behind a --dry-run/--yes confirmation. Use when an agent needs to read or post Slack data, triage incidents, or answer questions about what was said in a workspace. Do not use for building Slack apps or bots (that is application development) or workspace…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `README.md`, `evals/evals.json` and `references/00-source-index.md`). Compatibility notes: The bundled slack-cli script runs on Python 3.9+ with only the standard library. --help, channel/message/thread/search/file reads, and webhook signature…

It sits in Backend & APIs, covering Webhooks. It works with Slack. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • An agent needs to read
  • Post Slack data
  • Triage incidents
  • Answer questions about what was said in a workspace

Example prompts

  • “/slack”

Requirements

  • Python 3
  • A credential in SLACK_WEBHOOK_SECRET
  • Compatibility (from SKILL.md): The bundled slack-cli script runs on Python 3.9+ with only the standard library. --help, channel/message/thread/search/file reads, and webhook signature verification need no network; live reads require a Slack bot/user token with the right scopes and network access to api.slack.com.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read-only discovery before any mutation. List channels, read history, follow threads, search, and list files freely. The bundled slack-cli…
  2. Confirm the target, scope, and rollback path before acting. Sending a message or replying in a thread changes shared workspace state…
  3. Respect bounded reads. Slack paginates; never page past what the task needs. slack-cli --limit N caps every listing, and responses…
  4. Verify webhooks before trusting them. Any handler that accepts Slack events must verify X-Slack-Signature and X-Slack-Request-Timestamp…
  5. Keep evidence bounded. Quote short message excerpts and IDs; never paste full threads, tokens, or file contents into chat.

What it can do on your machine

Read from SKILL.md and the folder at commit 22b4723. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SLACK_WEBHOOK_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    The bundled slack-cli script runs on Python 3.9+ with only the standard library. --help, channel/message/thread/search/file reads, and webhook signature verification need no network; live reads require a Slack bot/user token with the right scopes and network access to api.slack.com.

    From compatibility in the SKILL.md frontmatter.

Context cost

Slack loads about 2.4k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 151 tokens; SKILL.md has 1,046 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit 22b4723, republished under its MIT licence (© magnus919). 1,046 words, ~2,384 tokens.

Download SKILL.mdSave it as .claude/skills/slack/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
slack
description
Operate Slack workspaces from a terminal or agent: list channels, read messages, follow threads, search message history, list files, and verify inbound webhook signatures — with a bundled slack-cli script that is read-only by default and gates every send behind a --dry-run/--yes confirmation. Use when an agent needs to read or post Slack data, triage incidents, or answer questions about what was said in a workspace. Do not use for building Slack apps or bots (that is application development) or workspace administration like user provisioning and org settings (that is the Slack admin console).
compatibility
The bundled slack-cli script runs on Python 3.9+ with only the standard library. --help, channel/message/thread/search/file reads, and webhook signature verification need no network; live reads require a Slack bot/user token with the right scopes and network access to api.slack.com.
license
MIT
metadata.source
https://api.slack.com/web
metadata.source_index
references/00-source-index.md
metadata.research_checked
2026-08-03

Slack Operations

Use this skill to read and, with explicit confirmation, write Slack data through the Slack Web API: channels, messages, threads, search, files, and webhook signature verification. This is a tool skill for the Slack platform. Building Slack apps and bots is application development; workspace administration (user provisioning, org-level settings, SSO) lives in the Slack admin console. This skill owns the everyday agent workflow: knowing what was said, finding it later, and posting a reply when a human confirms.

Operating contract

  1. Read-only discovery before any mutation. List channels, read history, follow threads, search, and list files freely. The bundled slack-cli script makes reads without writing anything.
  2. Confirm the target, scope, and rollback path before acting. Sending a message or replying in a thread changes shared workspace state visible to everyone: it requires an explicit human directive naming the channel, plus --dry-run preview and --yes confirmation through slack-cli. There is no "unsend" for team members who already read it.
  3. Respect bounded reads. Slack paginates; never page past what the task needs. slack-cli --limit N caps every listing, and responses summarize records rather than dumping raw payloads.
  4. Verify webhooks before trusting them. Any handler that accepts Slack events must verify X-Slack-Signature and X-Slack-Request-Timestamp against the app signing secret, or anyone who can reach the endpoint can forge events. slack-cli webhook verify does this check.
  5. Keep evidence bounded. Quote short message excerpts and IDs; never paste full threads, tokens, or file contents into chat.

The slack-cli script

scripts/slack-cli is an agent-first, stdlib-only CLI over the Slack Web API. It covers the full issue scope: messages, channels, threads, search, files, and webhook verification.

bash
slack/scripts/slack-cli --help                          # no token or network needed
slack/scripts/slack-cli --json --limit 10 channels list
slack/scripts/slack-cli --json messages list --channel C12345
slack/scripts/slack-cli --json threads list --channel C12345 --ts 1712345678.000001
slack/scripts/slack-cli --json search messages --query "incident"
slack/scripts/slack-cli --json files list --limit 5
slack/scripts/slack-cli messages send --channel C12345 --text "on it" --dry-run   # preview
slack/scripts/slack-cli messages send --channel C12345 --text "on it" --yes       # confirmed
slack/scripts/slack-cli webhook verify --body-file body.json --signature "v0=..." --timestamp 1712345678

Exit codes: 0 success, 1 API error or failed verification, 2 usage error. Sends are guarded: without --dry-run or --yes the script refuses with exit 1 and never calls the API. Reads are bounded by --limit (default 20, max 100).

Operating loop

  1. Scope the workspace surface: which channel(s) are relevant, what the question is (what was said, who said it, when), and whether any action is a mutation.
  2. Read with bounds: channels list to find IDs, messages list/threads list for history, search messages for cross-channel discovery. All read-only.
  3. Triage the answer: map the question to evidence (thread replies for context, search for the exact phrase, files list for shared artifacts).
  4. Act with confirmation: only a human directive to send, previewed with --dry-run and confirmed with --yes.
  5. Verify: confirm the posted message ts/channel in the response, or for webhooks confirm the signature check result before trusting the event.

Messages, channels, threads

  • Channels (conversations.list): public and private channels, archived state, member counts. Channel IDs (C...) are the stable key for every other call — resolve names to IDs before use.
  • Messages (conversations.history): newest-first history in a channel, one page at a time. Message records carry ts (the ID), user, and text. Use --cursor from the response metadata to page deliberately.
  • Threads (conversations.replies): replies keyed by the parent ts; the parent message is the first result. Thread replies keep thread_ts set to the parent.
  • Sending (chat.postMessage): the only mutation in this skill's surface. Always preview with --dry-run, confirm with --yes, and pass --thread-ts to reply in a thread instead of starting a new message. Verify the returned ts and channel.

Search and files

  • Search (search.messages): full-text search across visible history with Slack's search syntax (from:, in:, quoted phrases, before:/after:). Results include the matching channel; total tells you how many matches exist while matches stays bounded by --limit.
  • Files (files.list): files shared in the workspace, filterable by channel or user, with permalinks and sizes. Downloading file content is out of scope for the CLI (bounded reads); use it to find the file, then fetch the permalink with an authenticated request when a human asks for the content.
Show full SKILL.md (414 more words)Show less

Webhook verification

Slack signs every HTTP request to your event/command/interactivity endpoints. To verify:

  1. Take the raw request body (exactly as received — do not re-encode).
  2. Check X-Slack-Request-Timestamp is within ~5 minutes of now (replay protection).
  3. Compute v0=HMAC_SHA256(signing_secret, "v0:" + timestamp + ":" + body) and compare with X-Slack-Signature using a constant-time comparison.
  4. Reject with 401 if the timestamp is stale or the signature mismatches.

slack-cli webhook verify --body-file body.json --signature "v0=..." --timestamp <unix> runs exactly this check against SLACK_WEBHOOK_SECRET (or --secret) and reports a constant-time-verified result. Always verify before trusting event payloads — unverified webhook endpoints accept forged events.

Reference routing

Load whenReference
Sources, scope tables, refresh procedurereferences/00-source-index.md
API method surface, pagination, scopes, and webhook verification detailsreferences/01-web-api-operations.md

Included artifacts

  • scripts/slack-cli: bounded, stdlib-only CLI (messages, channels, threads, search, files, webhook verify; --json; --limit; send gated by --dry-run/--yes).
  • tests/test_slack_cli.py: 16 deterministic tests against a stub Slack API, including the mutation gate and the read-only contract.
  • references/: dated source index + web API operations reference.
  • evals/evals.json: six output-quality evaluation cases for agent runs.

Verification boundary

ClaimMinimum evidence
A channel exists and its nameslack-cli channels list --json returns it with its C... ID
A message was sentslack-cli messages send --yes returns the new ts and channel, and messages list shows it
A search found matchesslack-cli search messages --query "..." --json returns total_matches with bounded matches
A webhook is authenticslack-cli webhook verify exits 0 with verified: true for the exact body/signature/timestamp
A file existsslack-cli files list --json returns its F... ID and permalink

Hard boundaries

  • Never send a message or thread reply without a human directive, --dry-run preview, and --yes confirmation — Slack posts are public, durable, and unreadable-back.
  • Never trust an inbound webhook without signature and timestamp verification.
  • Never page reads past --limit; never dump full threads, tokens, or file contents into chat.
  • This skill operates the Slack Web API. It does not build Slack apps (application development), manage users/org settings (admin console), or cover alternative channels platforms (that is their own tooling).

When not to use

  • Building Slack apps or bots (Block Kit, Bolt, slash-command apps, OAuth flow design) — that is application development; see backend-engineering for service design.
  • Workspace administration (user provisioning, deprovisioning, org-level settings, SSO/SAML, data exports at the org level) — that is the Slack admin console, not the Web API.
  • Other team-chat platforms (Discord, Mattermost, Teams) — each has its own tooling; this skill covers Slack only.
  • Company-wide policy on messaging or channel governance — that is organizational policy, not an API operation.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in slack of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • references/00-source-index.md
  • references/01-web-api-operations.md
  • scripts/slack-cli
  • tests/test_slack_cli.py

Open the folder on GitHubat commit 22b4723

Compare with similar skills

Slack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Slack compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Slack this skillmagnus919/agent-skills115—~2.4kAutomated safety check: PassMIT
Channel Debug Corevercel-labs/vercel-openclaw-archived117—~2kAutomated safety check: NotesMIT
Frontmcp Channelsagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0
Add OAuth Integrationrome-os/rome743—~3.6kAutomated safety check: PassMIT
Chat SDK Botslobehub/lobehub83k—~1.5kAutomated safety check: PassCustom licence
Workspace APIfriday-platform/friday-studio104—~9.3kAutomated safety check: NotesCustom licence

Similar skills

  • Channel Debug Core

    vercel-labs/vercel-openclaw-archived

    Official

    Channel webhook triage for vercel-openclaw Slack/Telegram/Discord/WhatsApp issues: prove deployment state, collect admin readiness endpoints, build evidence-first handoff before fixes.

    117 GitHub stars~2k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Frontmcp Channels

    agentfront/frontmcp

    A skill your agent uses when pushing real-time notifications or events into Claude Code (or another MCP client) sessions, or building two-way chat bridges.

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Add a new Rome-managed OAuth integration for a third-party service so a user can delegate access by clicking Connect, and Rome can act on the service with the delegated token (the GitHub/Slack model…

    743 GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Chat SDK Bots

    lobehub/lobehub

    Builds chat bots once for Slack, Teams, Google Chat, Discord, GitHub and Linear with the Chat SDK, covering event handlers, cards, modals, streaming and state adapters.

    83k GitHub stars~1.5k tokensUpdated today
    Backend & APIsAuto-check passed
  • Workspace API

    friday-platform/friday-studio

    Create, list, update, delete, and clean up workspaces via the daemon HTTP API at $FRIDAYDURL.

    104 GitHub stars~9.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Watcher Creator

    asheshgoplani/agent-deck

    Guide for creating agent-deck watchers conversationally. An agent skill from asheshgoplani/agent-deck.

    1.1k GitHub stars~2.7k tokensUpdated today
    Backend & APIsAuto-check passed

More from magnus919/agent-skills

All 131 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    115 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    115 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    115 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    115 GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Slack

What does Slack do?

Operate Slack workspaces from a terminal or agent: list channels, read messages, follow threads, search message history, list files, and verify inbound webhook signatures — with a bundled slack-cli…. Slack is an agent skill from magnus919/agent-skills. Operate Slack workspaces from a terminal or agent: list channels, read messages, follow threads, search message history, list files, and verify inbound webhook signatures — with a bundled slack-cli script that is read-only by default and gates every send behind a --dry-run/--yes confirmation.

When should I use Slack?

Slack fits situations like: an agent needs to read; post Slack data; triage incidents; answer questions about what was said in a workspace.

How do I install Slack in Claude Code?

Run `npx skills add magnus919/agent-skills --skill slack -a claude-code`. Or copy the skill folder (slack in magnus919/agent-skills) into .claude/skills/slack in your project. Claude Code loads it when a task matches its description.

How do I install Slack in Codex?

Run `npx skills add magnus919/agent-skills --skill slack -a codex`. Or copy the skill folder (slack in magnus919/agent-skills) into .agents/skills/slack in your project. Codex loads it when a task matches its description.

Can I use Slack in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill slack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/slack, .gemini/skills/slack, .github/skills/slack and .opencode/skills/slack in your project.

What does Slack need to run?

Going by SKILL.md and its folder, Slack needs Python for the scripts in its folder and credentials named SLACK_WEBHOOK_SECRET. Our summary lists: Python 3; A credential in SLACK_WEBHOOK_SECRET. Compatibility (from SKILL.md): The bundled slack-cli script runs on Python 3.9+ with only the standard library. --help, channel/message/thread/search/file reads, and webhook signature verification need no network; live reads require a Slack bot/user token with the right scopes and network access to api.slack.com..

Does Slack access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Slack safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Slack use?

Slack is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Slack use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Slack?

Skills that share tags, products or a category with Slack: Channel Debug Core (vercel-labs/vercel-openclaw-archived, 117 stars), Frontmcp Channels (agentfront/frontmcp, 146 stars), Add OAuth Integration (rome-os/rome, 743 stars) and Chat SDK Bots (lobehub/lobehub, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Slack?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 115 GitHub stars. The repository holds 131 skills in this directory. The repository was last updated on October 10, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.