Better Auth Security Best Practices
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
A skill your agent uses when a developer asks which Slack Web API method does something, needs a method's OAuth scopes or token type, wants to call or test a family.method endpoint…
$ npx skills add slackapi/slack-skills-plugin --skill slack-api -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install slackapi/slack-skills-plugin slack-api --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/slackapi/slack-skills-plugin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/slack-api .claude/skills/slack-api && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "slack-api" agent skill from https://github.com/slackapi/slack-skills-plugin/tree/main/skills/slack-api into .claude/skills/slack-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "slack-api", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/slackapi/slack-skills-plugin/tree/main/skills/slack-apiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add slackapi/slack-skills-plugin --skill slack-api -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install slackapi/slack-skills-plugin slack-api --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/slackapi/slack-skills-plugin.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/slack-api .agents/skills/slack-api && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "slack-api" agent skill from https://github.com/slackapi/slack-skills-plugin/tree/main/skills/slack-api into .agents/skills/slack-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "slack-api", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add slackapi/slack-skills-plugin --skill slack-api -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install slackapi/slack-skills-plugin slack-api --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/slackapi/slack-skills-plugin.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/slack-api .cursor/skills/slack-api && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "slack-api" agent skill from https://github.com/slackapi/slack-skills-plugin/tree/main/skills/slack-api into .cursor/skills/slack-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "slack-api", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/slackapi/slack-skills-plugin.git --path skills/slack-api--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add slackapi/slack-skills-plugin --skill slack-api -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install slackapi/slack-skills-plugin slack-api --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/slackapi/slack-skills-plugin.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/slack-api .gemini/skills/slack-api && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "slack-api" agent skill from https://github.com/slackapi/slack-skills-plugin/tree/main/skills/slack-api into .gemini/skills/slack-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "slack-api", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install slackapi/slack-skills-plugin slack-apiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add slackapi/slack-skills-plugin --skill slack-api -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/slackapi/slack-skills-plugin.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/slack-api .github/skills/slack-api && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "slack-api" agent skill from https://github.com/slackapi/slack-skills-plugin/tree/main/skills/slack-api into .github/skills/slack-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "slack-api", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add slackapi/slack-skills-plugin --skill slack-api -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install slackapi/slack-skills-plugin slack-api --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/slackapi/slack-skills-plugin.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/slack-api .opencode/skills/slack-api && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "slack-api" agent skill from https://github.com/slackapi/slack-skills-plugin/tree/main/skills/slack-api into .opencode/skills/slack-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "slack-api", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
slack-apiA skill your agent uses when a developer asks which Slack Web API method does something, needs a method's OAuth scopes or token type, wants to call or test a family.method endpoint…
Slack API is an agent skill from slackapi/slack-skills-plugin, published by the product's own GitHub organization. Use when a developer asks which Slack Web API method does something, needs a method's OAuth scopes or token type, wants to call or test a family.method endpoint (chat.postMessage, conversations.history, users.info, views.open), is handling cursor pagination (nextcursor) or rate limits (tier/ratelimited/Retry-After), or is debugging errors like missingscope, invalidauth, or channelnotfound. Also trigger on a pasted slack.com/api/ URL or docs.slack.dev/reference/methods link.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Rate limiting and OAuth and OpenID Connect. It works with Slack. The repository describes itself as: Claude Code, Codex, Cursor, and npx skills plugin that enables your AI tools with a Slack MCP Server and Slack Developer Skills. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 64c3f33. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
docs.slack.devslack.comapi.slack.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Slack API loads about 3.3k tokens when it runs. Until then it costs about 123 tokens; SKILL.md has 1,671 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from slackapi/slack-skills-plugin at commit 64c3f33, republished under its MIT licence (© slackapi). 1,671 words, ~3,297 tokens.
.claude/skills/slack-api/SKILL.md (or your agent's skills folder).Help the developer discover the right Web API method, read its contract, and call it correctly. Slack exposes hundreds of methods named in family.method dot notation (e.g. chat.postMessage, conversations.history) at https://slack.com/api/<method>. Every method's doc page follows a fixed URL pattern, so the contract for any method is always one fetch away.
If $0 is provided, it is either a full method.name (jump to Step 2 to read its contract) or a family name (go to Step 1 and find it in the index).
Critical rules:
- Verify a method name and its required scopes against its doc page before calling it — never invent method names or guess scopes. Method names use
family.methoddot notation.- Every response has a top-level
okboolean. Always checkokbefore using the result; onok: false, read theerrorstring.- Method names, scopes, rate tiers, and arguments come from the live doc page (
https://docs.slack.dev/reference/methods/<method-lowercased>.md). The docs are the source of truth — discover from the live index, read the contract from the method's own page.
DO NOT rules:
- DO NOT assume a method is GET — many are POST. Check the doc page.
- DO NOT hardcode bearer tokens into committed code or share them in plain text.
- DO NOT use deprecated methods (
files.upload,dialog.open,rtm.*,oauth.access,search.*,stars.*,reminders.*) without checking the replacement — a deprecated method's own doc page names what supersedes it; prefer the replacement for new apps.- DO NOT paginate by incrementing a page number — Slack uses opaque cursors (see Step 5).
Execution posture — run reads, confirm writes:
- Read-only methods (
*.list,*.info,*.history,conversations.members,auth.test, etc.) may be run directly to help the developer.- State-changing or destructive methods (
chat.postMessage/update/delete, any*.delete/*.remove/*.kick/*.archive, and alladmin.*) — prepare the exact command and confirm with the developer before running it.
If the developer already knows the method — they named it, pasted a https://slack.com/api/<method> URL or a docs.slack.dev/reference/methods/<method> link, or gave a family.method — skip discovery:
Full-workflow indicators (start at Step 1):
Map the developer's intent to a family, then to a candidate method.
WebFetch the live method index:
https://docs.slack.dev/reference/methods.mdIt lists every Web API method in family.method notation with a one-line description and a link to that method's own doc page. It is complete and always current — scan it for a candidate, then follow the method's link into Step 2 to read the contract (the index has descriptions only; rate tier, scopes, token type, and pagination all live on the per-method page).
Never publish or call a method name you have not seen on a live page.
When you would rather search by keyword than scan the index, and the Slack CLI is available, use the slack:slack-cli skill — Step 3: Searching Documentation (slack docs search) — to query Slack's docs from the terminal. That step covers the command and flags; results will point you to the method's reference page, which you then read in Step 2. Without the CLI, WebFetch the index (https://docs.slack.dev/reference/methods.md) and scan it instead.
Fetch the method's doc page with WebFetch. Either follow the method's link from the index (Step 1) or construct the URL — the path segment is all-lowercase and ends in .md:
https://docs.slack.dev/reference/methods/<method-lowercased>.mdFor example, conversations.members → https://docs.slack.dev/reference/methods/conversations.members.md, and chat.postMessage → https://docs.slack.dev/reference/methods/chat.postmessage.md. When in doubt about casing, follow the index link rather than building the URL by hand.
Every method page documents, consistently:
https://slack.com/api/<method>xoxb- vs user xoxp-)Extract the required arguments and required scopes before calling. For what these cross-cutting concepts mean in general — beyond what the method page states — the canonical references are: the response envelope, POST bodies, and auth at https://docs.slack.dev/apis/web-api.md; pagination at https://docs.slack.dev/apis/web-api/pagination.md; and rate-limit tiers at https://docs.slack.dev/apis/web-api/rate-limits.md.
Calling any non-public method requires a token with the right scopes and type. This skill's job here is to determine, from the contract you read in Step 2, which token type and scopes the method needs — independent of how you ultimately send the token.
From the contract you read in Step 2:
xoxb-, xoxp-, xapp-) is and when to use it, see https://docs.slack.dev/authentication/tokens.md.missing_scope, the response's needed and provided fields name the gap — add the needed scope to the app manifest and reinstall the app.admin.* methods require an Enterprise Grid org-level token.A couple of methods need no auth: api.test (connectivity), auth.test (validates whatever token you do send) and blocks.validate.
You need a token only when the method requires one. There are two ways to get one — pick whichever fits the developer's setup. The Slack CLI is optional: if the developer does not have it and prefers not to install it, take Path B rather than forcing an install.
The CLI supplies an authenticated session, so once the developer is logged in you can call methods without handling a token yourself (Step 4, "Via the Slack CLI").
Use the slack:slack-cli skill — Step 1: Detect the Slack CLI — to check whether the public Slack CLI is installed and resolve its command name. That step also proposes installing the CLI when it is absent. The fingerprint check, alias fallback, and install instructions all live there; do not duplicate them here.
Once resolved, use the detected command name for all CLI commands in this skill. We refer to it as SLACK_CMD — substitute the actual resolved command name everywhere you see SLACK_CMD.
Use the slack:slack-cli skill — Step 5: Authentication (slack auth) — to check the developer's login state and, if needed, walk them through slack login. Authentication mechanics live there.
You do not need the CLI to call a method. Get a token of the type you determined above from the app's OAuth & Permissions page in the Slack app config (https://api.slack.com/apps → your app → OAuth & Permissions → OAuth Tokens): the Bot User OAuth Token (xoxb-…) or the User OAuth Token (xoxp-…). That page also lists the scopes currently granted — confirm the ones from Step 2 are present. Then send that token with curl or an SDK in Step 4 ("Via raw HTTP" / "Via an SDK").
First apply the execution posture: if the method changes state (post/update/delete/archive/kick, or any admin.*), show the developer the exact command and get a yes before running it. Read-only calls can be run directly.
To call a method from the terminal, use the slack:slack-cli skill — Step 4: Calling Web API Methods (slack api). That step covers the SLACK_CMD api <method> key=value … syntax so that it is not repeated here. Pass the required arguments you gathered from the method's doc page in Step 2.
The CLI uses the developer's authenticated session, so it is the simplest path once they are logged in (Step 3).
Use the Bash tool when the developer wants a raw request or isn't using the CLI. Send the token in the Authorization header — the bot or user token from Step 3 (Path B, or the CLI session).
Form-encoded (the default for most methods):
curl -s -X POST 'https://slack.com/api/conversations.list' \
-H 'Authorization: Bearer xoxb-YOUR-TOKEN' \
-d 'types=public_channel&limit=200'JSON body (for methods taking complex arguments like blocks, view, attachments, metadata):
curl -s -X POST 'https://slack.com/api/chat.postMessage' \
-H 'Authorization: Bearer xoxb-YOUR-TOKEN' \
-H 'Content-Type: application/json' \
-d '{"channel":"C0123456789","text":"Hello from the API"}'Check the method's page for which content type it expects. With form encoding, a structured argument is passed as a JSON-encoded string value (e.g. blocks=[...]).
In Bolt and the Slack SDKs, each method is a client function whose arguments match the doc page's argument table:
await client.chat.postMessage({ channel, text, blocks })client.chat_postMessage(channel=channel, text=text, blocks=blocks)(Note the JS dot form chat.postMessage vs the Python underscore form chat_postMessage.) To construct the blocks/view payload these calls take, use the slack:block-kit skill — this skill treats that payload as an opaque argument and focuses on the method call around it.
Methods that return collections use cursor pagination, not page numbers. A method's doc page states whether it paginates, and the full list of cursor-paginated methods is under Methods supporting cursor-based pagination at https://docs.slack.dev/apis/web-api/pagination.md:
limit (page size — check the method's max).response_metadata.next_cursor from the response.cursor=<next_cursor>.next_cursor comes back empty.# First page
curl -s -X POST 'https://slack.com/api/conversations.history' \
-H 'Authorization: Bearer xoxb-YOUR-TOKEN' \
-d 'channel=C0123456789&limit=200'
# Next page — pass the cursor from response_metadata.next_cursor
curl -s -X POST 'https://slack.com/api/conversations.history' \
-H 'Authorization: Bearer xoxb-YOUR-TOKEN' \
-d 'channel=C0123456789&limit=200&cursor=dXNlcjpVMDYxTkZUVDI='Cursors are opaque — never construct, parse, or reuse an old one.
When ok is false, branch on the error string:
not_authed, invalid_auth, missing_scope, channel_not_found, and invalid_arguments.ok, error, warning, response_metadata), see Evaluating responses at https://docs.slack.dev/apis/web-api.md.response_metadata.messages often pinpoints a malformed argument.Rate limits: on HTTP 429 / error: "ratelimited", honor the Retry-After response header (seconds) — wait, then retry. Do not retry in a tight loop. Each method's tier (1–4 or special) caps calls per minute; the tier table is at https://docs.slack.dev/apis/web-api/rate-limits.md, and newer non-Marketplace apps face stricter caps on some methods, so trust the method's own page for the exact number.
slackLists.* prefix — a bare lists.* name does not exist.slack:slack-cli; Block Kit payloads to slack:block-kit.© slackapi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/slack-api of slackapi/slack-skills-plugin.
Open the folder on GitHubat commit 64c3f33
Slack API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Slack API this skillslackapi/slack-skills-plugin | 144 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| Socialite Developmenthexlet-volunteers/hexlet-sicp | 114 | 5 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Add Channel Connect Buttonnovuhq/novu | 40k | — | ~1.6k | Automated safety check: Pass | Custom licence | |
| Frappe Core APIImpertio-Studio/Frappe_Claude_Skill_Package | 187 | 1 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package | 187 | 1 repos | ~4k | Automated safety check: Pass | MIT |
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
hexlet-volunteers/hexlet-sicp
Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.
novuhq/novu
Build a new channel Connect button (e.g. An agent skill from novuhq/novu.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.
rome-os/rome
Add a new Rome-managed OAuth integration for a third-party service so a user can delegate access by clicking Connect, and Rome can act on the service with the delegated token (the GitHub/Slack model…
slackapi/slack-skills-plugin
A skill your agent uses when a developer wants to build or validate Block Kit layouts for Slack messages, modals, or Home tabs: message layouts, modals/forms/dialogs, Home tab interfaces…
slackapi/slack-skills-plugin
A skill your agent uses when a developer wants to create, scaffold, or bootstrap a new Slack app or agent from scratch with the Slack CLI.
slackapi/slack-skills-plugin
A skill your agent uses when answering a conceptual or how-to question about Slack platform features, or when asked to look up, fetch, or summarize a docs.slack.dev page, including a pasted…
slackapi/slack-skills-plugin
A skill your agent uses when writing, drafting, scheduling, or improving a Slack message, announcement, or reply sent via the Slack MCP tools (slacksendmessage, slacksendmessagedraft…
slackapi/slack-skills-plugin
A skill your agent uses when locating messages, files, channels, or people across Slack, or gathering context before answering, with the search MCP tools (slacksearchpublic…
slackapi/slack-skills-plugin
A skill your agent uses when a developer wants to test, try out, smoke-test, verify, or confirm that a Slack app built with the Slack CLI (or a plain Bolt app) actually works, by running it in a…
Works with
Categories
A skill your agent uses when a developer asks which Slack Web API method does something, needs a method's OAuth scopes or token type, wants to call or test a family.method endpoint…. Slack API is an agent skill from slackapi/slack-skills-plugin, published by the product's own GitHub organization.open), is handling cursor pagination (nextcursor) or rate limits (tier/ratelimited/Retry-After), or is debugging errors like missingscope, invalidauth, or channelnotfound.
Slack API fits situations like: A developer asks which Slack Web API method does something; needs a methods OAuth scopes; test a family.method endpoint (chat.postMessage; conversations.history.
Run `npx skills add slackapi/slack-skills-plugin --skill slack-api -a claude-code`. Or copy the skill folder (skills/slack-api in slackapi/slack-skills-plugin) into .claude/skills/slack-api in your project. Claude Code loads it when a task matches its description.
Run `npx skills add slackapi/slack-skills-plugin --skill slack-api -a codex`. Or copy the skill folder (skills/slack-api in slackapi/slack-skills-plugin) into .agents/skills/slack-api in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add slackapi/slack-skills-plugin --skill slack-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/slack-api, .gemini/skills/slack-api, .github/skills/slack-api and .opencode/skills/slack-api in your project.
Going by SKILL.md and its folder, Slack API needs the command-line tools its instructions call (curl). Our summary lists: Python 3.
SKILL.md names 3 domains. In commands or code: docs.slack.dev, slack.com and api.slack.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Slack API is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Slack API: Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), Socialite Development (hexlet-volunteers/hexlet-sicp, 114 stars), Add Channel Connect Button (novuhq/novu, 40k stars) and Frappe Core API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
slackapi (a GitHub organization, an official publisher) maintains it in slackapi/slack-skills-plugin, which has 144 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 6, 2026.
Source: slackapi/slack-skills-plugin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.