Slack (archived)
Server metadata is temporarily withheld while this grade is under governance review.
Automated danger grade: this page reports detected or inferred risk from a scan. It is not an endorsement, certification, or claim that the server is malicious.
Low transparency: this server declares few or no tool behavior annotations, so the danger score is inferred from defaults. Treat as cannot verify safe — not necessarily dangerous.
Grade withheld: this entry's grade is temporarily withheld while the registry completes provenance verification and governance review of its published grades. The scan metadata above stays disclosed, and the dispute channel below remains open; the grade returns when review completes, with any change recorded in the corrections log.
Grade history
13 scans on record between 2026-07-03 and 2026-07-04. The grade has not changed across them.
| Scanned (UTC) | Grade | Engine | Attributed cause |
|---|---|---|---|
| 2026-07-03 02:46 | withheld | mcpaudit 2.1.0 | First scan on record |
| 2026-07-03 02:50 | withheld | mcpaudit 2.1.0 | No change |
| 2026-07-03 09:44 | withheld | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:00 | withheld | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:01 | withheld | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:12 | withheld | mcpaudit 2.3.0 | No change |
| 2026-07-03 10:16 | withheld | mcpaudit 2.3.0 | No change |
| 2026-07-03 12:42 | withheld | mcpaudit 2.3.0 | No change |
| 2026-07-03 13:20 | withheld | mcpaudit 2.4.0 | No change |
| 2026-07-03 14:13 | withheld | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:13 | withheld | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:16 | withheld | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:18 | withheld | mcpaudit 2.4.0 | No change |
History as recorded by this registry's own scans. The cause is an attribution from the inputs the registry records — the scanner engine identity and the declared tool surface — not proof of what changed on the server. Generated 2026-08-02.
How to read this grade
- What was scanned: @modelcontextprotocol/server-slack@2025.4.25, as distributed.
- When: 2026-07-04 08:18:06.
- By what: mcpaudit 2.4.0, applied to the published danger rubric (weights, bands, and the critical cap are all public).
- What the grade means: this registry's opinion, computed by the disclosed automated methodology against the artifact version above, on the scan date above. It measures conformance to the rubric at scan time.
- What it does not claim: it is not a statement that the product is malicious, insecure in your deployment, or unfit for use, and it is not an endorsement or certification.
- Disagree? Grades are re-checkable against the same package version, and corrections are welcome: open a dispute — see the dispute & correction policy.
Spec-shift exposure
Withheld while this entry is under review. Spec-shift exposure is server-specific metadata, so it is held back with the rest — this says nothing about whether the server is exposed.
Provenance & dispute
- Listing basis: operator-listed from a public catalog. This entry was not submitted by its vendor.
- Scan target: the published npm artifact
@modelcontextprotocol/server-slack@2025.4.25, installed and scanned locally using sandbox imagemcp-trust-scan:corpus-2026-07-03. The public record stores the sandbox image, but not the network mode, so this page does not claim network isolation for that run. - Credentials: this server declares required environment variables (
SLACK_BOT_TOKEN,SLACK_TEAM_ID). Scans never use real credentials; at most inert placeholder values are used for scan execution. - Dispute: vendor or maintainer of this server? Dispute this grade — first response within 14 days.
Add this badge to your README
Copy the Markdown below only if you want to link readers to the latest danger grade and scan caveats:
[](https://mcp-trust.vercel.app/ui/servers/mcp-archived-slack)
Findings
Finding detail is withheld while this entry's grade is under governance review.