Read and write Slack with session tokens — no OAuth, no bot, no admin approval.
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
SLACK_MCP_XOXC_TOKENAPI keyoptionalSlack session token. Optional — the auth-setup tool extracts it from your browser and stores it in the config file.
SLACK_MCP_XOXD_TOKENAPI keyoptionalSlack session cookie. Optional — the auth-setup tool extracts it from your browser and stores it in the config file.
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge read 1 source file from the published package tarball and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.
Read and write Slack with session tokens — no OAuth, no bot, no admin approval.