Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Slack Api Automation

ASecurity

Automate Slack via its native Web API: bots, messages, workflows, and integrations without middleware. Use when building Slack-native automations with code you control.

2 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentsgoreactapisecurity

Works with

api

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill slack-api-automation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Slack Api Automation?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Slack Api Automation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-slack-api-automation/badge)](https://www.skillsdirectory.com/skills/aicodedecode-slack-api-automation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: slack-api-automation
description: Automate Slack via its native Web API: bots, messages, workflows, and integrations without middleware. Use when building Slack-native automations with code you control.
category: workflow-automation
---

# Slack API Automation

## Overview

Slack's Web API (plus Events API, Socket Mode, and Block Kit) lets you build bots, post messages, manage channels, and react to events — with code you own.

Use cases: deploy notifications, alert routing, ChatOps commands, onboarding flows, standup bots, and custom integrations.

This skill uses Slack's native APIs directly — no middleware platform required.

## When to use

- Posting automated messages and alerts to Slack
- Building a Slack bot (notifications, commands, interactivity)
- Reacting to Slack events (messages, reactions, joins)
- ChatOps: triggering actions from Slack commands
- Workspace administration via API (channels, users, invites)

## Core concepts

- **Web API basics.**
  chat.postMessage, conversations.*, users.*, files.upload — REST with bearer tokens. Block Kit for rich, interactive message layouts.
- **App tokens and scopes.**
  Slack apps with granular OAuth scopes (chat:write, channels:read...). Least privilege; separate dev/prod apps. Rotate tokens.
- **Events API + Socket Mode.**
  Subscribe to events (message, reaction_added, member_joined_channel). Socket Mode avoids public webhooks during development.
- **Slash commands.**
  Custom /commands triggering your service. Great for ChatOps: /deploy, /incident, /oncall. Fast to build, obvious to use.
- **Block Kit.**
  Structured message layouts: sections, buttons, selects, modals. Interactive workflows (approvals, forms) inside Slack.
- **Rate limits.**
  Tiered rate limits per method. Handle 429s with Retry-After; batch where possible; cache channel/user lists.
- **Bots vs. user tokens.**
  Bot tokens for app actions; user tokens only when acting as a user is required. Prefer bots — auditable and scoped.
- **Workflow Builder + webhooks.**
  For simple flows, native Workflow Builder with incoming webhooks covers a lot without code. Code when logic gets complex.

## Practical workflow

1. **Define the automation.**
   What event, what action, what message? Sketch the Block Kit layout for anything user-facing.
2. **Create the Slack app.**
   App manifest or dashboard: scopes (minimal), events subscribed, slash commands, interactivity URLs. Dev app first.
3. **Authenticate securely.**
   OAuth flow for distribution; bot tokens in secrets manager. Never hardcode tokens; never commit them.
4. **Build the handler.**
   Receive events/commands, validate signatures (signing secret — always verify), execute logic, respond with Block Kit.
5. **Handle rate limits.**
   Respect Retry-After on 429s; queue outbound messages; cache lookups. Test under burst conditions.
6. **Test in dev workspace.**
   Full flow in a test workspace/channel before touching production channels. Especially for broadcast-y automations.
7. **Deploy and monitor.**
   Hosted service with logging; alert on handler errors; Slack-side: monitor app metrics for failures.
8. **Document.**
   README: what it does, commands/events, scopes needed, owner, how to disable. Bots without docs become mysteries.

## Common pitfalls

- **Missing signature verification.**
  Accepting Events API payloads without verifying the signing secret. Spoofable endpoints are a security hole.
- **Overbroad scopes.**
  Requesting admin scopes 'just in case.' Least privilege; audit scopes yearly.
- **No rate limit handling.**
  Burst-posting into 429s and dropping messages. Queues + Retry-After respect are mandatory.
- **Hardcoded tokens.**
  Tokens in code, repos, or chat. Secrets manager + rotation; treat tokens like passwords.
- **Spammy bots.**
  Bots posting to #general for every minor event. Route to specific channels; respect notification norms; provide mute/opt-out.
- **Untested in prod-like.**
  Dev-tested only, then unleashed on 500-person channels. Test workspace first, always.
- **Ignoring interactivity timeouts.**
  Slash commands must respond in 3s (ack) or use response_url. Design for the timeout.
- **No off switch.**
  Bot misbehaving with no quick disable. Document how to disable; keep app admin access handy.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →