@modelcontextprotocol/server-slack
MCP server for interacting with Slack
Installing this server brings 15 third-party packages inside your agent's trust boundary (1 direct). This is attack surface, not a vulnerability count — it does not affect the grade above.
Findings (2)
- HIGH
DEPRECATED— @modelcontextprotocol/server-slack is marked deprecated on npm. Deprecated packages receive no security fixes. Migrate. - LOW
NO_REPO— @modelcontextprotocol/server-slack has no linked source repository. Unverifiable source. Prefer packages with a public repo.
Embed this badge
[](https://vulnrable.com/mcp/modelcontextprotocol--server-slack/) Automated registry-metadata scan; not a code audit. Rescanned on each site deploy.