Latest release: v2026.7.1Download zip
Compatibility
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Purpose and capability are coherent: artifacts disclose Slack channels, DMs, commands, app events, and tool actions such as send, read, edit, delete, react, pin, file handling, emoji listing, and member info.
Instruction Scope
The bundled skill gives direct Slack tool usage examples and includes a safety note to confirm unclear destructive deletes; the high-impact actions are visible rather than hidden.
Install Mechanism
Package metadata identifies @openclaw/slack as an official, trusted OpenClaw plugin with source-linked release context; package.json has no install scripts or binaries.
Credentials
Slack bot/app/user tokens and Slack network access are expected for this integration; channel allowlists, DM policy, user-token read-only mode, and action gates provide scoping controls.
Persistence & Privilege
No OS-level persistence or privilege escalation was found; the plugin uses OpenClaw runtime state for Slack delivery/thread dedupe and can perform disclosed config migration when configWrites is enabled.
Scan Findings in Context
[SkillSpector] expected: SkillSpector reported a clean scan with no issues; artifact review did not find contradictory malicious behavior.
[VirusTotal] expected: VirusTotal telemetry was clean, with no malicious or suspicious engine detections.
[unicode-control-chars] expected: The Unicode control-character signal matched zero-width joiners in emoji mappings, not hidden instructions or obfuscation.
Assessment
Install only in Slack workspaces where you are comfortable giving the configured bot/app token the listed Slack scopes. Keep tokens in OpenClaw secrets or environment variables, prefer bot tokens over user tokens, keep userTokenReadOnly enabled unless needed, restrict allowed channels/DM users, and be deliberate before enabling message delete/edit/pin actions or Slack-based exec approvals.Verification
Tags
OpenClaw Slack
Official OpenClaw channel plugin for Slack channels, DMs, commands, and app events.
Install from OpenClaw:
openclaw plugin add @openclaw/slack
Configure the Slack app credentials and allowed workspaces/channels in OpenClaw. The plugin lets agents receive Slack events and reply through the configured Slack app.
