slack-messaging

slack-messaging is a skill for Claude Code, Codex from pekral/cursor-rules. It costs 28 tokens per session (1,438 once invoked), scanned C, original, MIT.

Use when you need to send messages to a Slack channel or read recent messages from a channel via the Slack Web API.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/pekral/cursor-rules/slack-messaging
Any agent
npx skills add pekral/cursor-rules --skill slack-messaging
Clone the repo
git clone --depth 1 https://github.com/pekral/cursor-rules

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for slack-messaging

README.md
[![agentmods](https://agentmods.dev/badge/skills/pekral/cursor-rules/slack-messaging.svg)](https://agentmods.dev/skills/pekral/cursor-rules/slack-messaging)
Your own site
<a href="https://agentmods.dev/skills/pekral/cursor-rules/slack-messaging"><img src="https://agentmods.dev/badge/skills/pekral/cursor-rules/slack-messaging.svg" alt="Measured on agentmods" height="20"></a>
Per session 28 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,438 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 2 findings. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00028 $0.01438
Opus 5 $0.00014 $0.00719
Sonnet 5 $0.00006 $0.00288
Haiku 4.5 $0.00003 $0.00144

Measured today against content hash b47f47621fca, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

slack-messaging scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

The scan reads SKILL.md. This mod also ships 3 executable files (scripts/_lib.sh, scripts/read.sh, scripts/send.sh), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Downloads and executes remote codehighSupply chain

curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.

- No silent download-and-execute (`curl … | sh`).

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- TLS is never disabled — no `curl -k`, no `--insecure`, no `verify=false`.
skills/slack-messaging/SKILL.md · 153 lines

How it starts

The opening of the file, as written. The whole thing — 153 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Slack Messaging

Purpose

Send and read Slack messages programmatically via the Slack Web API. Two deterministic shell scripts backed by a shared helper library:

  • send.sh — post a message to a channel via chat.postMessage
  • read.sh — fetch recent messages from a channel via conversations.history and emit them as stable JSON

Credentials are read exclusively from the SLACK_BOT_TOKEN environment variable. The token is never written to a file, never appears in script output or logs, and is never committed to the repository.


Constraints

  • Token only from env var SLACK_BOT_TOKEN. Never from a file, never echoed.
  • TLS is never disabled — no curl -k, no --insecure, no verify=false.
  • No silent download-and-execute (curl … | sh).
  • Errors on network/security operations are always surfaced — no 2>/dev/null on calls whose result matters, no empty catch.
  • set -euo pipefail in every script.
  • Exit-code contract: 0 success; 1 usage/argument error; 2 missing tool (curl/jq) or missing SLACK_BOT_TOKEN; 3 API failure (HTTP non-2xx, network error, or Slack ok:false).

Setup — co a kam vložit

1. Vytvoř Slack App

  1. Přejdi na https://api.slack.com/apps a klikni Create New AppFrom scratch.

  2. Vyber workspace a pojmenuj appku (např. messaging-bot).

  3. V sekci OAuth & PermissionsBot Token Scopes přidej scopy:

    Scope Použití
    chat:write odesílání zpráv (send.sh)
    channels:history čtení zpráv z veřejných kanálů (read.sh)
    channels:read přístup k metadatům veřejných kanálů
    groups:history čtení zpráv z privátních kanálů (read.sh)
  4. Klikni Install to Workspace a potvrď oprávnění.

  5. Zkopíruj Bot User OAuth Token (začíná xoxb-…) z OAuth & Permissions.

2. Bezpečné nastavení tokenu

Nastav token jako env var — NIKDY ho necommituj do repa, NIKDY ho nevkládej do .env souboru sledovaného Gitem:

# shell profil (mimo repo) — ~/.zshrc nebo ~/.bash_profile
export SLACK_BOT_TOKEN=xoxb-...

# CI secret (GitHub Actions):
# Settings → Secrets → New repository secret → Name: SLACK_BOT_TOKEN
# V workflow: env: SLACK_BOT_TOKEN: ${{ secrets.SLACK_BOT_TOKEN }}

Read the full file on GitHub · 153 lines

Files

What ships with it

3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today First seen · 153 lines · 28 tokens per session scan C b47f47621fca

Subscribe to this mod's changes

slack-messaging is a skill published in the GitHub repository pekral/cursor-rules (6 stars, last pushed 3d ago), licensed MIT. It adds 28 tokens to every session and 1,438 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it C with 2 findings (downloads and executes remote code, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

browse-and-evaluate

Use when exploring the ai-agent-skills catalog to find, compare, and evaluate skills before installing. Always use --fields to limit output size and --dry-run before committing to an install.

MoizIbnYousaf/Ai-Agent-Skills · 43 tokens

loop-engineering

Shared loop-engineering reference for COG skills - the agent loop, deterministic verifiers, termination conditions, in-loop context management, and named patterns. Invoke when designing or debugging a skill that iterates (search-verify-retry, scan-until-dry, fetch-retry-gate).

huytieu/COG-second-brain · 63 tokens

render-airdrop-carousel

Assemble a viral iOS "AirDrop" notification-carousel video ad (≈6–8s, 9:16) from a brand line plus 6–16 real product photos — a native AirDrop share-sheet card ("Brand would like to share a · Decline / Accept") springs up and its preview window CYCLES through the products, landing on a range/lineup payoff with an…

gooseworks-ai/goose-skills · 207 tokens

render-3d-product-showcase

Assemble a premium 3D product-showcase ad from a config — four beat clips (an orbiting hero rotation, a macro push-in, a physics reveal, a typographic close) normalized to the brand-color canvas, hard-concatenated in order, closed on a deterministic Playwright brand end card, and mixed under one instrumental bed at…

gooseworks-ai/goose-skills · 159 tokens

vfx-text-cursor

Cursor light trail, chromatic rays, and directional flares for word-by-word quote reveals in video intros.

nexu-io/html-video · 28 tokens

music

Generate, remix, extend, edit, and analyze AI music (Mureka). Triggers on: "音乐", "music", "生成音乐", "generate music", "翻唱", "cover", "混音", "remix", "续写", "extend", "纯音乐", "instrumental", "配乐", "soundtrack", "分轨", "stem", "识别歌词", "recognize lyrics", "作曲", "compose", "create a song", "做一首歌".

marswaveai/skills · 109 tokens