← Home

@mastra/slack

Slack integration for Mastra agents with app factory, OAuth, and slash commands

13
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

abhiaiyersmthomasrase-calcsamnikaiyertylerbarneswardpeet

Keywords

mastraslackchatbotaiagent

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/slack/src/client/services.gen.d.ts AI (source-diff): Auto-generated OpenAPI client typings, not obfuscation. ai
phantom-deps phantom-dep:ts-to-zod AI (phantom-deps): Used via codegen script gen:zod:schema, not a direct import. ai
source-diff obfuscated-file:src/client/services.gen.ts AI (source-diff): Auto-generated OpenAPI client code, long import lines only. ai
phantom-deps phantom-dep:easy-day-js AI (phantom-deps): Phantom-dep heuristic; easy-day-js may be used indirectly. Not independently disqualifying. ai
provenance missing-githead AI (provenance): SLSA provenance attestation compensates; GitHub Actions CI/CD publish flow for this package doesn't consistently set gitHead. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Mastra monorepo uses 0.0.0 as initial version for new packages; not a malware indicator. ai
phantom-deps phantom-dep:@chat-adapter/slack AI (phantom-deps): @chat-adapter/slack is a declared runtime dependency; phantom-dep heuristic is a false positive here. ai

Versions (showing 13 of 13)

Version Deps Published
1.5.1 1 / 6
1.5.0 1 / 6
1.4.0 1 / 6
1.3.2 1 / 6
1.3.0 1 / 6
1.2.1 1 / 6
1.2.0 1 / 6
1.1.1 1 / 6
1.1.0 1 / 6
1.0.2 4 / 14
1.0.1 4 / 14
1.0.0 2 / 15
0.0.0 1 / 6

v1.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.2

3 findings
HIGH New obfuscated file: dist/slack/src/client/services.gen.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/client/services.gen.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

3 findings
HIGH New obfuscated file: dist/slack/src/client/services.gen.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/client/services.gen.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.