Skip to content
Back to skills

Slack App Stinger

ASecurity

Build Slack apps with Bolt. Use for slash commands, Block Kit, modals, Events API, OAuth installs, or Marketplace submission. Read README.md for the guide map.

  • 85 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 9, 2026
developmentpythongojavaexpressfastapidjangoapibackenddevopssecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 27, 2026

npx -y skills add legioncodeinc/vibe-coding-tools --skill slack-app-stinger --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Slack App Stinger?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Slack App Stinger
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/legioncodeinc-slack-app-stinger/badge)](https://www.skillsdirectory.com/skills/legioncodeinc-slack-app-stinger)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "slack-app-stinger"
license: AGPL-3.0-or-later
description: "Build Slack apps with Bolt. Use for slash commands, Block Kit, modals, Events API, OAuth installs, or Marketplace submission. Read README.md for the guide map."
---

# slack-app-stinger

Start with [README.md](README.md) for the workflow map and detailed references.

The Slack developer playbook for `slack-app-wasp-drone`. Encodes opinionated, research-backed patterns for every major Slack app surface: from first Bolt app scaffold to Marketplace submission.

## Quick navigation

| Task | Guide |
|---|---|
| Create a new Slack app, pick HTTP vs Socket Mode | `guides/00-setup-and-bolt.md` |
| Add a slash command | `guides/01-slash-commands.md` |
| Build Block Kit messages and interactive components | `guides/02-block-kit.md` |
| Open / push / update modals | `guides/03-modals.md` |
| Subscribe to events, verify webhooks | `guides/04-events-api.md` |
| Multi-workspace OAuth install flow | `guides/05-oauth-install.md` |
| Submit to App Directory / Marketplace | `guides/06-app-directory.md` |

## Critical directives

These are the non-negotiables. Violating any of them is the most common cause of production Slack app failures. See the relevant guide for code patterns.

1. **Acknowledge Slack payloads within 3 seconds, then dispatch async for long-running work.** Slack retries unacknowledged payloads up to 3 times and flags unreliable apps. This applies to slash commands, interactive component actions, and Events API deliveries equally. Source: `research/external/2026-05-20-events-api-verification.md`, `research/external/2026-05-20-slash-commands-interactive.md`.

2. **Verify Slack request signatures before processing any payload.** Bolt does this automatically. Custom HTTP handlers (Express, FastAPI routes) must implement HMAC-SHA256 verification manually using the app's signing secret. Source: `research/external/2026-05-20-events-api-verification.md`.

3. **Never store Slack tokens in plaintext config files or committed environment variables.** Bot tokens (`xoxb-`) and signing secrets go in an environment variable manager or secrets vault. Source: `research/external/2026-05-20-bolt-sdk-setup-patterns.md`.

4. **Always validate the `state` parameter in OAuth callbacks.** Bolt auto-generates and validates `state` via `stateSecret`. Bypassing this validation is a CSRF vulnerability that allows workspace installation hijacking. Source: `research/external/2026-05-20-oauth-multi-workspace.md`.

5. **Deduplicate Events API payloads using `event_id` before processing.** Slack delivers events at-least-once. Store the `event_id` (Redis SETNX, DB unique constraint) and discard duplicates. Source: `research/external/2026-05-20-events-api-verification.md`.

6. **If the app will be distributed commercially at scale, use HTTP mode and plan for Marketplace submission from the start.** Socket Mode apps cannot be listed in the Slack Marketplace. Apps intended for commercial distribution must go through Marketplace review (December 2024 policy update). Source: `research/external/2026-05-20-socket-mode-vs-http.md`, `research/external/2026-05-20-dev-policy-update.md`.

7. **Never use Slack data to train LLMs.** This is an explicit, absolute prohibition in the December 2024 Slack App Developer Policy update ("under any circumstances"). AI-powered Slack bots must not route user message content through LLM training pipelines. Source: `research/external/2026-05-20-dev-policy-update.md`.

## Scope note

This stinger covers the **Bolt SDK (JS, Python, Java)** and the classic Slack Platform. The **Deno Slack SDK** and the next-generation **Workflow Builder platform** are distinct products with separate documentation and are out of scope here. When developers encounter both in the official docs, direct them to `https://tools.slack.dev/bolt-js/` (Bolt JS) vs `https://tools.slack.dev/deno-slack-sdk/` (Deno/Workflow Builder) for the right starting point.

## Handoff map

- Deployment infrastructure for the Bolt app backend (Lambda, Fly.io, Render): route to `devops-wasp-drone`.
- Token vault, signing secret rotation, security audit: route to `security-wasp-drone`.
- Django or FastAPI backend decisions beyond Bolt integration: route to `python-wasp-drone`.
- Slack Connect or Enterprise Grid administration: out of scope; direct the user to Slack's enterprise documentation.

---

*Forged by `stinger-forge` from `ai-tools/command-briefs/slack-app-wasp-drone-command-brief.md` and `research/`. Part of the Wasp Nest.*

Files in this skill

  • README.md618 B
  • SKILL.md4.9 KB
  • examples/events-api-handler.md5.1 KB
  • examples/slash-command-with-modal.md5.5 KB
  • guides/00-setup-and-bolt.md5.5 KB
  • guides/01-slash-commands.md4.6 KB
  • guides/02-block-kit.md5.2 KB
  • guides/03-modals.md5.9 KB
  • guides/04-events-api.md5.2 KB
  • guides/05-oauth-install.md6.2 KB
  • guides/06-app-directory.md6.5 KB
  • reports/README.md830 B
  • research/external/2026-05-20-app-directory-marketplace.md3.6 KB
  • research/external/2026-05-20-app-manifest-reference.md3.1 KB
  • research/external/2026-05-20-block-kit-modals.md3 KB
  • research/external/2026-05-20-bolt-sdk-setup-patterns.md1.9 KB
  • research/external/2026-05-20-dev-policy-update.md2.8 KB
  • research/external/2026-05-20-events-api-verification.md2.8 KB
  • research/external/2026-05-20-oauth-multi-workspace.md3.2 KB
  • research/external/2026-05-20-slash-commands-interactive.md3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…