This Slack bot skill is mostly coherent, but it gives an agent broad Slack read/write access and persists sensitive tokens and workspace metadata locally, so it needs careful review before use.
Install only if you trust the external agent-messenger package and are comfortable giving an agent Slack bot access. Create a dedicated Slack app, grant only the scopes needed for your workflow, avoid private-channel and user-email scopes unless necessary, prefer environment variables or a secret manager over saved plaintext credentials when possible, and periodically clear or review both the credential file and MEMORY.md.