Slack agent and MCP preflight reviews

SecureLore

SecureLore helps Slack builders catch approval blockers before they ask an admin, submit to judges, or prepare a Marketplace review. It runs inside Slack, stores review evidence, and produces practical artifacts instead of generic chatbot advice.

# agent-reviewSecureLore
SecureLore reviewREJECT

5 blocker(s) and 2 warning(s) found. Address blockers before asking admins to approve the app.

Broad history scope requested
AI disclosure is incomplete
files:read needs evidence
Admin briefPatch planAdd evidence
Review Room

Risk: REJECT - Evidence captured: 2

Scope reason added by builder

What it reviews

Built for the handoff between builders and Slack admins.

Slack manifest review

MCP tool metadata checks

Scope justification packets

Live workspace precedent search

Marketplace readiness artifacts

Evidence capture inside Slack

Builder review

Paste a real Slack manifest or MCP tools/list response and get blockers, warnings, patch plans, and admin-ready artifacts.

Review Room

Turn each review into a Slack-native room where builders add evidence, answer policy questions, and reopen the latest state from App Home.

Policy memory

Ground checks against stored Slack Marketplace and platform guidance using Cohere embeddings over Neon Postgres with pgvector.

Workspace Evidence Scout

Use Slack Real-Time Search on explicit request to find cited public-channel precedent without copying search results into SecureLore storage.

Version-bound approval

Bind every reviewer decision to a SHA-256 fingerprint and mark approval stale when the manifest, tools, disclosures, or policy context changes.

Admin approval queue

Route reviews to configured Slack reviewers and an approval channel without requesting broad Slack admin scopes.

AI and data disclosure

Review output is generated with explicit guardrails.

SecureLore uses OpenRouter-hosted language models for review enrichment and Cohere embeddings for policy retrieval. Slack data is not used to train models. Real-Time Search results are displayed live with Slack permalinks and are never stored by SecureLore. Review packets, feedback, and submitted evidence are retained only to support the workspace review workflow and can be deleted on request.