Great write-up, however I have concerns over the security of this product, especially the part where they submit a Slack token directly over email.
Email itself is not secure, but at the very least an attacker intercepting a single message will only get the content of that message. An attacker intercepting the token will however gain persistent, remote access to all their current & future Slack messages with no way for the user to even know they've been compromised.