Back to skill

Security audit

Personal Task Tracking

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its ClickUp task-management purpose, but it includes unsafe API-token checking instructions and state-changing ClickUp actions without clear confirmation guidance.

Review before installing. Use a dedicated least-privileged ClickUp token, do not run the documented echo command for CLICKUP_API_KEY, avoid logging the token in agent transcripts or terminals, and require explicit approval before running create-task or close-task against a live workspace.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:43
Finding

ClickUp API Token Disclosure Through Documented Terminal Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43–47
Vulnerability Type: Sensitive credential exposure
Risk Level: Medium

Vulnerable Code

bash
Check if they are available as environment variables:
```bash
echo $CLICKUP_API_KEY
echo $CLICKUP_TEAM_ID
echo $CLICKUP_ASSIGNEE_ID
text

The documentation instructs users or agents to print the complete value of `CLICKUP_API_KEY`. This is an authentication credential rather than a harmless configuration value. Printing it is unnecessary for determining whether the variable is configured.

### Technical Analysis

Terminal output can be retained in CI logs, agent tool results, chat transcripts, shell transcripts, screen recordings, or debugging records. Following the documented command therefore transfers the complete API token from an environment variable into less-protected output channels.

Although the team and assignee identifiers are generally less sensitive, printing them alongside the token can provide useful account context to anyone who captures the output. The script itself uses the token only as an authorization header sent to ClickUp's fixed official HTTPS API; no unauthorized external destination was identified.

### Attack Path

1. A user or automated agent follows the configuration-check instructions in `SKILL.md`.
2. `echo $CLICKUP_API_KEY` writes the complete ClickUp API token to standard output.
3. The terminal or agent output is retained in a log, transcript, recording, or conversation history.
4. An unauthorized party with access to that retained output obtains the token.
5. The party submits the token in an `Authorization` header to the ClickUp API.
6. The party can read or modify ClickUp data to the extent permitted by the compromised token.

### Impact Assessment

Successful exploitation discloses the privileges already assigned to the ClickUp API token. Depending on its account and workspace permissions, an attacke
...[truncated 518 chars]
Remediation
View remediation

Remediation Suggestions

Replace value-printing commands with presence-only checks that never expose credential contents:

bash
if [ -n "${CLICKUP_API_KEY:-}" ]; then
    echo "CLICKUP_API_KEY is set"
else
    echo "CLICKUP_API_KEY is not set"
fi

if [ -n "${CLICKUP_TEAM_ID:-}" ]; then
    echo "CLICKUP_TEAM_ID is set"
else
    echo "CLICKUP_TEAM_ID is not set"
fi

if [ -n "${CLICKUP_ASSIGNEE_ID:-}" ]; then
    echo "CLICKUP_ASSIGNEE_ID is set"
else
    echo "CLICKUP_ASSIGNEE_ID is not set"
fi

Additional hardening measures:

  • Explicitly warn users never to print, paste, or log CLICKUP_API_KEY.
  • Redact the token from CI output, agent transcripts, debugging traces, and shell history.
  • Rotate any token that may already have appeared in retained output.
  • Use a dedicated ClickUp identity or token with only the workspace permissions required by this Skill.
  • Validate CLICKUP_ASSIGNEE_ID only for create-task, because read-only commands do not require it.
  • Preserve the fixed HTTPS ClickUp API origin and avoid accepting user-controlled API hosts.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises shell-based operational capability but does not declare any explicit tool scope or permission boundary. That increases the chance an agent may invoke local shell commands more broadly than intended, including commands that access credentials or modify remote ClickUp state without clear governance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to echo and export the ClickUp API token without any caution about credential exposure. Printing secrets to the terminal can leak them into logs, scrollback, recordings, or shared shells, and normalizing unsafe secret handling increases the risk of credential compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation includes create-task and close-task workflows that modify remote ClickUp data, but it does not clearly warn that these actions are state-changing or require explicit approval. In an agent setting, that omission can lead to unintended task creation or closure in a live workspace.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
# API call helper
clickup_api() {
    local endpoint="$1"
    curl -s "https://api.clickup.com/api/v2${endpoint}" \
        -H "Authorization: ${CLICKUP_API_KEY}"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/clickup-query.sh (reported line 71)May include surrounding context.

sh
# API call helper
clickup_api() {
    local endpoint="$1"
    curl -s "https://api.clickup.com/api/v2${endpoint}" \
        -H "Authorization: ${CLICKUP_API_KEY}"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/clickup-query.sh (reported line 78)May include surrounding context.

sh
# API call helper
clickup_api() {
    local endpoint="$1"
    curl -s "https://api.clickup.com/api/v2${endpoint}" \
        -H "Authorization: ${CLICKUP_API_KEY}"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/clickup-query.sh (reported line 88)May include surrounding context.

sh
# API call helper
clickup_api() {
    local endpoint="$1"
    curl -s "https://api.clickup.com/api/v2${endpoint}" \
        -H "Authorization: ${CLICKUP_API_KEY}"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/clickup-query.sh (reported line 386)May include surrounding context.

sh
# API call helper
clickup_api() {
    local endpoint="$1"
    curl -s "https://api.clickup.com/api/v2${endpoint}" \
        -H "Authorization: ${CLICKUP_API_KEY}"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/clickup-query.sh (reported line 463)May include surrounding context.

sh
# API call helper
clickup_api() {
    local endpoint="$1"
    curl -s "https://api.clickup.com/api/v2${endpoint}" \
        -H "Authorization: ${CLICKUP_API_KEY}"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/clickup-query.sh (reported line 71)May include surrounding context.

sh
# API call helper
clickup_api() {
    local endpoint="$1"
    curl -s "https://api.clickup.com/api/v2${endpoint}" \
        -H "Authorization: ${CLICKUP_API_KEY}"
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/clickup-query.sh (reported line 386)May include surrounding context.

sh
due_date: ($due_date_ms | tonumber)
        }')

    response=$(curl -s -w '\n%{http_code}' "https://api.clickup.com/api/v2/list/${list_id}/task" \
        -X POST \
        -H "Authorization: ${CLICKUP_API_KEY}" \
        -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/clickup-query.sh (reported line 463)May include surrounding context.

sh
fi

    payload=$(jq -n --arg status "$closed_status" '{status: $status}')
    response=$(curl -s -w '\n%{http_code}' "https://api.clickup.com/api/v2/task/${task_id}" \
        -X PUT \
        -H "Authorization: ${CLICKUP_API_KEY}" \
        -H "Content-Type: application/json" \

Static analysis

No suspicious patterns detected.