T09 · Insecure Skill Coding Practices
- Location
SKILL.md:43- Finding
ClickUp API Token Disclosure Through Documented Terminal Output
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43–47
Vulnerability Type: Sensitive credential exposure
Risk Level: MediumVulnerable Code
bash Check if they are available as environment variables: ```bash echo $CLICKUP_API_KEY echo $CLICKUP_TEAM_ID echo $CLICKUP_ASSIGNEE_IDtext The documentation instructs users or agents to print the complete value of `CLICKUP_API_KEY`. This is an authentication credential rather than a harmless configuration value. Printing it is unnecessary for determining whether the variable is configured. ### Technical Analysis Terminal output can be retained in CI logs, agent tool results, chat transcripts, shell transcripts, screen recordings, or debugging records. Following the documented command therefore transfers the complete API token from an environment variable into less-protected output channels. Although the team and assignee identifiers are generally less sensitive, printing them alongside the token can provide useful account context to anyone who captures the output. The script itself uses the token only as an authorization header sent to ClickUp's fixed official HTTPS API; no unauthorized external destination was identified. ### Attack Path 1. A user or automated agent follows the configuration-check instructions in `SKILL.md`. 2. `echo $CLICKUP_API_KEY` writes the complete ClickUp API token to standard output. 3. The terminal or agent output is retained in a log, transcript, recording, or conversation history. 4. An unauthorized party with access to that retained output obtains the token. 5. The party submits the token in an `Authorization` header to the ClickUp API. 6. The party can read or modify ClickUp data to the extent permitted by the compromised token. ### Impact Assessment Successful exploitation discloses the privileges already assigned to the ClickUp API token. Depending on its account and workspace permissions, an attacke ...[truncated 518 chars]- Remediation
View remediation
Remediation Suggestions
Replace value-printing commands with presence-only checks that never expose credential contents:
bash if [ -n "${CLICKUP_API_KEY:-}" ]; then echo "CLICKUP_API_KEY is set" else echo "CLICKUP_API_KEY is not set" fi if [ -n "${CLICKUP_TEAM_ID:-}" ]; then echo "CLICKUP_TEAM_ID is set" else echo "CLICKUP_TEAM_ID is not set" fi if [ -n "${CLICKUP_ASSIGNEE_ID:-}" ]; then echo "CLICKUP_ASSIGNEE_ID is set" else echo "CLICKUP_ASSIGNEE_ID is not set" fiAdditional hardening measures:
- Explicitly warn users never to print, paste, or log
CLICKUP_API_KEY. - Redact the token from CI output, agent transcripts, debugging traces, and shell history.
- Rotate any token that may already have appeared in retained output.
- Use a dedicated ClickUp identity or token with only the workspace permissions required by this Skill.
- Validate
CLICKUP_ASSIGNEE_IDonly forcreate-task, because read-only commands do not require it. - Preserve the fixed HTTPS ClickUp API origin and avoid accepting user-controlled API hosts.
- Explicitly warn users never to print, paste, or log
