Back to skill

Security audit

ClickUp

Security checks for vulnerabilities and agentic risk

Overview

This ClickUp skill is a clearly disclosed OOMOL connector wrapper that can read and change ClickUp data, with explicit confirmation rules for writes and deletions.

Before installing, understand that this skill can create, update, and delete ClickUp tasks, lists, folders, spaces, comments, and related data through your connected OOMOL account. Only approve write or destructive actions after checking the exact ClickUp target and payload.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.