Security audit
ClickUp
Security checks for vulnerabilities and agentic risk
Overview
This ClickUp skill is a clearly disclosed OOMOL connector wrapper that can read and change ClickUp data, with explicit confirmation rules for writes and deletions.
Before installing, understand that this skill can create, update, and delete ClickUp tasks, lists, folders, spaces, comments, and related data through your connected OOMOL account. Only approve write or destructive actions after checking the exact ClickUp target and payload.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
