Back to skill

Security audit

ClickUp Operator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent ClickUp automation skill that can change live tasks, so users should install it only if they want low-confirmation ClickUp actions.

Install this only if you are comfortable with an agent creating and updating real ClickUp tasks when your request is clear. During setup, keep token handling private, confirm the destination lists and assignee defaults, and consider adding your own confirmation rule for moves, status changes, due-date changes, or reassignment in shared workspaces.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
`SKILL.md` is the entrypoint and traffic controller for this skill.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly promotes low-friction operation on live ClickUp data and says to act 'without unnecessary confirmation,' which increases the chance of unintended task creation, moves, reassignment, or due-date changes. Although the file includes onboarding and validation phases, the top-level description and core behavior still bias the agent toward immediate state-changing actions without strong user-consent guardrails for destructive or ambiguous operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The default prompt is broadly phrased to handle creating, routing, updating, and reading ClickUp work with minimal back-and-forth, which can cause the skill to activate or be selected for a wide range of generic productivity requests. In an agent environment, this increases the chance of over-broad invocation and unintended task mutations or data access without sufficiently explicit user confirmation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · examples/internal-smoke-test.md (reported line 9)May include surrounding context.

md
Prompt:

`Create a task to check my task list.`

Verify:

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · examples/safe-live-smoke-test.md (reported line 15)May include surrounding context.

md
Prompt:

`Create a task to check my task list.`

Verify:

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · examples/test-cases.md (reported line 11)May include surrounding context.

md
Prompt:

`Create a task to check my task list.`

Verify:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example prompt is very broad and mirrors ordinary natural-language requests a user might make in many contexts. In a skill designed to act without unnecessary confirmation, this can cause unintended task creation when ambiguous conversational text is interpreted as an operational command.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The readback example 'What's on my list today?' is a vague, everyday request that could easily overlap with normal conversation. Because the skill is intended to read from ClickUp automatically, ambiguous matching may expose task data when the user did not clearly intend to invoke the integration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document instructs a live smoke test that creates items in a production ClickUp workspace, but it does not present a clear upfront warning that the procedure will modify live data and may create noise or unintended workflow effects. Although it suggests temporary config snapshots and TEST - prefixes, those mitigations do not replace explicit user consent and environment-safety guidance before performing write actions in a live system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The onboarding flow explicitly tells the agent to help obtain a ClickUp auth token and store or reference it in a local environment path, but it does not require informed user consent, secure-secret handling guidance, or restrictions on where the credential may be written. In an agent-driven setup flow, this can lead to accidental exposure of long-lived tokens in plaintext files, unsafe directories, logs, or config snapshots, especially because the same document also requires saving setup data into config.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/internal-install.md (reported line 19)May include surrounding context.

md
### 1. Confirm ClickUp access

- verify the ClickUp MCP/auth route is already working
- do not ask the user for a new token until the known local auth path has been checked

### 2. Resolve the live defaults

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rule to 'execute immediately' authorizes external state changes in ClickUp without a user-facing warning or confirmation unless ambiguity affects routing, which can lead to unintended modifications of real project data. In this skill's context, the danger is amplified because it manages task creation, movement, assignment, and scheduling in a production collaboration system, so mistaken interpretation directly alters shared work artifacts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The rule classifies broad natural-language phrases like 'reminder' or any 'plainly actionable one-off task' as signals to create tasks, which can cause unintended writes to ClickUp from ordinary conversation. In a skill explicitly designed to execute immediately and avoid unnecessary confirmation, this increases the chance of accidental task creation, assignment, and due-date setting based on ambiguous user input.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · templates/structure-discovery-worksheet.md (reported line 40)May include surrounding context.

md
## Exceptions / special rules

- Are there buckets the agent should never use without confirmation?
- Are there buckets where due dates should not be auto-added?
- Are there buckets where assignees should not be auto-set?

Static analysis

No suspicious patterns detected.