Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md `SKILL.md` is the entrypoint and traffic controller for this skill.
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent ClickUp automation skill that can change live tasks, so users should install it only if they want low-confirmation ClickUp actions.
Install this only if you are comfortable with an agent creating and updating real ClickUp tasks when your request is clear. During setup, keep token handling private, confirm the destination lists and assignee defaults, and consider adding your own confirmation rule for moves, status changes, due-date changes, or reassignment in shared workspaces.
Referenced artifact was not completely inspected
`SKILL.md` is the entrypoint and traffic controller for this skill.
The skill explicitly promotes low-friction operation on live ClickUp data and says to act 'without unnecessary confirmation,' which increases the chance of unintended task creation, moves, reassignment, or due-date changes. Although the file includes onboarding and validation phases, the top-level description and core behavior still bias the agent toward immediate state-changing actions without strong user-consent guardrails for destructive or ambiguous operations.
The default prompt is broadly phrased to handle creating, routing, updating, and reading ClickUp work with minimal back-and-forth, which can cause the skill to activate or be selected for a wide range of generic productivity requests. In an agent environment, this increases the chance of over-broad invocation and unintended task mutations or data access without sufficiently explicit user confirmation.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Prompt:
`Create a task to check my task list.`
Verify:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Prompt:
`Create a task to check my task list.`
Verify:
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Prompt:
`Create a task to check my task list.`
Verify:
The example prompt is very broad and mirrors ordinary natural-language requests a user might make in many contexts. In a skill designed to act without unnecessary confirmation, this can cause unintended task creation when ambiguous conversational text is interpreted as an operational command.
The readback example 'What's on my list today?' is a vague, everyday request that could easily overlap with normal conversation. Because the skill is intended to read from ClickUp automatically, ambiguous matching may expose task data when the user did not clearly intend to invoke the integration.
The document instructs a live smoke test that creates items in a production ClickUp workspace, but it does not present a clear upfront warning that the procedure will modify live data and may create noise or unintended workflow effects. Although it suggests temporary config snapshots and TEST - prefixes, those mitigations do not replace explicit user consent and environment-safety guidance before performing write actions in a live system.
The onboarding flow explicitly tells the agent to help obtain a ClickUp auth token and store or reference it in a local environment path, but it does not require informed user consent, secure-secret handling guidance, or restrictions on where the credential may be written. In an agent-driven setup flow, this can lead to accidental exposure of long-lived tokens in plaintext files, unsafe directories, logs, or config snapshots, especially because the same document also requires saving setup data into config.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### 1. Confirm ClickUp access
- verify the ClickUp MCP/auth route is already working
- do not ask the user for a new token until the known local auth path has been checked
### 2. Resolve the live defaults
The rule to 'execute immediately' authorizes external state changes in ClickUp without a user-facing warning or confirmation unless ambiguity affects routing, which can lead to unintended modifications of real project data. In this skill's context, the danger is amplified because it manages task creation, movement, assignment, and scheduling in a production collaboration system, so mistaken interpretation directly alters shared work artifacts.
The rule classifies broad natural-language phrases like 'reminder' or any 'plainly actionable one-off task' as signals to create tasks, which can cause unintended writes to ClickUp from ordinary conversation. In a skill explicitly designed to execute immediately and avoid unnecessary confirmation, this increases the chance of accidental task creation, assignment, and due-date setting based on ambiguous user input.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Exceptions / special rules
- Are there buckets the agent should never use without confirmation?
- Are there buckets where due dates should not be auto-added?
- Are there buckets where assignees should not be auto-set?
No suspicious patterns detected.