clickup-automation

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires connecting to an external MCP server at https://rube.app/mcp. This is the official endpoint for the Rube platform by Composio, which provides the necessary ClickUp integration tools.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface due to its data ingestion patterns. * Ingestion points: Data is retrieved from ClickUp using tools like CLICKUP_GET_TASKS, CLICKUP_GET_TASK, and CLICKUP_GET_TASK_COMMENTS as documented in SKILL.md. * Boundary markers: The skill does not define specific markers or instructions to isolate or ignore potential malicious prompts embedded within ClickUp task descriptions or comments. * Capability inventory: The agent possesses significant write capabilities, including the ability to create, update, and delete tasks, folders, and spaces across the ClickUp workspace. * Sanitization: There is no evidence of sanitization or validation of the content retrieved from ClickUp before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 07:55 AM