clickup-automation
Pass
Audited by Gen Agent Trust Hub on Mar 5, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires connecting to an external MCP server at
https://rube.app/mcp. This is the official endpoint for the Rube platform by Composio, which provides the necessary ClickUp integration tools. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface due to its data ingestion patterns. * Ingestion points: Data is retrieved from ClickUp using tools like
CLICKUP_GET_TASKS,CLICKUP_GET_TASK, andCLICKUP_GET_TASK_COMMENTSas documented inSKILL.md. * Boundary markers: The skill does not define specific markers or instructions to isolate or ignore potential malicious prompts embedded within ClickUp task descriptions or comments. * Capability inventory: The agent possesses significant write capabilities, including the ability to create, update, and delete tasks, folders, and spaces across the ClickUp workspace. * Sanitization: There is no evidence of sanitization or validation of the content retrieved from ClickUp before it is processed by the agent.
Audit Metadata