clickup

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent for ClickUp task/doc management, and its data flow appears intended for ClickUp. However, it hinges on an unverified global `clickup` CLI with no documented provenance in the supplied skill, while official ClickUp docs more clearly support direct API/OAuth and an official MCP path. That external dependency trust gap makes the skill high security risk even without clear evidence of malware.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/discountry%2Fclickup-cli%2Fclickup%2F@e6fc7f6254250bf96b9b013118ddedc49c846cda