clickup

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose (ClickUp MCP task management automation) is coherent with its capabilities, install/usage model, and data flows. It does not exhibit suspicious credential handling, external exfiltration, or high-risk permission requirements. The design appears purpose-appropriate and proportionate for automating task lifecycle actions via MCP tools. Overall risk is low to moderate with respect to supply-chain integrity, primarily relying on trusted MCP tool schemas; no credential or secret handling is evident in the fragment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:29 PM
Package URL
pkg:socket/skills-sh/maroffo%2Fclaude-forge%2Fclickup%2F@3e159d0bd02a41f0420e08be1710e16631b6a71d