clickup-mcp

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated ClickUp purpose is legitimate and the remote MCP endpoint is official, but the skill's core workaround is not: it extracts a long-lived OAuth token from Claude's credential file, stores it in a new env file, and forwards it to mcporter, a non-ClickUp tool with unclear trust. That creates disproportionate credential-handling and supply-chain risk even without clear evidence of malware.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fclickup-mcp%2F@4b21fe2c674b34e40d31cde65d4f7907eb180579