clickup
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the Membrane CLI tool using the command
npm install -g @membranehq/cli@latest. This is a standard dependency for interacting with the Membrane platform. - [COMMAND_EXECUTION]: The skill makes extensive use of the
membraneCLI to perform operations such as authentication, connection management, and action execution. These commands are part of the intended functionality for interacting with the ClickUp API through the Membrane proxy. - [INDIRECT_PROMPT_INJECTION]: The skill has the surface for indirect prompt injection as it ingests data from external sources.
- Ingestion points: Data is ingested from ClickUp tasks, lists, folders, and comments via
membrane action runandmembrane request(SKILL.md). - Boundary markers: None explicitly defined in the provided instructions to separate user data from system instructions.
- Capability inventory: The skill can execute shell commands via the
membraneCLI and perform network requests through the Membrane proxy (SKILL.md). - Sanitization: There is no explicit mention of sanitization or filtering of the content retrieved from ClickUp before it is processed by the agent.
Audit Metadata