clickup

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the Membrane CLI tool using the command npm install -g @membranehq/cli@latest. This is a standard dependency for interacting with the Membrane platform.
  • [COMMAND_EXECUTION]: The skill makes extensive use of the membrane CLI to perform operations such as authentication, connection management, and action execution. These commands are part of the intended functionality for interacting with the ClickUp API through the Membrane proxy.
  • [INDIRECT_PROMPT_INJECTION]: The skill has the surface for indirect prompt injection as it ingests data from external sources.
  • Ingestion points: Data is ingested from ClickUp tasks, lists, folders, and comments via membrane action run and membrane request (SKILL.md).
  • Boundary markers: None explicitly defined in the provided instructions to separate user data from system instructions.
  • Capability inventory: The skill can execute shell commands via the membrane CLI and perform network requests through the Membrane proxy (SKILL.md).
  • Sanitization: There is no explicit mention of sanitization or filtering of the content retrieved from ClickUp before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 12:08 PM
Security Audit — agent-trust-hub — clickup