clickup

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, and the Membrane CLI install path is verifiable via npm and matching docs, so this is not malware. However, it routes ClickUp authentication and API traffic through a third-party intermediary platform, which is broader than a direct ClickUp integration and creates medium security risk from credential forwarding and indirect data access.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Sep 20, 2026, 12:09 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fclickup%2F@5180df0ae2179890029a04564abda1bf0da268bf209efe6b0273cdaca1726906
Security Audit — socket — clickup