clickup-automation

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s ClickUp automation purpose is coherent, but its execution trust is inconsistent. It relies on a legacy/intermediary Rube MCP endpoint and outdated tool names instead of the current documented Composio or official ClickUp MCP paths, so users would route ClickUp-authorized actions through a third party with unclear current ownership/maintenance. No direct malware indicators or credential-file theft are present, but the provenance and data-routing mismatch make this higher-risk than a normal documentation skill.

Confidence: 88%Severity: 54%
Audit Metadata
Analyzed At
Sep 6, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fclickup-automation%2F@fb1b722b949939bcd1df1682fe3192afff31ff5fa902ffab2edf5665fd21eaaa
Security Audit — socket — clickup-automation