clickup-automation
Warn
Audited by Socket on Sep 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s ClickUp automation purpose is coherent, but its execution trust is inconsistent. It relies on a legacy/intermediary Rube MCP endpoint and outdated tool names instead of the current documented Composio or official ClickUp MCP paths, so users would route ClickUp-authorized actions through a third party with unclear current ownership/maintenance. No direct malware indicators or credential-file theft are present, but the provenance and data-routing mismatch make this higher-risk than a normal documentation skill.
Confidence: 88%Severity: 54%
Audit Metadata