{"data":{"skill":{"slug":"andresnaza-clickup-integration-expert","name":"ClickUp Integration Expert","icon":"📦","repo":"https://github.com/AndresNaza/claude-plugins/tree/main/clickup-sync/skills/clickup-integration","status":"approved","author":"AndresNaza","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"8ff15dad-a74c-47d8-a7d7-a810c49aeaf1","skill_id":"0a630540-f92c-4a6a-9f48-0ac8ff1500ff","version":13,"content_hash":"v3:bdc4c7c6e1e64de0e81902bd9656da84164bdaf7:759966b6513c3195172d73cad412dfd15053d3b9469633a311c542cda6c233b0:b8f5ad55154c584ab4fce2b3cbd34f734ac9f7ffabbab249e8e2e2391d53d8ed:736b696c6c732f616e647265736e617a612f636c69636b75702d696e746567726174696f6e2d657870657274:3cde9f171906880080cdd033e1020de0","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 13 external-command detections are false positives caused by Markdown code fences and inline command labels, not executable shell syntax. The remaining URL documents the official ClickUp MCP endpoint for an explicit user-run installation command; no prompt injection, secret collection, or covert data-exfiltration intent was found.","remediation":[{"issue":"The skill asks users to install and authenticate an external MCP service.","severity":"low","suggestion":"State that users should verify the ClickUp endpoint and review OAuth scopes before installing or authorizing the MCP."},{"issue":"Sync commands can update remote ClickUp data.","severity":"low","suggestion":"Recommend a dry run, a status check, and explicit user confirmation before push or bidirectional sync operations."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":35,"line_start":24},{"file":"SKILL.md","line_end":41,"line_start":35},{"file":"SKILL.md","line_end":42,"line_start":41},{"file":"SKILL.md","line_end":43,"line_start":42},{"file":"SKILL.md","line_end":44,"line_start":43},{"file":"SKILL.md","line_end":45,"line_start":44},{"file":"SKILL.md","line_end":46,"line_start":45},{"file":"SKILL.md","line_end":47,"line_start":46},{"file":"SKILL.md","line_end":52,"line_start":47},{"file":"SKILL.md","line_end":54,"line_start":52},{"file":"SKILL.md","line_end":56,"line_start":54},{"file":"SKILL.md","line_end":61,"line_start":56}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":53,"line_start":53}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":69,"audit_model":"claude","audited_at":"2026-07-17T09:47:32.92+00:00","created_at":"2026-07-17T15:42:19.939131+00:00","static_findings":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Stored in `.roadmap/clickup-config.json`:","category":"external_commands","line_end":22,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```json","category":"external_commands","line_end":35,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":41,"severity":"medium","line_start":35},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/clickup-sync:setup` | Configure ClickUp connection |","category":"external_commands","line_end":42,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/clickup-sync:push` | Push to ClickUp |","category":"external_commands","line_end":43,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/clickup-sync:pull` | Pull from ClickUp |","category":"external_commands","line_end":44,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/clickup-sync:sync` | Full bidirectional sync |","category":"external_commands","line_end":45,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/clickup-sync:status` | View sync status |","category":"external_commands","line_end":46,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/clickup-sync:link` | Manually link items |","category":"external_commands","line_end":47,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `/clickup-sync:unlink` | Remove sync links |","category":"external_commands","line_end":52,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":54,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":56,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Then run `/mcp` to authenticate via OAuth.","category":"external_commands","line_end":61,"severity":"medium","line_start":56},{"id":"network:SKILL.md:53:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"claude mcp add --transport http clickup https://mcp.clickup.com/mcp","category":"network","line_end":53,"severity":"low","line_start":53}],"finding_verdicts":[{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"This is an inline Markdown path enclosed in backticks. It does not invoke a shell or execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"This opens a fenced JSON example. Markdown fences are documentation syntax, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:35:ruby-shell-backtick-execution","reason":"This closes the JSON code fence. It contains no executable command or dynamic input.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"This is an inline label for a documented skill command in a Markdown table. It is not a shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"This is an inline label for a documented skill command in a Markdown table. It is not a shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"This is an inline label for a documented skill command in a Markdown table. It is not a shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"This is an inline label for a documented skill command in a Markdown table. It is not a shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"This is an inline label for a documented skill command in a Markdown table. It is not a shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"This is an inline label for a documented skill command in a Markdown table. It is not a shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"This is an inline label for a documented skill command in a Markdown table. It is not a shell backtick expression.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"This opens a fenced Bash example. The fence itself is Markdown and does not execute content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"This closes the Bash code fence. It is documentation syntax, not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"This is an inline reference to the MCP command used for OAuth authentication. It is not shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:53:hardcoded-url","reason":"The URL is the documented ClickUp MCP endpoint used in an explicit installation command. The skill does not send data to it itself or conceal the network action.","verdict":"false_positive","confidence":0.88}],"semantic_findings":[],"subject_marketplace_commit_sha":"bdc4c7c6e1e64de0e81902bd9656da84164bdaf7","subject_content_hash":"759966b6513c3195172d73cad412dfd15053d3b9469633a311c542cda6c233b0","subject_tree_hash":"b8f5ad55154c584ab4fce2b3cbd34f734ac9f7ffabbab249e8e2e2391d53d8ed","subject_plugin_path":"skills/andresnaza/clickup-integration-expert","audit_payload_hash":"3cde9f171906880080cdd033e1020de0","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"bdc4c7c6e1e64de0e81902bd9656da84164bdaf7","contentHash":"759966b6513c3195172d73cad412dfd15053d3b9469633a311c542cda6c233b0","treeHash":"b8f5ad55154c584ab4fce2b3cbd34f734ac9f7ffabbab249e8e2e2391d53d8ed","pluginPath":"skills/andresnaza/clickup-integration-expert","auditPayloadHash":"3cde9f171906880080cdd033e1020de0"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/andresnaza-clickup-integration-expert/audits/13/attestation","status":"superseded"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"superseded","verificationState":"not_verified"},"isLatest":false}}