Skip to content

Security: he8um/clickup-skills

Security

SECURITY.md

Security Policy

This repository should never include ClickUp credentials, API tokens, OAuth secrets, private workspace IDs, customer data, or internal business data.

Reporting a security issue

Open a private security advisory or contact the maintainer directly. Do not disclose secrets or private workspace data in public issues.

Safe usage

When using the Skill with AI agents:

  • Use read-only mode first.
  • Ask for a dry-run plan before write actions.
  • Never paste tokens into prompts.
  • Store credentials in environment variables or approved secret managers.
  • Review generated automation and API actions before execution.

There aren't any published security advisories