clickup-enterprise-rbac
Facilitates ClickUp Enterprise SSO and OAuth 2.0 for multi-workspace access and role-based permissions management.
Install this skill
Security score
The clickup-enterprise-rbac skill was audited on May 18, 2026 and we found 14 security issues across 4 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
Template literal with variable interpolation in command context
| 42 | const data = await clickupRequest(`/team/${teamId}`); |
Template literal with variable interpolation in command context
| 66 | return `https://app.clickup.com/api?client_id=${process.env.CLICKUP_CLIENT_ID}&redirect_uri=${encodeURIComponent(process.env.CLICKUP_REDIRECT_URI!)}&state=${state}`; |
Template literal with variable interpolation in command context
| 140 | error: `Requires role ${requiredRole} or higher`, |
Template literal with variable interpolation in command context
| 167 | await clickupRequest(`/team/${teamId}/group`, { |
Fetch to external URL
| 71 | const response = await fetch('https://api.clickup.com/api/v2/oauth/token', { |
Fetch to external URL
| 84 | const teamsResponse = await fetch('https://api.clickup.com/api/v2/team', { |
Fetch to external URL
| 118 | const teamsRes = await fetch('https://api.clickup.com/api/v2/team', { |
Access to .env file
| 66 | return `https://app.clickup.com/api?client_id=${process.env.CLICKUP_CLIENT_ID}&redirect_uri=${encodeURIComponent(process.env.CLICKUP_REDIRECT_URI!)}&state=${state}`; |
Access to .env file
| 75 | client_id: process.env.CLICKUP_CLIENT_ID, |
Access to .env file
| 76 | client_secret: process.env.CLICKUP_CLIENT_SECRET, |
External URL reference
| 66 | return `https://app.clickup.com/api?client_id=${process.env.CLICKUP_CLIENT_ID}&redirect_uri=${encodeURIComponent(process.env.CLICKUP_REDIRECT_URI!)}&state=${state}`; |
External URL reference
| 71 | const response = await fetch('https://api.clickup.com/api/v2/oauth/token', { |
External URL reference
| 84 | const teamsResponse = await fetch('https://api.clickup.com/api/v2/team', { |
External URL reference
| 118 | const teamsRes = await fetch('https://api.clickup.com/api/v2/team', { |