Agent skill

Clickup Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls.

MITAuto-check passedBackend & APIs

Install Clickup Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill clickup-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace clickup-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/clickup-security-basics .claude/skills/clickup-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clickup-security-basics
GitHub stars
2.8k
Token cost
~1k tokens
SKILL.md length
384 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls.

  • Works in 6 steps: Inventory credentials, callbacks,… → Remove client-side or repository… → Enforce OAuth state, exact redirect… → …
  • Threat-modeling
  • SKILL.md covers Overview, Prerequisites, Tool Discipline and Current Contract, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Clickup Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls. Use when threat-modeling or reviewing a ClickUp integration. Trigger with "secure ClickUp", "ClickUp security review", or "ClickUp token rotation".

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Designed for Claude Code; credential and access changes require authorized security and Workspace owners

It sits in Backend & APIs, covering Webhooks, Security review and Threat modeling. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Threat-modeling
  • Reviewing a ClickUp integration
  • With secure ClickUp
  • ClickUp security review

Example prompts

  • “secure ClickUp”
  • “ClickUp security review”
  • “ClickUp token rotation”
  • “/clickup-security-basics”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code; credential and access changes require authorized security and Workspace owners
  • Pre-approved tools (allowed-tools): Read, Glob, Grep, WebFetch, Write, Edit

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Inventory credentials, callbacks, Workspaces, scopes/capabilities, webhooks, queues, stores, logs, and operator access.
  2. Remove client-side or repository secrets; inject environment-specific references at runtime.
  3. Enforce OAuth state, exact redirect handling, Workspace allow-lists, and deny-by-default write policies.
  4. Verify webhook signatures with constant-time comparison before JSON processing; apply replay/idempotency controls.
  5. Redact content and secrets from errors, traces, bundles, analytics, and CI artifacts.
  6. Exercise leak, revocation, cross-tenant, forged/replayed webhook, partial-write, and incident recovery scenarios.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • WebFetch
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developer.clickup.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code; credential and access changes require authorized security and Workspace owners

    From compatibility in the SKILL.md frontmatter.

Context cost

Clickup Security Basics loads about 1k tokens when it runs, and up to ~1.6k if it reads all its reference files. Until then it costs about 78 tokens; SKILL.md has 384 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 384 words, ~1,039 tokens.

Download SKILL.mdSave it as .claude/skills/clickup-security-basics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
clickup-security-basics
description
Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls. Use when threat-modeling or reviewing a ClickUp integration. Trigger with "secure ClickUp", "ClickUp security review", or "ClickUp token rotation".
allowed-tools
Read, Glob, Grep, WebFetch, Write, Edit
compatibility
Designed for Claude Code; credential and access changes require authorized security and Workspace owners
argument-hint
[repository-or-service] [assessment|remediation]
version
1.8.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
saas, clickup, security
model
inherit
effort
high

ClickUp Integration Security

Overview

Protect long-lived credentials and sensitive work content across outbound API calls, inbound webhooks, queues, logs, and operator tooling.

Prerequisites

  • A data-flow and trust-boundary diagram plus credential/Workspace inventory
  • Named security, service, data, and ClickUp Workspace owners
  • Synthetic fixtures and an incident/rotation runbook

Tool Discipline

Use Read, Glob, and Grep to inspect the repository, adapters, configuration names, tests, and evidence. Use WebFetch only for current official ClickUp documentation. Use Write or Edit after confirming the target file, Workspace boundary, and requested mode.

Current Contract

  • Personal tokens do not expire; OAuth tokens currently do not expire but that behavior is subject to change.
  • OAuth Authorization Code callbacks require exact redirects, state validation, and server-side client-secret handling.
  • Webhook requests use per-webhook secrets and raw-body HMAC-SHA256 in X-Signature; ClickUp has no fixed webhook source IP.
  • API authorization reflects the user and authorized Workspaces, so the app must enforce its own tenant policy.

Authentication

Use a personal token only for accountable individual/testing work or OAuth Authorization Code for a user-facing integration. Inject the token server-side through a governed secret reference, send it in Authorization, verify authorized Workspace IDs, and never print the token, OAuth client secret, or webhook secret.

Show full SKILL.md (187 more words)Show less

Instructions

  1. Inventory credentials, callbacks, Workspaces, scopes/capabilities, webhooks, queues, stores, logs, and operator access.
  2. Remove client-side or repository secrets; inject environment-specific references at runtime.
  3. Enforce OAuth state, exact redirect handling, Workspace allow-lists, and deny-by-default write policies.
  4. Verify webhook signatures with constant-time comparison before JSON processing; apply replay/idempotency controls.
  5. Redact content and secrets from errors, traces, bundles, analytics, and CI artifacts.
  6. Exercise leak, revocation, cross-tenant, forged/replayed webhook, partial-write, and incident recovery scenarios.

Approval Boundaries

Do not rotate shared credentials, reauthorize Workspaces, change ACLs, or inspect private content without accountable owner approval.

Output

Return threats, controls, credential/tenant map, webhook findings, data exposures, tested incident paths, residual risk, and owners.

Error Handling

ConditionResponse
Credential found in source or logsRevoke/regenerate, scrub accessible artifacts, and open an incident.
Webhook signature is absent/invalidReject before parsing or enqueueing.
Workspace guard is missingDisable writes until tenant enforcement exists.
Security owner is absentDo not approve production use.

Examples

The example below is a redacted operator receipt; it contains no task text, member data, credential, or webhook secret.

text
secrets-in-source=0; oauth-state=pass; workspace-guard=pass; webhook-hmac=pass; replay-test=pass; residual=2

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/clickup-security-basics of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Clickup Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clickup Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clickup Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMIT
Security Threat Modelingdevcodex-labs/devcodex439—~771Automated safety check: PassAGPL-3.0
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
GitHub Actions Hardeninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Sec Checkwaynesutton/markdown-site627—~753Automated safety check: PassMIT
Security Threat Modelmajiayu000/spellbook287—~561Automated safety check: PassMIT

Similar skills

  • Security Threat Modeling

    devcodex-labs/devcodex

    安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。

    439 GitHub stars~771 tokensUpdated 24 days ago
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • GitHub Actions Hardening

    github/awesome-copilot

    Official

    Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Sec Check

    waynesutton/markdown-site

    Security review checklist for Convex functions, auth logic, public queries, admin routes, webhooks, uploads, and AI-generated code.

    627 GitHub stars~753 tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Security Threat Model

    majiayu000/spellbook

    Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation.

    287 GitHub stars~561 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated yesterday
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Questions about Clickup Security Basics

What does Clickup Security Basics do?

Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls. Clickup Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls.

When should I use Clickup Security Basics?

Clickup Security Basics fits situations like: threat-modeling; reviewing a ClickUp integration; with secure ClickUp; clickUp security review.

How do I install Clickup Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill clickup-security-basics -a claude-code`. Or copy the skill folder (skills/.curated/clickup-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/clickup-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Clickup Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill clickup-security-basics -a codex`. Or copy the skill folder (skills/.curated/clickup-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/clickup-security-basics in your project. Codex loads it when a task matches its description.

Can I use Clickup Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill clickup-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clickup-security-basics, .gemini/skills/clickup-security-basics, .github/skills/clickup-security-basics and .opencode/skills/clickup-security-basics in your project.

What does Clickup Security Basics need to run?

SKILL.md names no scripts, command-line tools or credentials: Clickup Security Basics is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Glob, Grep, WebFetch, Write, Edit. Compatibility (from SKILL.md): Designed for Claude Code; credential and access changes require authorized security and Workspace owners.

Does Clickup Security Basics access the network?

SKILL.md names 1 domain. As links in the text: developer.clickup.com. This is read from the text; nothing was executed.

Is Clickup Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Clickup Security Basics use?

Clickup Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clickup Security Basics use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 584 tokens, read only when the agent opens those files.

What are the alternatives to Clickup Security Basics?

Skills that share tags, products or a category with Clickup Security Basics: Security Threat Modeling (devcodex-labs/devcodex, 439 stars), Security Review (doorkeeper-gem/doorkeeper, 5.5k stars), GitHub Actions Hardening (github/awesome-copilot, 40k stars) and Sec Check (waynesutton/markdown-site, 627 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clickup Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.