Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.cvrt-jh/clickup-mcp

NPM · @CAVORT-IT-SYSTEMS/CLICKUP-MCP · SCANNED SEP 20

Lightweight ClickUp MCP server - 37 tools, token-optimized (95% smaller responses)

0 this week 81 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 31 of 96 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability76
  • AI-judged instruction clarity (good).Pass
  • Tool/resource definitions use about 2563 tokens (~69/item across 37 items; 37 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
  • Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage96
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 88% of tool parameters carry a description.Partial
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 8 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "clickup_delete_list" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 37 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the io.github.cvrt-jh/clickup-mcp server?

io.github.cvrt-jh/clickup-mcp runs locally as an npm package, launched with npx -y @cavort-it-systems/clickup-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @cavort-it-systems/clickup-mcp

# add to Claude Code
claude mcp add cvrt-jh-clickup-mcp -- npx -y @cavort-it-systems/clickup-mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "cvrt-jh-clickup-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@cavort-it-systems/clickup-mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "cvrt-jh-clickup-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@cavort-it-systems/clickup-mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add cvrt-jh-clickup-mcp -- npx -y @cavort-it-systems/clickup-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "cvrt-jh-clickup-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@cavort-it-systems/clickup-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add cvrt-jh-clickup-mcp --command npx --arg -y --arg @cavort-it-systems/clickup-mcp
# ~/.hermes/config.yaml
mcp_servers:
  cvrt-jh-clickup-mcp:
    command: "npx"
    args: ["-y", "@cavort-it-systems/clickup-mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "cvrt-jh-clickup-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@cavort-it-systems/clickup-mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add cvrt-jh-clickup-mcp -t stdio -c npx -a -y @cavort-it-systems/clickup-mcp
// mcp.json
{
  "mcpServers": {
    "cvrt-jh-clickup-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@cavort-it-systems/clickup-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 18 Sept 26 +1
    • Security disclosure: unverified → fail functional
  • 17 Sept 26 0
    • Security disclosure: fail → unverified functional
  • 16 Sept 26 −3
    • Stability: pass → 0.77 functional
  • 15 Sept 26 0
    • Stability: 0.97 → pass security
    • Security disclosure: unverified → fail functional
  • 14 Sept 26 +1
    • Security disclosure: fail → unverified functional
  • 12 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 10 Sept 26 −2
    • Security disclosure: unverified → fail functional
    • Stability: pass → 0.83 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Analysed npm/@cavort-it-systems/clickup-mcp@1.0.3

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Dependencies 96 packages
Packages resolved 96
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 37 exposed · ~2,563 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
clickup_add_dependency ~65

Add a dependency between tasks (waiting_on or blocking)

NameTypeReqDescription
dependency_ofstringTask ID that this task blocks
depends_onstringTask ID this task is waiting on
task_idstringyesThe task to add the dependency to

No output schema declared.

No examples provided.

clickup_add_tag_to_task ~43

Add a tag to a task

NameTypeReqDescription
tag_namestringyesTag name to add
task_idstringyesClickUp task ID

No output schema declared.

No examples provided.

clickup_add_task_link ~41

Link two tasks together

NameTypeReqDescription
links_tostringyesSecond task ID to link to
task_idstringyesFirst task ID

No output schema declared.

No examples provided.

clickup_create_checklist ~39

Create a checklist on a task

NameTypeReqDescription
namestringyesChecklist name
task_idstringyesClickUp task ID

No output schema declared.

No examples provided.

clickup_create_checklist_item ~50

Add an item to a checklist

NameTypeReqDescription
assigneenumberUser ID to assign
checklist_idstringyesChecklist ID
namestringyesItem name

No output schema declared.

No examples provided.

clickup_create_comment ~70

Add a comment to a task

NameTypeReqDescription
assigneenumberUser ID to assign with this comment
comment_textstringyesComment text
notify_allbooleanNotify all assignees (default true)
task_idstringyesClickUp task ID

No output schema declared.

No examples provided.

clickup_create_list ~130

Create a new list in a folder or as a folderless list in a space

NameTypeReqDescription
contentstringList description
due_datenumberDue date as Unix timestamp in milliseconds
folder_idstringFolder ID (for list inside folder)
namestringyesList name
prioritynumberPriority (1=urgent, 2=high, 3=normal, 4=low)
space_idstringSpace ID (for folderless list)
statusstringStatus name to use as default

No output schema declared.

No examples provided.

clickup_create_reply ~38

Add a threaded reply to a comment

NameTypeReqDescription
comment_idstringyesComment ID
comment_textstringyesReply text

No output schema declared.

No examples provided.

clickup_create_space_tag ~76

Create a new tag in a space

NameTypeReqDescription
namestringyesTag name
space_idstringyesClickUp space ID
tag_bgstringBackground color hex (e.g. '#000000')
tag_fgstringForeground color hex (e.g. '#ffffff')

No output schema declared.

No examples provided.

clickup_create_task ~248

Create a new task in a list

NameTypeReqDescription
assigneesarrayArray of user IDs to assign
custom_fieldsarrayCustom field values to set
descriptionstringTask description (plain text or markdown)
due_datenumberDue date as Unix timestamp in milliseconds
due_date_timebooleanWhether due_date includes time
list_idstringyesClickUp list ID
markdown_descriptionstringTask description in markdown
namestringyesTask name
notify_allbooleanNotify assignees (default true)
parentstringParent task ID (to create subtask)
prioritynumberPriority: 1=urgent, 2=high, 3=normal, 4=low
start_datenumberStart date as Unix timestamp in milliseconds
start_date_timebooleanWhether start_date includes time
statusstringStatus name (must match list's statuses)
tagsarrayArray of tag names
time_estimatenumberTime estimate in milliseconds

No output schema declared.

No examples provided.

clickup_delete_checklist ~29

Delete a checklist and all its items

NameTypeReqDescription
checklist_idstringyesChecklist ID

No output schema declared.

No examples provided.

clickup_delete_checklist_item ~39

Delete a checklist item

NameTypeReqDescription
checklist_idstringyesChecklist ID
checklist_item_idstringyesChecklist item ID

No output schema declared.

No examples provided.

clickup_delete_dependency ~68

Remove a dependency. Note: uses query params, not body.

NameTypeReqDescription
dependency_ofstringTask ID that this task was blocking
depends_onstringTask ID this task was waiting on
task_idstringyesThe task to remove the dependency from

No output schema declared.

No examples provided.

clickup_delete_list ~34

Delete a list. This is permanent and cannot be undone.

NameTypeReqDescription
list_idstringyesClickUp list ID

No output schema declared.

No examples provided.

clickup_delete_space_tag ~42

Delete a tag from a space

NameTypeReqDescription
space_idstringyesClickUp space ID
tag_namestringyesTag name to delete

No output schema declared.

No examples provided.

clickup_delete_task ~28

Permanently delete a task

NameTypeReqDescription
task_idstringyesClickUp task ID

No output schema declared.

No examples provided.

clickup_delete_task_link ~42

Remove a link between two tasks

NameTypeReqDescription
links_tostringyesSecond task ID to unlink
task_idstringyesFirst task ID

No output schema declared.

No examples provided.

clickup_edit_checklist ~50

Rename or reorder a checklist

NameTypeReqDescription
checklist_idstringyesChecklist ID
namestringNew checklist name
positionnumberNew position (0-indexed)

No output schema declared.

No examples provided.

clickup_edit_checklist_item ~105

Edit a checklist item (name, resolved status, assignee, or parent)

NameTypeReqDescription
assigneenumberUser ID to assign (or null to unassign)
checklist_idstringyesChecklist ID
checklist_item_idstringyesChecklist item ID
namestringNew item name
parentstringParent checklist item ID (to nest items)
resolvedbooleanMark as resolved/unresolved

No output schema declared.

No examples provided.

clickup_edit_space_tag ~82

Edit (rename or recolor) a tag in a space

NameTypeReqDescription
new_namestringNew tag name
space_idstringyesClickUp space ID
tag_bgstringNew background color hex
tag_fgstringNew foreground color hex
tag_namestringyesCurrent tag name

No output schema declared.

No examples provided.

clickup_get_comments ~60

Get comments on a task (paginated, 25 per page)

NameTypeReqDescription
startnumberStart offset for pagination
start_idstringComment ID to start from
task_idstringyesClickUp task ID

No output schema declared.

No examples provided.

clickup_get_folders ~46

List folders in a space (includes nested lists)

NameTypeReqDescription
archivedbooleanInclude archived folders (default false)
space_idstringyesClickUp space ID

No output schema declared.

No examples provided.

clickup_get_list ~32

Get a single list's details including its statuses

NameTypeReqDescription
list_idstringyesClickUp list ID

No output schema declared.

No examples provided.

clickup_get_list_members ~32

Get members with access to a specific list

NameTypeReqDescription
list_idstringyesClickUp list ID

No output schema declared.

No examples provided.

clickup_get_lists ~69

Get lists in a folder, or folderless lists in a space. Provide either folder_id or space_id.

NameTypeReqDescription
archivedbooleanInclude archived lists (default false)
folder_idstringClickUp folder ID
space_idstringClickUp space ID

No output schema declared.

No examples provided.

clickup_get_replies ~28

Get threaded replies to a comment

NameTypeReqDescription
comment_idstringyesComment ID

No output schema declared.

No examples provided.

clickup_get_space_tags ~30

List all tags in a space

NameTypeReqDescription
space_idstringyesClickUp space ID

No output schema declared.

No examples provided.

clickup_get_spaces ~43

List all spaces in a workspace

NameTypeReqDescription
archivedbooleanInclude archived spaces (default false)
team_idstringyesClickUp workspace/team ID

No output schema declared.

No examples provided.

clickup_get_task ~58

Get a task by its ID

NameTypeReqDescription
include_markdown_descriptionbooleanReturn description as markdown
include_subtasksbooleanInclude subtasks (default false)
task_idstringyesClickUp task ID

No output schema declared.

No examples provided.

clickup_get_tasks ~211

List tasks in a list with optional filters

NameTypeReqDescription
archivedbooleanInclude archived tasks
assigneesarrayFilter by assignee IDs
date_created_gtnumberCreated after (ms)
date_created_ltnumberCreated before (ms)
date_updated_gtnumberUpdated after (ms)
date_updated_ltnumberUpdated before (ms)
due_date_gtnumberDue date greater than (ms)
due_date_ltnumberDue date less than (ms)
include_closedbooleanInclude closed tasks
include_markdown_descriptionboolean
list_idstringyesClickUp list ID
order_bystring
pagenumberPage number (0-indexed)
reversebooleanReverse sort order
statusesarrayFilter by status names
subtasksbooleanInclude subtasks

No output schema declared.

No examples provided.

clickup_get_workspace_members ~25

Get all members across all workspaces (extracted from teams response)

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

clickup_remove_tag_from_task ~43

Remove a tag from a task

NameTypeReqDescription
tag_namestringyesTag name to remove
task_idstringyesClickUp task ID

No output schema declared.

No examples provided.

clickup_search_tasks ~202

Search tasks across an entire workspace

NameTypeReqDescription
assigneesarray
date_created_gtnumber
date_created_ltnumber
date_updated_gtnumber
date_updated_ltnumber
due_date_gtnumber
due_date_ltnumber
folder_idsarrayFilter by folder IDs
include_closedboolean
include_markdown_descriptionboolean
list_idsarrayFilter by list IDs
order_bystring
pagenumberPage number (0-indexed)
project_idsarrayFilter by project IDs
reverseboolean
space_idsarrayFilter by space IDs
statusesarray
subtasksboolean
team_idstringyesClickUp workspace/team ID

No output schema declared.

No examples provided.

clickup_set_custom_field ~63

Set a custom field value on a task (update_task cannot do this)

NameTypeReqDescription
field_idstringyesCustom field ID
task_idstringyesClickUp task ID
valueyesCustom field value (type depends on field type)

No output schema declared.

No examples provided.

clickup_update_comment ~67

Edit a comment's text or resolve/unresolve it

NameTypeReqDescription
assigneenumberNew assignee user ID
comment_idstringyesComment ID
comment_textstringNew comment text
resolvedbooleanMark as resolved/unresolved

No output schema declared.

No examples provided.

clickup_update_task ~212

Update a task. Assignees use add/rem arrays, not a flat list.

NameTypeReqDescription
archivedbooleanArchive/unarchive the task
assigneesobjectAssignee changes (add/rem)
descriptionstringNew description
due_datenumberDue date as Unix timestamp in milliseconds
due_date_timeboolean
markdown_descriptionstringNew description in markdown
namestringNew task name
parentstringMove to new parent (set null to unparent)
prioritynumberPriority: 1=urgent, 2=high, 3=normal, 4=low
start_datenumberStart date as Unix timestamp in milliseconds
start_date_timeboolean
statusstringNew status
task_idstringyesClickUp task ID
time_estimatenumberTime estimate in milliseconds

No output schema declared.

No examples provided.

clickup_whoami ~23

Get current user info and list of workspaces with members

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

Common questions

What is the io.github.cvrt-jh/clickup-mcp server?

io.github.cvrt-jh/clickup-mcp is listed in the public MCP registry as io.github.cvrt-jh/clickup-mcp. Lightweight ClickUp MCP server - 37 tools, token-optimized (95% smaller responses). This page covers its npm package (@cavort-it-systems/clickup-mcp).

Is the io.github.cvrt-jh/clickup-mcp server safe to use?

io.github.cvrt-jh/clickup-mcp scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.cvrt-jh/clickup-mcp server expose?

io.github.cvrt-jh/clickup-mcp exposes 37 tools: clickup_whoami, clickup_get_spaces, clickup_get_folders, clickup_get_lists, clickup_get_list, and 32 more. Their descriptions and schemas cost roughly 2,563 tokens of context every time the server is loaded.

Is the io.github.cvrt-jh/clickup-mcp server still maintained?

io.github.cvrt-jh/clickup-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.cvrt-jh/clickup-mcp server under?

io.github.cvrt-jh/clickup-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.