Critical-risk tools in ClickUp MCP Server - Enhanced
22 of the 202 tools in ClickUp MCP Server - Enhanced are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
clickup_bulk_delete_tasksDestructive⚠️ DESTRUCTIVE: Delete multiple tasks from ClickUp in a single operation. This action cannot be undone and will permanently remove all specified tasks.
-
clickup_delete_attachmentDestructiveDelete an attachment from ClickUp. This action cannot be undone.
-
clickup_delete_chat_messageDestructiveDelete a message from a chat channel. This action cannot be undone.
-
clickup_delete_chat_message_reactionDestructiveRemove a reaction from a message in a chat channel.
-
clickup_delete_checklistDestructiveDelete a checklist from a ClickUp task. Removes the checklist and all its items.
-
clickup_delete_checklist_itemDestructiveDelete an item from a ClickUp checklist.
-
clickup_delete_commentDestructiveDelete a comment from ClickUp.
-
clickup_delete_custom_fieldDestructiveDelete a custom field from ClickUp. This will remove the field and all its values from tasks. This action cannot be undone.
-
clickup_delete_dependencyDestructiveDelete a dependency relationship between tasks.
-
clickup_delete_docDestructive⚠️ DESTRUCTIVE: Delete a ClickUp document. This action cannot be undone and will permanently remove the document and all its content.
-
clickup_delete_doc_pageDestructiveDelete a page from a ClickUp document. This action cannot be undone.
-
clickup_delete_folderDestructiveDelete a folder from ClickUp. Removes the folder and its contents.
-
clickup_delete_goalDestructiveDelete a goal from ClickUp. This action cannot be undone and will remove all associated targets.
-
clickup_delete_goal_targetDestructiveDelete a target from a goal. This action cannot be undone.
-
clickup_delete_listDestructive⚠️ DESTRUCTIVE: Delete a list from ClickUp. This action cannot be undone and will permanently remove the list and all its tasks.
-
clickup_delete_subtaskDestructive⚠️ DESTRUCTIVE: Delete a subtask from ClickUp. This action cannot be undone and will permanently remove the subtask.
-
clickup_delete_taskDestructive⚠️ DESTRUCTIVE: Delete a task from ClickUp. This action cannot be undone and will permanently remove the task and all its data.
-
clickup_delete_time_entryDestructiveDelete a time entry from ClickUp. This action cannot be undone.
-
clickup_delete_viewDestructiveDelete a view from ClickUp. This action cannot be undone.
-
clickup_delete_webhookDestructiveDelete a webhook from ClickUp. This will stop all notifications to the webhook endpoint.
-
clickup_merge_tasksDestructiveMerge multiple tasks into a single task. The primary task will retain all data, and secondary tasks will be deleted after merging their content.
-
clickup_remove_chat_channel_memberDestructiveRemove a user from a chat channel membership.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.