Critical-risk tools in ClickUp MCP - Premium
8 of the 54 tools in ClickUp MCP - Premium are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
delete_bulk_tasksDestructive 4/5PERMANENTLY delete multiple tasks. Each task needs: taskId or taskName + listName. Cannot be undone.
-
delete_folderDestructive 4/5Delete folder. Requires folderId (preferred) or folderName + space info. WARNING: Permanent.
-
delete_listDestructive 4/5Delete list. Requires listId (preferred) or listName. WARNING: Permanent.
-
delete_space_tagDestructive 4/5Delete tag from ClickUp space. Requires tagName + (spaceId or spaceName). Warning: removes from all tasks, cannot be undone.
-
delete_taskDestructive 4/5PERMANENTLY delete task. If a task name is provided do not lookup the task ID, it will be resolved automatically. Cannot be undone.
-
delete_task_linkDestructive 4/5Remove link between tasks. Requires taskId (preferred) and linkId (target task ID).
-
delete_time_entryDestructive 4/5Delete a time entry. Requires timeEntryId.
-
remove_tag_from_taskDestructive 4/5Remove tag from task. Requires tagName + (taskId or taskName + optional listName). Only removes association; tag remains in space.
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.
More on ClickUp MCP - Premium
Enforce policy on ClickUp MCP - Premium
One command generates a policy scaffold for every server in your MCP config.
npx -y @policylayer/intercept init