High-risk tools in ClickUp MCP Server - Enhanced
9 of the 202 tools in ClickUp MCP Server - Enhanced are classified as high risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at high risk
-
clickup_add_processing_ruleExecute⚙️ **PROCESSING RULE ENGINE** - Add custom processing rules for real-time event handling. Define conditions and actions for automated responses to ClickUp events.
-
clickup_bulk_attachment_operationsExecutePerform bulk operations on multiple attachments for efficiency.
-
clickup_ping_webhookExecuteSend a test ping to a webhook endpoint to verify it
-
clickup_process_webhookExecuteProcess an incoming webhook payload and extract structured information about the event.
-
clickup_resolve_dependency_conflictsExecuteAutomatically resolve dependency conflicts such as circular dependencies and invalid statuses.
-
clickup_retry_webhook_eventsExecuteRetry failed webhook events for a specific webhook.
-
clickup_start_realtime_engineExecute🚀 **REAL-TIME PROCESSING ENGINE** - Start the real-time data processing engine for live ClickUp integration. Enables WebSocket connections, event streaming, and real-time analy...
-
clickup_start_timerExecuteStart a timer for the authenticated user. Optionally associate with a task.
-
clickup_stop_realtime_engineExecute🛑 **STOP REAL-TIME ENGINE** - Gracefully stop the real-time processing engine and return final metrics.
Attacks that target this class
High-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.