Borrowing it
Nothing to install: this file belongs to sebastienheyd/clickup-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/sebastienheyd/clickup-mcp/main/CLAUDE.mdgit clone --depth 1 https://github.com/sebastienheyd/clickup-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/sebastienheyd/clickup-mcp/claude-md)<a href="https://agentmods.dev/instructions/sebastienheyd/clickup-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/sebastienheyd/clickup-mcp/claude-md/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/instructions/sebastienheyd/clickup-mcp/claude-md"><img src="https://agentmods.dev/badge/instructions/sebastienheyd/clickup-mcp/claude-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00734 | $0.00734 |
| Opus 5 | $0.00367 | $0.00367 |
| Sonnet 5 | $0.00147 | $0.00147 |
| Haiku 4.5 | $0.00073 | $0.00073 |
Grade A, and why
clickup-mcp CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
- ClickUp api documentation is available here: https://developer.clickup.com/reference/gettasks
- Think about api limits. ClickUp allows 100 api calls per minute per user. A typical workflow must not exceed that.
- Implement caching by using a global variable and setting it to null after a setTimeout with GLOBAL_REFRESH_INTERVAL. The ClickUp Api limit resets after a minute, so we usually don't need to cache longer than a minute.
- Cache promises, not results, to prevent race conditions when multiple concurrent calls happen before the first completes (see getAllTeamMembers, getCurrentUser, getTaskSearchIndex, getSpaceSearchIndex patterns).
- Use "npm run build" to compile the typescript for validation.
- Use "npm run cli" to test mcp calls.
- CLI syntax: npm run cli key=value key2=""quoted string"" arrayKey='["item1","item2"]' objectKey='{"field":"value"}'
- For multi-line values (markdown descriptions/comments) call "npx ts-node src/cli.ts" directly - "npm run cli" re-splits arguments through a second shell and loses them.
- Use "npm run test" to run tests.
- Use "npm run smoke" after a build to check the MCP protocol layer (initialize, tools/list, schemas) - "npm run cli" calls tool callbacks directly and never exercises stdio transport or tool registration. Add "-- <task_id> <image.png>" to also post a real comment with an image.
- Tests need src/tests/setup.ts preloaded (see the test script): it points global fetch at the npm undici so MockAgent can intercept. Node's built-in fetch uses Node's own bundled undici, which MockAgent cannot reach.
- Use console.error to prevent writing log messages to stdout.
- MCPB manifest.json spec is at https://github.com/anthropics/mcpb/blob/main/README.md - update tools section when adding new MCP tools.
- Update the CHANGELOG.md when changing or implementing a new feature.
- Backwards compatibility does not matter, an LLM will understand new parameters.
- Mention ID's, not just names, when outputting references. for example "User: Username (user_id: 12345)"
PUT /api/v2/comment/{id}accepts the same undocumented richcommentfragment array as comment creation (the API reference only listscomment_text, andassignee/resolvedare not actually required). Sendingcommentandcomment_texttogether appends the latter. There is noGET /comment/{id}, so editComment reads the task's comment list to check author and age. That list returns only the 25 newest comments per page -start_dateis not a real parameter and is ignored; older pages needstart+start_idof the previous page's last comment.- Image writing lives in src/shared/attachments.ts: markdown image sources are uploaded to the task, then comments get a
type: "image"fragment carrying the whole attachment object (a bare URL string renders as an empty tile), while descriptions only need the markdown URL swapped. Attachments always belong to a task - doc pages cannot have them. Reading renders images back asmarkdown (clickup-text.tstoMarkdownImage) so a comment read via getTaskById can be fed straight back into editComment without losing them - keep that read/write symmetry intact. - Commit messages and CHANGELOG entries must always be written in English.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 20 lines · 734 tokens per session scan A dfcb0b501c9b
clickup-mcp CLAUDE.md is an instructions file published in the GitHub repository sebastienheyd/clickup-mcp (0 stars, last pushed 23d ago), licensed MIT. It adds 734 tokens to every session, about $0.0037 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
deepseek-harness AGENTS.md
AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.