clickup-debug-bundle

v2026.09.24

Collect a minimal redacted ClickUp connectivity and contract bundle without task bodies, tokens, or webhook secrets. Use when escalating a ClickUp API incident. Trigger with "ClickUp debug bundle", "ClickUp diagnostics", or "collect ClickUp evidence".

GitHub
Install command
npx skhub add jeremylongshore/clickup-debug-bundle
Markdown
SKILL.md

ClickUp Redacted Diagnostic Bundle

Overview

Create supportable evidence while preventing a troubleshooting artifact from becoming a second sensitive-data store. Make every included field explainable to the named reviewer.

Prerequisites

  • An incident identifier, approved output directory, retention deadline, and named reviewer
  • A scoped credential stored outside command history and artifact content
  • An allow-list of read-only probes and fields

Tool Discipline

Use Read, Glob, and Grep to inspect the repository, adapters, configuration names, tests, and evidence. Use WebFetch only for current official ClickUp documentation. Use Write or Edit after confirming the target file, Workspace boundary, and requested mode.

Current Contract

  • Useful evidence includes status, endpoint version, latency, response type, sanitized error code, and rate headers.
  • GET /api/v2/user and GET /api/v2/team can prove identity and authorized Workspaces without reading task content.
  • Provider status is separate from tenant authorization and application behavior.
  • Authorization headers, response bodies, user emails, task names, comments, attachments, and webhook secrets are excluded.

Authentication

Use a personal token only for accountable individual/testing work or OAuth Authorization Code for a user-facing integration. Inject the token server-side through a governed secret reference, send it in Authorization, verify authorized Workspace IDs, and never print the token, OAuth client secret, or webhook secret.

Instructions

  1. Confirm incident scope, collection owner, field allow-list, output path, and deletion deadline.
  2. Inspect local configuration names and versions without printing values.
  3. Run bounded read-only identity/workspace and status probes; capture only approved metadata.
  4. Record sanitized rate headers, status codes, timings, schema digests, and local adapter versions.
  5. Scan the bundle for credential and content patterns; require human review before sharing.
  6. Hash, transfer through the approved channel, and delete or retain on schedule.

Approval Boundaries

Do not add raw headers, full environment dumps, task payloads, member records, or attachments to make the bundle more convenient.

Output

Return bundle path, SHA-256, included field classes, excluded classes, scan result, reviewer, sharing decision, and deletion deadline.

Error Handling

ConditionResponse
Redaction scan finds a secretDo not share; quarantine, rotate, and regenerate.
Probe would read work contentSkip it and record the evidence gap.
Output directory is uncontrolledRefuse collection until a governed location exists.
Incident scope expandsObtain a new collection approval.

Examples

The example below is a redacted operator receipt; it contains no task text, member data, credential, or webhook secret.

incident=CU-142; probes=3; task-bodies=0; secrets=0; sha256=recorded; review=approved; delete-by=2026-09-17

Resources

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

skills/.curated/clickup-debug-bundle

Default branch

main

Latest commit

e5a6c3b

Tree SHA

c2dc8e8