Server data from the Official MCP Registry
Free, local MCP server that audits ClickUp, Slack & Teams for work that slipped through.
About
Free, local MCP server that audits ClickUp, Slack & Teams for work that slipped through.
Security Report
Pickle is a well-intentioned, open-source MCP server with a privacy-first design and proper SSRF protections. The codebase demonstrates good security practices in token handling and API request validation. However, there are moderate-severity issues: token leakage in error messages, missing input validation on some parameters, and potential information disclosure that users should be aware of. The permissions (network_http, env_vars) are appropriate for the stated purpose of auditing ClickUp/Slack/Teams. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.
3 files analyzed · 12 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: CLICKUP_API_KEY
Environment variable: SLACK_TOKEN
Environment variable: TEAMS_TOKEN
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-adityaarsharma-pickle": {
"env": {
"SLACK_TOKEN": "your-slack-token-here",
"TEAMS_TOKEN": "your-teams-token-here",
"CLICKUP_API_KEY": "your-clickup-api-key-here"
},
"args": [
"-y",
"pickle-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
🥒 Pickle: the free AI ops manager for ClickUp, Slack & Teams

ClickUp Brain reads your tasks. Slack AI reads your messages. Both are paid add-ons, and each only sees its own app. Pickle is a free AI ops manager that runs on your own machine, reads across all three, and tells you what slipped through: stale tasks, dropped promises, decisions buried in a DM.
Pickle is a free, open-source AI ops manager for your team, packaged as an MCP server you run yourself. Give it your own ClickUp / Slack / Teams token, and your AI client (Claude, Cursor, Codex, Cline, Zed…) audits your workspace the way a sharp ops manager would: catching the work that quietly fell through.
No account. No hosted server. No key from us. No telemetry. Pickle adds no middleman. It talks only to your tools, with your token. Nothing is sent to us, because there's no "us" to send it to.
⭐ Pickle is free and will stay free. There is no paid tier. If you think workspace tools should run on your own machine, star the repo. Stars are the only way it gets found.
Why this is different
| ClickUp Brain | Slack AI | Pickle | |
|---|---|---|---|
| Sees across your tools | ❌ ClickUp only | ❌ Slack only | ✅ ClickUp + Slack + Teams |
| Where your data flows | Their cloud | Their cloud | Only to your own tools, with your token |
| A third party holds your token | Yes | Yes | No, it stays in your local config |
| Cost | Paid add-on | ~$10/user/mo | Free · MIT · open source |
| You can read every line | ❌ | ❌ | ✅ it's all right here |
Honest version of the privacy claim: Pickle does read your ClickUp/Slack/Teams. That's the job. But it reads them directly, from your machine, with your token, and sends nothing to any Pickle server. Verify it yourself. The code is in server-remote/server.mjs, and there is no analytics, no beacon, no phone-home.
Install: one command
Guided: it asks which tools you use, points you to where each token lives, and writes your MCP config for you.
curl -fsSL https://pickle.adityaarsharma.com/install.sh | bash
Or add it to your MCP client yourself (via npm):
{
"mcpServers": {
"pickle": {
"command": "npx",
"args": ["-y", "pickle-mcp"],
"env": { "CLICKUP_API_KEY": "pk_your_own_token" }
}
}
}
Add SLACK_TOKEN (xoxp-…) and/or TEAMS_TOKEN to the same env block to switch on the cross-tool patterns. Restart your client. npx runs it locally on your machine, no global install, no clone.
The installer asks which tools you use (ClickUp / Slack / Teams), takes the token you already have for each, and writes the MCP config for your client automatically. No hand-editing, no key from us.
Prefer to do it by hand? See
docs/manual-install.md. The only token you ever provide is your own platform token (e.g. ClickUppk_…from Settings → Apps).
Then just ask your AI:
"Pickle, run my morning audit: scan my ClickUp from the last 7 days and show me the 3 worst things I missed, worst first."
What it catches
- Stale in-progress: "doing" for days, zero activity
- Dropped promises: "I'll do X by Friday" with no follow-through
- Decisions buried in DMs: a call made in a thread that never became a task
- Delegations nobody chased: you asked, it never landed, everyone forgot
- Standup copy-paste, zombie tasks, empty-description work, blocker rot… full list in
docs/patterns.md
Works with
Claude Code · Claude Desktop · Cursor · Codex · Cline · Continue · Zed · any MCP host. The reasoning runs in your model. Pickle just fetches and structures the data. Optional Claude Code skills add /pickle-* slash commands as a convenience layer.
Free, and what I ask instead of money
Pickle has no paid tier and never will. Instead:
- ⭐ Star the repo if it caught even one thing worth fixing. A free tool has no ad budget, so a star is genuinely how the next person finds it.
- 📮 Get update notes + workspace-AI tips: occasional, practical notes on using AI in real team workflows (the same patterns Pickle runs). Reply anytime with a suggestion or a pattern you want added. I read every one.
🧭 Want your team to actually use AI well?
Pickle is what I use to keep my own team honest. If you're rolling AI into how your company works (onboarding people onto it, wiring it into real workflows, choosing which LLM for what), reach out to me. I help teams go from "we bought AI licenses" to "AI is actually in our workflow," with real use-cases instead of hype.
Built in the open by Aditya Sharma, a marketer who codes.
FAQ
Is Pickle really free? Yes. MIT-licensed, no paid tier, no account, no credit card. I built it in the open; a ⭐ is the only thing I ask.
Do I need a Pickle account or an API key from you? No. Pickle issues nothing. The only token you provide is your own ClickUp / Slack / Teams token, and it lives in your local MCP config.
Does my data get sent to you or to any cloud?
No middleman. Pickle runs on your machine and talks only to your tools (ClickUp / Slack / Microsoft Graph) using your token. There is no Pickle server, no telemetry, no phone-home. Pickle does read your ClickUp/Slack/Teams (that's the job), but it sends nothing to us. Verify it in server-remote/server.mjs.
Which AI clients does it work with? Any MCP-compatible host: Claude Code, Claude Desktop, Cursor, Codex, Cline, Continue, Zed, and more. The reasoning runs in your model.
What should I ask Pickle first? After installing, restart your AI client and paste: "Pickle, run my morning audit: scan my ClickUp from the last 7 days and show me the 3 worst things I missed, worst first." You get a ranked, punchy result instead of a data dump, so you feel the value on the first run.
How is this different from ClickUp Brain or Slack AI? Those are cloud add-ons that each see only their own tool and send your data to their servers. Pickle runs locally, reads across ClickUp + Slack + Teams, and keeps your token on your machine. Different axis: privacy + cross-tool, not "more features."
Is it safe to give it my token?
The token stays in your local config file (chmod 600), and the code is open. Read it before you connect. Nothing is transmitted anywhere except the platform's own API.
Will Pickle change or delete anything in my tools?
The audit itself is read-only — it only reads and reports. Pickle can create a reminder, drop a comment, or make a task if you explicitly ask it to (for example "remind me about XYZ-184"), because the server also exposes write tools for that. If you want a hard, code-level guarantee that nothing can be written or deleted no matter what a model asks, set PICKLE_READONLY=1 in the env block — it blocks every mutating tool at the server. Details in docs/security.md. You stay in control.
Do I need Slack and Teams too, or is ClickUp enough? ClickUp alone is a great start. Slack/Teams unlock the cross-tool patterns (decisions-in-DMs, ghost mode) because those need chat data.
Can it audit GitHub or other tools? Not yet. A GitHub audit (stale PRs, dropped reviews) is a planned/welcome contribution.
Is there a hosted version? No. Pickle is local by design. If you want your team to adopt AI tools like this well, reach out. That's the consulting I do.
Contributing
Issues and PRs welcome: new patterns, new connectors (a GitHub audit for stale PRs is a great first one), better client configs.
License
MIT © Aditya Sharma
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
