Server data from the Official MCP Registry
Free, local MCP server that audits ClickUp, Slack & Teams for work that slipped through.
Free, local MCP server that audits ClickUp, Slack & Teams for work that slipped through.
Pickle is a well-intentioned, open-source MCP server with a privacy-first design and proper SSRF protections. The codebase demonstrates good security practices in token handling and API request validation. However, there are moderate-severity issues: token leakage in error messages, missing input validation on some parameters, and potential information disclosure that users should be aware of. The permissions (network_http, env_vars) are appropriate for the stated purpose of auditing ClickUp/Slack/Teams. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.
3 files analyzed · 12 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Set these up before or after installing:
Environment variable: CLICKUP_API_KEY
Environment variable: SLACK_TOKEN
Environment variable: TEAMS_TOKEN
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-adityaarsharma-pickle": {
"env": {
"SLACK_TOKEN": "your-slack-token-here",
"TEAMS_TOKEN": "your-teams-token-here",
"CLICKUP_API_KEY": "your-clickup-api-key-here"
},
"args": [
"-y",
"pickle-mcp"
],
"command": "npx"
}
}
}From the project's GitHub README.

ClickUp Brain reads your tasks. Slack AI reads your messages. Both are paid add-ons, and each only sees its own app. Pickle is a free AI ops manager that runs on your own machine, reads across all three, and tells you what slipped through: stale tasks, dropped promises, decisions buried in a DM.
Pickle is a free, open-source AI ops manager for your team, packaged as an MCP server you run yourself. Give it your own ClickUp / Slack / Teams token, and your AI client (Claude, Cursor, Codex, Cline, Zed…) audits your workspace the way a sharp ops manager would: catching the work that quietly fell through.
No account. No hosted server. No key from us. No telemetry. Pickle adds no middleman. It talks only to your tools, with your token. Nothing is sent to us, because there's no "us" to send it to.
⭐ Pickle is free and will stay free. There is no paid tier. If you think workspace tools should run on your own machine, star the repo. Stars are the only way it gets found.
| ClickUp Brain | Slack AI | Pickle | |
|---|---|---|---|
| Sees across your tools | ❌ ClickUp only | ❌ Slack only | ✅ ClickUp + Slack + Teams |
| Where your data flows | Their cloud | Their cloud | Only to your own tools, with your token |
| A third party holds your token | Yes | Yes | No, it stays in your local config |
| Cost | Paid add-on | ~$10/user/mo | Free · MIT · open source |
| You can read every line | ❌ | ❌ | ✅ it's all right here |
Honest version of the privacy claim: Pickle does read your ClickUp/Slack/Teams. That's the job. But it reads them directly, from your machine, with your token, and sends nothing to any Pickle server. Verify it yourself. The code is in server-remote/server.mjs, and there is no analytics, no beacon, no phone-home.
Guided: it asks which tools you use, points you to where each token lives, and writes your MCP config for you.
curl -fsSL https://pickle.adityaarsharma.com/install.sh | bash
Or add it to your MCP client yourself (via npm):
{
"mcpServers": {
"pickle": {
"command": "npx",
"args": ["-y", "pickle-mcp"],
"env": { "CLICKUP_API_KEY": "pk_your_own_token" }
}
}
}
Add SLACK_TOKEN (xoxp-…) and/or TEAMS_TOKEN to the same env block to switch on the cross-tool patterns. Restart your client. npx runs it locally on your machine, no global install, no clone.
The installer asks which tools you use (ClickUp / Slack / Teams), takes the token you already have for each, and writes the MCP config for your client automatically. No hand-editing, no key from us.
Prefer to do it by hand? See
docs/manual-install.md. The only token you ever provide is your own platform token (e.g. ClickUppk_…from Settings → Apps).
Then just ask your AI:
"Pickle, audit my ClickUp from the last 7 days. What did I miss?"
docs/patterns.mdClaude Code · Claude Desktop · Cursor · Codex · Cline · Continue · Zed · any MCP host. The reasoning runs in your model. Pickle just fetches and structures the data. Optional Claude Code skills add /pickle-* slash commands as a convenience layer.
Pickle has no paid tier and never will. Instead:
Pickle is what I use to keep my own team honest. If you're rolling AI into how your company works (onboarding people onto it, wiring it into real workflows, choosing which LLM for what), reach out to me. I help teams go from "we bought AI licenses" to "AI is actually in our workflow," with real use-cases instead of hype.
Built in the open by Aditya Sharma, a marketer who codes.
Is Pickle really free? Yes. MIT-licensed, no paid tier, no account, no credit card. I built it in the open; a ⭐ is the only thing I ask.
Do I need a Pickle account or an API key from you? No. Pickle issues nothing. The only token you provide is your own ClickUp / Slack / Teams token, and it lives in your local MCP config.
Does my data get sent to you or to any cloud?
No middleman. Pickle runs on your machine and talks only to your tools (ClickUp / Slack / Microsoft Graph) using your token. There is no Pickle server, no telemetry, no phone-home. Pickle does read your ClickUp/Slack/Teams (that's the job), but it sends nothing to us. Verify it in server-remote/server.mjs.
Which AI clients does it work with? Any MCP-compatible host: Claude Code, Claude Desktop, Cursor, Codex, Cline, Continue, Zed, and more. The reasoning runs in your model.
How is this different from ClickUp Brain or Slack AI? Those are cloud add-ons that each see only their own tool and send your data to their servers. Pickle runs locally, reads across ClickUp + Slack + Teams, and keeps your token on your machine. Different axis: privacy + cross-tool, not "more features."
Is it safe to give it my token?
The token stays in your local config file (chmod 600), and the code is open. Read it before you connect. Nothing is transmitted anywhere except the platform's own API.
Do I need Slack and Teams too, or is ClickUp enough? ClickUp alone is a great start. Slack/Teams unlock the cross-tool patterns (decisions-in-DMs, ghost mode) because those need chat data.
Can it audit GitHub or other tools? Not yet. A GitHub audit (stale PRs, dropped reviews) is a planned/welcome contribution.
Is there a hosted version? No. Pickle is local by design. If you want your team to adopt AI tools like this well, reach out. That's the consulting I do.
Issues and PRs welcome: new patterns, new connectors (a GitHub audit for stale PRs is a great first one), better client configs.
MIT © Aditya Sharma
Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
by mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.