todoist-setup
Warn
Audited by Socket on May 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core Todoist sync purpose is coherent, and direct calls to Todoist’s official API are expected, but the skill also downloads and runs an external MCP package via `npx` and forwards the user’s Todoist API key to it. Combined with raw local token storage and an autonomous sync mode, the footprint is broader and riskier than a minimal setup skill.
Confidence: 87%Severity: 72%
Audit Metadata