todoist-automation

Warn

Audited by Socket on Oct 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The Todoist automation scope is coherent, but the skill's setup is outdated and routes all access through a Composio/Rube MCP intermediary instead of direct Todoist APIs. That makes the trust and data-flow model broader than necessary and potentially broken, though there is no clear evidence of credential theft or malicious payload execution.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Oct 8, 2026, 08:59 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Ftodoist-automation%2F@b45e49ff7e5b29787b7298a1ded4ac17093649afe414de9252874d36b05b5d6f