todoist-automation
Warn
Audited by Socket on Oct 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The Todoist automation scope is coherent, but the skill's setup is outdated and routes all access through a Composio/Rube MCP intermediary instead of direct Todoist APIs. That makes the trust and data-flow model broader than necessary and potentially broken, though there is no clear evidence of credential theft or malicious payload execution.
Confidence: 89%Severity: 58%
Audit Metadata