task-management
Warn
Audited by Socket on Apr 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Suspicious. The stated purpose is coherent for a Todoist skill, but the actual trust boundary is not: it relies on an unverified `todoist-cli` and passes a real Todoist API token into it. The functionality is proportionate to task management, yet install provenance and credential forwarding make this a high-risk skill rather than a benign direct Todoist integration.
Confidence: 86%Severity: 84%
Audit Metadata