task-management

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious. The stated purpose is coherent for a Todoist skill, but the actual trust boundary is not: it relies on an unverified `todoist-cli` and passes a real Todoist API token into it. The functionality is proportionate to task management, yet install provenance and credential forwarding make this a high-risk skill rather than a benign direct Todoist integration.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Apr 19, 2026, 07:05 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Ftask-management%2F@56fe334187456c9a09abd5d7256a2bc50e643bd7