todoist-automation

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities match Todoist automation, and the endpoint appears to be officially operated by Composio, so this is not overt malware. However, all Todoist data and delegated access are funneled through a third-party MCP proxy rather than direct official Todoist endpoints, which creates a meaningful trust and data-flow risk disproportionate to a simple Todoist helper.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Jun 19, 2026, 09:45 PM
Package URL
pkg:socket/skills-sh/ncdevshiv%2FNC-skills-mcp%2Ftodoist-automation%2F@52ac3ff75f306ce2f9f33c66878100294827f3bef1bf0c2500b2a6e284691470
Security Audit — socket — todoist-automation