todoist-automation
Warn
Audited by Socket on Jun 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities match Todoist automation, and the endpoint appears to be officially operated by Composio, so this is not overt malware. However, all Todoist data and delegated access are funneled through a third-party MCP proxy rather than direct official Todoist endpoints, which creates a meaningful trust and data-flow risk disproportionate to a simple Todoist helper.
Confidence: 86%Severity: 58%
Audit Metadata