todoist-automation

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes task content and project data from Todoist which serves as a potential vector for indirect prompt injection. • Ingestion points: Data retrieved via TODOIST_GET_ALL_TASKS and TODOIST_GET_ALL_PROJECTS (SKILL.md). • Boundary markers: None present to differentiate between data and instructions. • Capability inventory: Extensive task and project modification tools allow for significant changes to the user account (SKILL.md). • Sanitization: No instructions provided for sanitizing or escaping retrieved content.
  • [EXTERNAL_DOWNLOADS]: The skill references an external MCP server endpoint (https://rube.app/mcp) and documentation from a third-party service (composio.dev).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — todoist-automation