Back to skill

Security audit

Todoist Task Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Todoist CLI guide with expected task-management powers, but users should protect the Todoist API token and be careful with delete or complete commands.

Install only if you are comfortable giving the Todoist CLI access to your Todoist account. Store the API token like a password, restrict permissions on ~/.config/todoist/config.json, avoid committing or sharing it, and preview task IDs before using complete or delete commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:14
Finding

Todoist API Token Stored Without Restrictive File Permissions

Content
View full analysis
~/.config/todoist/config.json ``` ``` ### Technical Analysis The setup instructions store a long-lived Todoist API token in a plaintext configuration file but do not establish restrictive permissions for either the containing directory or the file. `mkdir -p` applies permissions according to the user's current `umask`, while shell redirection creates `config.json` using similarly inherited permissions. With a permissive or misconfigured `umask`, the directory may be traversable and the configuration file may be readable by other local users or processes. The instructions also do not verify or correct permissions on an existing directory or configuration file. Although the CLI may require a file-based token, the credential should be protected explicitly rather than relying on environment-specific defaults. ### Attack Path 1. A user follows the documented setup procedure and places a valid Todoist API token in `~/.config/todoist/config.json`. 2. The user's `umask` or pre-existing directory permissions result in the directory being traversable and the file being readable by another local account or untrusted process. 3. The attacker reads the token from the configuration file. 4. The attacker uses the stolen token with the Todoist API or a compatible client. 5. The attacker accesses or manipulates Todoist data within the permissions granted to that token. This exploitation path requires local filesystem access through another account, a compromised local process, or an equivalent ability to read files under the user's home directory. ### Impact Assessme ...[truncated 478 chars]
Remediation
View remediation
~/.config/todoist/config.json chmod 600 ~/.config/todoist/config.json ``` Additional hardening measures: - Verify and correct permissions even when the directory or file already exists. - Prefer an operating-system credential store or secret manager if supported by the CLI. - Avoid placing the real token directly in shell commands where it may be retained in shell history. - Do not print, log, or commit the token. - Rotate the token immediately if unauthorized filesystem access or credential exposure is suspected. - Document the expected permissions: `0700` for `~/.config/todoist` and `0600` for `config.json`. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup instructions tell users to place a Todoist API token in a local config file but do not label it as a sensitive secret or mention file-permission and leakage risks. API tokens grant account access, so normalizing plaintext storage without caution can lead to credential exposure through shell history, backups, logs, or overly permissive filesystem access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill instructs users to persist an authentication token in ~/.config/todoist/config.json, creating long-lived session material on disk. Persistent credentials are a real security concern because compromise of the local account, backups, or dotfiles can expose the token and allow unauthorized Todoist access until revoked.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

  1. Install: brew install todoist-cli
  2. Get your API token from https://app.todoist.com/app/settings/integrations/developer
  3. Create config:
bash
mkdir -p ~/.config/todoist
echo '{"token": "YOUR_API_TOKEN"}' > ~/.config/todoist/config.json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents destructive operations like todoist close and todoist delete without any warning, confirmation guidance, or note that these actions change or remove user data. In an agent setting, that omission increases the chance of accidental task completion or deletion when the model translates a vague request into a command.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.