Back to skill

Security audit

todoist-mind

Security checks for vulnerabilities and agentic risk

Overview

This Todoist skill should go to Review because it ships a plaintext Todoist token and its documentation understates live account access, including broad sync and task deletion.

Do not install this version without review. The publisher should remove and rotate the packaged Todoist token, make credential handling consistent, clearly document that the script performs live API calls, disable full-account sync by default, document or remove list_tasks, and require explicit confirmation for destructive actions such as deleting tasks.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/API_CONFIG.json:1
Finding

Plaintext Todoist API Credential Committed in Configuration

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/todoist_api.py:65
Finding

Undisclosed Live API Execution with Automatic Full-Resource Synchronization

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior does not match the detected capabilities: undeclared task listing and possible automatic full Todoist synchronization materially expand data access beyond the stated purpose. In a task-management skill, this is especially risky because a full sync can expose all projects and tasks, including sensitive personal or business data, without clear user awareness or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains a hardcoded Todoist API token in plaintext, which is a credential exposure vulnerability. Anyone who can access the repository, packaged skill, logs, or deployment artifacts can use this token to interact with the Todoist account, potentially reading tasks/projects and modifying or deleting data via the API.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill appears capable of file access and network/API interaction but does not declare an explicit tool scope such as permissions or allowed-tools. This weakens containment and review because operators cannot easily verify what the skill is allowed to access, increasing the chance of overbroad execution or unintended data exposure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation says the API token is stored in a local JSON file and not read from environment variables, while the manifest requires an environment variable for the same secret. Conflicting secret-handling instructions can cause insecure credential storage, accidental commits of tokens to disk, or operational confusion that leads users to expose credentials in the wrong place.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents destructive operations such as task completion and deletion without warning users that these actions may be irreversible or operationally significant. In the Todoist context, this can lead to unintended loss of task state or auditability, especially if an agent executes commands automatically from natural-language prompts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill claims to be a live Todoist-management integration but later states the script is only a mock stub that prints actions. This inconsistency can mislead users and reviewers about whether real external side effects occur, which undermines trust and can result in unsafe deployment assumptions or accidental substitution of unreviewed live code later.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/todoist_api.py (reported line 8)May include surrounding context.

python
import requests

# --- Configuration ---
API_URL = "https://api.todoist.com/api/v2"
CONFIG_PATH = "./skills/todoist-manager/references/API_CONFIG.json"
# ---------------------

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code performs a full-account sync using resource_types ['all'] before every command when sync is enabled, even for narrow actions like completing or deleting a single task. This causes unnecessary collection and transmission of the user's broader Todoist data set, violating least privilege and expanding exposure if logs, downstream components, or future code changes mishandle the synced data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several success and failure messages are hard-coded in Russian, such as task creation, completion, deletion, and listing output. This imposes a specific language on users without any opt-in or documented locale constraint, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script implements a list_tasks capability that is not declared in the skill metadata or documented command interface. This creates a scope mismatch: a caller or reviewing system may believe the skill only adds/completes/deletes tasks and lists projects, while the code can also enumerate task contents across the account, exposing more user data than expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The primary description is written in Russian and presents the skill as operating in that language, but there is no opt-in, alternative locale, or explanation that the skill is intentionally region-specific. The policy requires flagging language or locale constraints when they are imposed without user choice or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.