T09 · Insecure Skill Coding Practices
- Location
references/API_CONFIG.json:1- Finding
Plaintext Todoist API Credential Committed in Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Todoist skill should go to Review because it ships a plaintext Todoist token and its documentation understates live account access, including broad sync and task deletion.
Do not install this version without review. The publisher should remove and rotate the packaged Todoist token, make credential handling consistent, clearly document that the script performs live API calls, disable full-account sync by default, document or remove list_tasks, and require explicit confirmation for destructive actions such as deleting tasks.
references/API_CONFIG.json:1Plaintext Todoist API Credential Committed in Configuration
scripts/todoist_api.py:65Undisclosed Live API Execution with Automatic Full-Resource Synchronization
The documented behavior does not match the detected capabilities: undeclared task listing and possible automatic full Todoist synchronization materially expand data access beyond the stated purpose. In a task-management skill, this is especially risky because a full sync can expose all projects and tasks, including sensitive personal or business data, without clear user awareness or consent.
The file contains a hardcoded Todoist API token in plaintext, which is a credential exposure vulnerability. Anyone who can access the repository, packaged skill, logs, or deployment artifacts can use this token to interact with the Todoist account, potentially reading tasks/projects and modifying or deleting data via the API.
The skill appears capable of file access and network/API interaction but does not declare an explicit tool scope such as permissions or allowed-tools. This weakens containment and review because operators cannot easily verify what the skill is allowed to access, increasing the chance of overbroad execution or unintended data exposure.
The documentation says the API token is stored in a local JSON file and not read from environment variables, while the manifest requires an environment variable for the same secret. Conflicting secret-handling instructions can cause insecure credential storage, accidental commits of tokens to disk, or operational confusion that leads users to expose credentials in the wrong place.
The skill documents destructive operations such as task completion and deletion without warning users that these actions may be irreversible or operationally significant. In the Todoist context, this can lead to unintended loss of task state or auditability, especially if an agent executes commands automatically from natural-language prompts.
The skill claims to be a live Todoist-management integration but later states the script is only a mock stub that prints actions. This inconsistency can mislead users and reviewers about whether real external side effects occur, which undermines trust and can result in unsafe deployment assumptions or accidental substitution of unreviewed live code later.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests
# --- Configuration ---
API_URL = "https://api.todoist.com/api/v2"
CONFIG_PATH = "./skills/todoist-manager/references/API_CONFIG.json"
# ---------------------
The code performs a full-account sync using resource_types ['all'] before every command when sync is enabled, even for narrow actions like completing or deleting a single task. This causes unnecessary collection and transmission of the user's broader Todoist data set, violating least privilege and expanding exposure if logs, downstream components, or future code changes mishandle the synced data.
Several success and failure messages are hard-coded in Russian, such as task creation, completion, deletion, and listing output. This imposes a specific language on users without any opt-in or documented locale constraint, which matches the language/locale policy violation category.
The script implements a list_tasks capability that is not declared in the skill metadata or documented command interface. This creates a scope mismatch: a caller or reviewing system may believe the skill only adds/completes/deletes tasks and lists projects, while the code can also enumerate task contents across the account, exposing more user data than expected.
The primary description is written in Russian and presents the skill as operating in that language, but there is no opt-in, alternative locale, or explanation that the skill is intentionally region-specific. The policy requires flagging language or locale constraints when they are imposed without user choice or documented justification.
No suspicious patterns detected.