Todoist CLI
PassAudited by VirusTotal on May 13, 2026.
Findings (1)
The OpenClaw skill bundle for 'todoist-cli' is benign. The `_meta.json` provides standard metadata. The `skill.md` clearly defines the skill's purpose, installation methods (via brew or go install from GitHub), and usage examples, all focused on managing Todoist tasks. There are no indications of prompt injection attempts against the AI agent, no commands designed for data exfiltration, persistence, or unauthorized execution. The required `TODOIST_API_TOKEN` is a legitimate credential for the tool's intended function.
