Pndr

PassAudited by ClawScan on May 1, 2026.

Overview

Pndr appears to be a coherent productivity-account MCP integration, but installing it gives an AI authorized access to read, create, edit, and delete private Pndr data.

This skill looks purpose-aligned and does not ship executable code, but you should install it only if you are comfortable giving your AI assistant access to your Pndr account. Use a revocable token, keep credentials private, and ask the assistant to confirm before deleting or broadly changing your data.

Findings (3)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Anyone or any agent with the configured token may be able to access and modify the user's Pndr data according to the token's permissions.

Why it was flagged

The skill requires OAuth credentials or an access token for the user's Pndr account. This is expected for the integration, but it is sensitive authority over the account.

Skill content
Then provide your Pndr OAuth credentials when prompted.
Recommendation

Use a dedicated Pndr OAuth client or token if possible, avoid pasting secrets into ordinary chats, and revoke the token if you stop using the integration.

What this means

Mistaken or overly broad agent actions could remove or alter tasks, lists, journal entries, habits, packages, tags, or comments.

Why it was flagged

The MCP tool catalog includes destructive account operations. These are consistent with a productivity manager, but users should understand that the agent may be able to delete or change stored data.

Skill content
`delete_list` - Delete a list and all its items
Recommendation

Ask the agent to confirm before deletions or bulk edits, and review important changes in Pndr when using the integration.

What this means

Private productivity and journal data may be included in AI interactions when the assistant uses the Pndr MCP tools.

Why it was flagged

The skill intentionally connects an AI assistant to private Pndr account data over MCP. This is the core purpose, but it means personal tasks, journal content, package data, and related records can be retrieved or changed through the integration.

Skill content
Pndr exposes your personal productivity data through the Model Context Protocol (MCP), allowing AI assistants to interact with your tasks, habits, and journal on your behalf.
Recommendation

Only connect this skill to an assistant and MCP client you trust, and avoid storing highly sensitive journal entries or attachments if you do not want them accessible through AI tooling.