Back to skill

Security audit

Todoist Litiao

Security checks for vulnerabilities and agentic risk

Overview

This Todoist skill is mostly coherent, but it needs Review because it can change or delete Todoist account data and gives broad invocation, global install, and token-handling guidance without enough safeguards.

Install only if you intend an agent to access and modify your Todoist account. Prefer an exact reviewed CLI version, avoid putting the API token directly in shell history, and require confirmation before actions that complete, move, update, reopen, or delete tasks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned Third-Party npm Package Installed Globally

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 19
Vulnerability Type: Supply-chain exposure through a mutable third-party dependency
Risk Level: Medium

Vulnerable Code:

bash
# Requires todoist-ts-cli >= 0.2.0 (for --top / --order)
npm install -g todoist-ts-cli@^0.2.0

Technical Analysis

The installation command uses the mutable semantic-version range ^0.2.0. For a package below version 1.0.0, this permits npm to resolve a later compatible 0.2.x release rather than an exact, previously audited artifact.

The command also installs the package globally. npm packages can define lifecycle scripts that execute during installation with the privileges of the invoking user. Consequently, compromise of the package publisher, registry artifact, or a subsequently released compatible version could result in arbitrary local code execution. The skill does not provide a lockfile, package-integrity hash, verified provenance, or instructions to disable installation scripts.

This is a supply-chain weakness rather than evidence that the currently published dependency is malicious.

Attack Path

  1. An attacker compromises the npm publisher account or another part of the package publication process.
  2. The attacker publishes a malicious release accepted by the ^0.2.0 range.
  3. A user follows the documented global installation command.
  4. npm resolves and downloads the attacker-controlled compatible version.
  5. Malicious package code or an npm lifecycle script executes with the installing user's privileges.
  6. The package may then access user-readable data, credentials, and Todoist operations available through the configured token.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the account running npm. The attacker could access or modify files available to that account, steal environment variables and credentials, or misuse the configured Todoist ...[truncated 201 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to an exact, reviewed version rather than using a caret range.
  • Prefer a project-local, lockfile-backed installation over a global installation.
  • Verify package provenance and registry ownership before recommending the dependency.
  • Record and verify the package integrity hash in a lockfile.
  • Audit package contents and lifecycle scripts before installation.
  • Where compatible with the package, use npm install --ignore-scripts to prevent lifecycle-script execution.
  • Provide a controlled update process in which each new dependency version is reviewed before the pinned version changes.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:25
Finding

Todoist API Token Exposed Through Command-Line Authentication

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25–30
Vulnerability Type: Sensitive credential exposure through command arguments
Risk Level: Medium

Vulnerable Code:

bash
2. Either:
   ```bash
   todoist auth <your-token>
   # or
   export TODOIST_API_TOKEN="your-token"
   ```

Technical Analysis

The primary authentication example instructs the user to substitute a Todoist API token directly into a command-line argument. The resulting command may be retained in shell history and can be captured by command logging, terminal telemetry, audit systems, or process inspection while it executes.

The alternative environment-variable method avoids placing the token directly in the argument list, but environment variables can still be inherited by child processes or exposed through diagnostics. Neither method documents secure secret storage, restricted configuration-file permissions, hidden interactive input, or token rotation following accidental disclosure.

Attack Path

  1. A user runs todoist auth with the actual API token as a command-line argument.
  2. The shell records the command in its history, or local monitoring captures the process arguments.
  3. Another local user, support bundle, synchronization service, malicious process, or log reader obtains the recorded token.
  4. The attacker uses the token with the Todoist API or compatible tooling.
  5. The attacker accesses or manipulates Todoist data within the permissions granted to that token.

Impact Assessment

Exposure can allow unauthorized access to the victim's Todoist account data within the token's scope. Based on the documented CLI operations, this may include reading tasks, projects, labels, and comments, as well as creating, updating, completing, reopening, moving, commenting on, or deleting tasks. This issue does not by itself grant operating-system privilege escalation; its principal impact is compromise of ...[truncated 47 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the example that accepts the API token as a command-line argument.
  • Use hidden interactive input that does not echo the token or place it in shell history.
  • Store the token in an operating-system credential manager or a dedicated secret store.
  • If a secret file is supported, require restrictive file permissions and ensure it is excluded from version control and backups where appropriate.
  • If an environment variable must be used, set it only for the required process and avoid placing it in shared shell initialization files.
  • Document how to revoke and rotate a Todoist API token after suspected disclosure.
  • Warn users against including tokens in logs, screenshots, support bundles, or command examples.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is broad enough to match common requests about tasks, reminders, and productivity, which increases the chance the agent invokes this skill in ordinary conversations without clear user intent to access Todoist. Because the skill can read and modify external account data, over-broad triggering can lead to unintended data exposure or unauthorized task changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation includes destructive and state-changing commands like complete, reopen, move, update, and delete without warning that they modify persistent user data. In an agent setting, this can normalize direct execution of risky operations and increase the likelihood of accidental or premature changes to a user's task database.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.