Back to skill

Security audit

todoist latest

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Todoist command-line integration that can change live Todoist tasks when the user asks it to.

Install only if you want an agent to use your configured td CLI with your Todoist account. Invoke it explicitly for Todoist work, verify the Homebrew tap or Cargo package source, and review any add, edit, complete, bulk complete, or delete action before it runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description includes broad everyday phrases such as "my tasks," "task list," and "add a task," which can cause the skill to activate in contexts where the user did not explicitly intend to use Todoist. Because this skill supports state-changing operations against a real Todoist account, accidental invocation could lead to unintended access to task data or unintended modifications.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents destructive operations like `done`, `delete`, and edit actions without any warning or confirmation guidance. In an agentic setting, this increases the chance that ambiguous or misinterpreted user requests result in irreversible or hard-to-recover changes to the user's task data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.