Back to skill

Security audit

Todoist

Security checks for vulnerabilities and agentic risk

Overview

This Todoist skill is mostly coherent, but it asks users to install an unpinned global CLI and handle a Todoist API token in ways that deserve review before use.

Install only if you are comfortable granting CLI access to your Todoist account. Prefer a pinned, reviewed CLI version, avoid running npm install with elevated privileges, avoid placing your API token directly in shell history, and verify task IDs before completing, moving, or deleting tasks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 19
Vulnerability Type: Insecure third-party dependency installation
Risk Level: Medium

Vulnerable Code:

bash
npm install -g todoist-ts-cli@^0.2.0

Technical Analysis

The installation command uses the semver range ^0.2.0 rather than an exact, audited version. It also provides no lockfile, integrity hash, package provenance verification, or lifecycle-script restriction. Consequently, the installed package content may change after the Skill has been reviewed.

The global installation scope increases the impact because npm may execute package lifecycle scripts with the privileges of the installing user, and the package becomes available system-wide. The documentation states that the CLI is built on the official TypeScript SDK, but it does not establish that the CLI package itself is maintained or endorsed by Todoist.

Attack Path

  1. An attacker compromises the todoist-ts-cli package, its publisher account, or a dependency included by an allowed package release.
  2. A malicious or compromised version satisfying ^0.2.0 is published.
  3. A user follows the documented global installation command.
  4. npm retrieves the compromised release and may execute its installation lifecycle scripts.
  5. Malicious code runs under the installing user's account and can access resources available to that account.

Impact Assessment

Successful exploitation could permit arbitrary local code execution with the privileges of the user running npm. Depending on those privileges, the attacker could access user files, environment variables, stored credentials, and Todoist authentication material. If installation is performed with elevated privileges, the potential scope may extend to system-wide resources.

Remediation
View remediation

Remediation Suggestions

  • Pin the package to an exact version that has been reviewed, rather than using a semver range.
  • Record and verify package integrity and provenance before installation.
  • Prefer a project-local dependency with a committed lockfile instead of a global installation.
  • Review the package and its transitive dependency tree before recommending it.
  • Disable npm lifecycle scripts during installation where compatible with the package's operation.
  • Document that users should not run the installation with elevated privileges.
  • Establish a controlled update process in which each new version is audited before the pin is changed.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:27
Finding

Todoist API Token Exposed Through a Command-Line Argument

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 27
Vulnerability Type: Sensitive credential exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code:

bash
todoist auth <your-token>

Technical Analysis

The documented authentication method places the Todoist API token directly in a command-line argument. After variable substitution, the plaintext credential may be recorded in shell history. It may also be temporarily visible through local process-inspection facilities while the command is running.

A Todoist API token is an authentication credential. Its disclosure can allow another party to act through the Todoist account within the permissions associated with that token.

Attack Path

  1. The user replaces the placeholder with a real Todoist API token and executes the documented command.
  2. The shell records the complete command, including the token, in its command history, or exposes it through process arguments while the command runs.
  3. Another local user, process, support bundle, backup, or diagnostic collector obtains the exposed command.
  4. The attacker extracts the token and uses it to authenticate to Todoist.
  5. The attacker reads or modifies Todoist data accessible to the compromised account until the token is revoked or otherwise invalidated.

Impact Assessment

Exploitation could compromise the confidentiality and integrity of the user's Todoist data. An attacker possessing the token may be able to inspect tasks and projects and create, update, complete, move, comment on, or delete account data, subject to the token's effective permissions. This issue does not, by itself, establish operating-system privilege escalation.

Remediation
View remediation

Remediation Suggestions

  • Replace command-line token entry with hidden interactive input that does not echo or store the credential.
  • Where supported, pass the token through standard input or a secure operating-system credential store.
  • Ensure any persisted credential file is created with restrictive user-only permissions.
  • Warn users not to place tokens directly in shell commands or scripts.
  • Provide instructions for removing affected shell-history entries if this method was previously used.
  • Recommend immediate token revocation and regeneration if exposure is suspected.
  • Avoid logging environment variables, process arguments, authentication commands, or configuration files containing the token.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description is broadly phrased to activate on generic requests about tasks, reminders, or productivity, which increases the chance the agent invokes this skill in situations the user did not specifically intend to route to Todoist. Over-broad activation can lead to unnecessary access to a connected third-party account and unintended task creation, modification, or disclosure of task data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation exposes destructive and state-changing commands such as complete, reopen, move, update, and delete without any warning to confirm intent or verify task identity before execution. In an agent setting, this increases the risk of accidental or over-eager modification of a user's Todoist data, especially when a search result or inferred task ID is used incorrectly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.