Back to skill

Security audit

todoist-orbit

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Todoist automation skill that can modify Todoist data and upload chosen files, with those capabilities mostly disclosed.

Install only if you want an agent to act on your Todoist account with your API token. Review destructive commands before use, especially delete operations, and only upload files or stdin content that you intend to store in Todoist.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-notes.md (reported line 23)May include surrounding context.

md
- `POST /api/v1/tasks/{id}/move`
- `POST /api/v1/tasks/{id}/close`
- `POST /api/v1/tasks/{id}/reopen`
- `DELETE /api/v1/tasks/{id}`

### Projects
- `GET /api/v1/projects`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-notes.md (reported line 32)May include surrounding context.

md
- `POST /api/v1/projects/{id}`
- `POST /api/v1/projects/{id}/archive`
- `POST /api/v1/projects/{id}/unarchive`
- `DELETE /api/v1/projects/{id}`
- `GET /api/v1/projects/search`
- project search: `projects search` now calls the dedicated Todoist project search endpoint; `--exact` still performs a local exact-name pass over the returned results for compatibility

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-notes.md (reported line 43)May include surrounding context.

md
- `POST /api/v1/sections/{id}`
- `POST /api/v1/sections/{id}/archive`
- `POST /api/v1/sections/{id}/unarchive`
- `DELETE /api/v1/sections/{id}`
- section move: no REST endpoint exists; the CLI keeps `sections move` only as a compatibility stub that returns an error

### Labels

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-notes.md (reported line 51)May include surrounding context.

md
- `GET /api/v1/labels/{id}`
- `POST /api/v1/labels`
- `POST /api/v1/labels/{id}`
- `DELETE /api/v1/labels/{id}`
- `GET /api/v1/labels/search`
- label search: `labels search` now calls the dedicated Todoist label search endpoint; `--exact` still performs a local exact-name pass over the returned results for compatibility

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises and documents capabilities that read environment variables, access local files, write/read attachment content, and make network requests to Todoist, but it does not declare an explicit tool scope such as permissions or allowed-tools. That omission weakens reviewability and least-privilege controls, making it easier for a caller or host to invoke a skill with broader-than-expected access to secrets and local data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill prominently supports uploads, comments, add-file, and add-stdin workflows that transmit local file contents and arbitrary text to Todoist's servers, but the description and safety guidance do not explicitly warn that this data leaves the local environment. Users may unknowingly send sensitive notes, logs, transcripts, or files to a third-party service, increasing the risk of privacy breaches or secret disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/todoist_orbit.py (reported line 15)May include surrounding context.

python
from urllib.parse import urlencode
from urllib.request import Request, urlopen

API_BASE = "https://api.todoist.com/api/v1"
DEFAULT_TIMEOUT = 60

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code reads arbitrary local files and uploads their raw contents to a remote Todoist endpoint. Although uploads are part of the feature, there is no confirmation prompt or user-facing disclosure in this file near the upload path that the selected file's contents will be sent over the network.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.