Back to skill

Security audit

Todoist 任务可见性管理

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Todoist helper, but it gives a token-backed shell script broad Todoist API control without tight scoping or confirmation safeguards.

Install only if you are comfortable giving the skill broad Todoist API authority through your token. Prefer using it with a dedicated Todoist token if possible, review each write action before running it, keep any token file private with restrictive permissions, and avoid passing untrusted text into the comment or task JSON scripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/add_comment.sh:27
Finding

Unescaped User Input in JSON Comment Payload

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi COMMENT_JSON=$( jq -n \ --arg task_id "$TASK_ID" \ --arg content "[$TIMESTAMP] $COMMENT" \ '{task_id: $task_id, content: $content}' ) ``` Additional hardening measures: 1. Validate task identifiers against the exact format required by the Todoist API. 2. Retain `jq --arg` encoding for all externally supplied string values. 3. Reject invalid input before making a network request. 4. Use `curl --fail-with-body --show-error --silent` so HTTP failures produce a nonzero exit status. 5. Print the success message only after confirming a successful HTTP response. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/config.sh:1
Finding

Plaintext Bearer Token Storage and Unsafe Configuration Sourcing Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as a narrow Todoist task-status manager, but the documented API wrapper supports arbitrary Todoist endpoints and arbitrary HTTP methods. That is a significant capability expansion: a caller expecting a limited workflow could instead read, modify, or delete broader Todoist resources, creating a confused-deputy risk and violating least privilege. Because the skill also relies on an API token, this broader-than-advertised access materially increases the blast radius.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as a narrow Todoist task-status manager, but the documented API wrapper supports arbitrary Todoist endpoints and arbitrary HTTP methods. That is a significant capability expansion: a caller expecting a limited workflow could instead read, modify, or delete broader Todoist resources, creating a confused-deputy risk and violating least privilege. Because the skill also relies on an API token, this broader-than-advertised access materially increases the blast radius.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents shell-based scripts and API operations but does not declare any tool scope such as allowed-tools or permissions. That makes its execution boundary ambiguous and can lead to overbroad shell access being granted when only limited Todoist operations were intended. In a skill that handles API tokens and performs networked actions, undeclared shell capability increases the chance of unintended command execution or misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger condition is broad enough to match ordinary conversation about Todoist, task management, status tracking, or API usage. Overbroad activation can cause the skill to be invoked unexpectedly, which is especially risky for a skill with shell usage and authenticated API effects because it may perform actions in contexts where the user did not intend external task modifications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's description, usage, examples, and error messages are all presented in Chinese, which imposes a specific language on users without opt-in or explanation. The policy requires avoiding forced language or locale constraints unless the skill offers a choice or clearly documents a justified regional scope.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/add_comment.sh (reported line 43)May include surrounding context.

sh
)

# 发送请求
curl -s -X POST \
    -H "Authorization: Bearer ${TODOIST_TOKEN}" \
    -H "Content-Type: application/json" \
    -d "$COMMENT_JSON" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sync_task.sh (reported line 86)May include surrounding context.

sh
)

# 发送请求
curl -s -X POST \
    -H "Authorization: Bearer ${TODOIST_TOKEN}" \
    -H "Content-Type: application/json" \
    -d "$COMMENT_JSON" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sync_task.sh (reported line 103)May include surrounding context.

sh
)

# 发送请求
curl -s -X POST \
    -H "Authorization: Bearer ${TODOIST_TOKEN}" \
    -H "Content-Type: application/json" \
    -d "$COMMENT_JSON" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This shell script sends task JSON and authenticates with TODOIST_TOKEN via outbound HTTP requests to the Todoist API. Although the file comments describe its purpose, there is no runtime disclosure, confirmation, or explicit warning that user task content and credentials will be transmitted to an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/add_comment.sh (reported line 31)May include surrounding context.

sh
# 配置变量(需要用户设置)
TODOIST_TOKEN="${TODOIST_TOKEN:-}"
API_BASE="https://api.todoist.com/api/v1"

# 检查 token
if [[ -z "$TODOIST_TOKEN" ]]; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sync_task.sh (reported line 48)May include surrounding context.

sh
# 配置变量(需要用户设置)
TODOIST_TOKEN="${TODOIST_TOKEN:-}"
API_BASE="https://api.todoist.com/api/v1"

# 检查 token
if [[ -z "$TODOIST_TOKEN" ]]; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/todoist_api.sh (reported line 9)May include surrounding context.

sh
# 配置变量(需要用户设置)
TODOIST_TOKEN="${TODOIST_TOKEN:-}"
API_BASE="https://api.todoist.com/api/v1"

# 检查 token
if [[ -z "$TODOIST_TOKEN" ]]; then

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script accepts arbitrary HTTP methods, endpoints, and request bodies, which grants broad authenticated access to the user's Todoist account rather than limiting actions to the skill's stated purpose of visibility and status tracking. In an agent context, this overbroad capability can be misused to read, modify, or delete unrelated Todoist data if upstream inputs are influenced by prompts or untrusted instructions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This code sends data and an authorization bearer token over the network to an external API. External transmission is expected for Todoist integration, but in this implementation it is still security-relevant because the transmitted scope is not constrained and requests can include arbitrary payloads under the user's credentials.

Content

Scanner excerpt · scripts/todoist_api.sh (reported line 39)May include surrounding context.

sh
# 发送请求
if [[ -n "$DATA" ]]; then
    curl -s -X "$METHOD" \
        -H "Authorization: Bearer ${TODOIST_TOKEN}" \
        -H "Content-Type: application/json" \
        -d "$DATA" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script transmits authenticated requests using the user's bearer token to Todoist without any confirmation, consent flow, or visible notice at the point of use. In a tool-using agent environment, that increases the risk of silent exfiltration or unintended account actions because users may not realize when their data is being sent to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell script performs an outbound API call that transmits user-provided comment text and uses a bearer token, but the only nearby text says it is 'sending request' and does not disclose the privacy or external-transmission aspect to the user. Under the code-file warning rule, network calls that transmit user or system data should have some visible disclosure unless clearly covered elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell config template uses Chinese throughout its human-readable comments and instructions, which can function as a natural-language policy violation if organizational guidance requires not forcing a specific language without user choice. There is no alternative language option or indication that the skill is intended only for a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings in comments and command output are consistently Chinese, with no option for users to select another language. This can violate language/locale policy when a skill imposes a specific language without offering choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

Comments and CLI output such as usage and error messages are written only in Chinese. This creates a language policy issue because the script forces a specific language/locale without opt-in or an alternative for users who do not read Chinese.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.