todoist-automation

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities are mostly aligned with Todoist automation, and it does not include malware-like payloads, credential-file theft, or download-execute behavior. The main risk is trust and data-flow centralization through a third-party MCP intermediary (Rube/Composio), plus a documentation inconsistency around whether API keys are required and only partial verification of the exact rube.app MCP endpoint. This is better classified as a moderate-trust integration risk than confirmed malicious behavior.

Confidence: 81%Severity: 52%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:03 AM
Package URL
pkg:socket/skills-sh/aAAaqwq%2FAGI-Super-Team%2Ftodoist-automation%2F@8c30e389dbc71c4c1cd9000e1e49e8640ec57028