action-items-todoist

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its footprint is broad and trust-heavy. It legitimately automates meeting follow-ups, yet it relies on multiple third-party CLIs, forwards sensitive workspace/env-backed credentials and meeting transcripts through them, chains into another skill, and can take autonomous business actions. This looks more like a high-risk automation skill than malware, with the main concerns being supply-chain trust, credential forwarding, and privacy exposure rather than clear deception.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Apr 8, 2026, 08:47 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Faction-items-todoist%2F@be2f55f3ef113e1733d8e8a5732cdd4d2ae93587