todoist

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose matches task-management capabilities, but its trust model is incomplete: it requires an external CLI and a separate secrets helper, lacks install details, and uses a binary name that does not cleanly match the official Doist documentation. This is not strong evidence of malware or overt exfiltration, but it is medium risk due to ambiguous execution provenance and credential forwarding to external tooling.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/joelhooks%2Ftodoist-cli%2Ftodoist%2F@6f6a7d774483daa5519fa43d39a43a8ec77c3487