todoist-due-drafts

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill is conceptually aligned with automating email drafts from Todoist outreach tasks and notifying the user. However, it introduces notable security concerns around credential exposure, data flows involving meeting transcripts, and autonomous drafting without explicit per-task user confirmation. The architecture relies on reading sensitive config (.env, user.json), uses multiple external services (Todoist, Granola, Grain, Gmail, WhatsApp), and then drafts and notifies in an automated fashion. These factors render the skill SUSPICIOUS with elevated risk, though not clearly malicious. The primary risk stems from credential access and potential unintended data leakage through context-rich drafts and notifications. Recommend adding explicit user consent prompts per task, minimizing credential exposure (e.g., scoped tokens, ephemeral drafts), auditing data flows, and ensuring logs do not capture sensitive content.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 04:26 AM
Package URL
pkg:socket/skills-sh/mgonto%2Fexecutive-assistant-skills%2Ftodoist-due-drafts%2F@b55ae8a699012882c6dc6008e439c8c7054de5ec