todoist-automation

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities fit Todoist automation, but it routes all operations and auth through a third-party hosted MCP service (Rube/Composio) instead of Todoist's official endpoints, and its setup claims are inconsistent with vendor docs about MCP auth. This is not confirmed malware, but it carries meaningful trust and data-flow risk due to intermediary credential/token handling and remote action execution.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Ftodoist-automation%2F@d7030d1b36cf0b023852795447d91a8c98853cc7