Is buddyh/todoist-cli safe?

https://github.com/openclaw/skills/tree/main/skills/buddyh/todoist-cli

97
SAFE

This skill provides clean documentation for a legitimate Todoist CLI tool with no malicious behavior detected. It requires an API token for authentication but this is for legitimate interaction with the Todoist service.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 95/100 · 25%
Code Execution 100/100 · 20%
Clone Behavior 100/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 95/100 · 5%

Findings (3)

LOW Requires API Token -5

Skill requires TODOIST_API_TOKEN environment variable for authentication to Todoist service

INFO External Authentication URL -5

References external URL for obtaining API token, but it points to legitimate Todoist developer settings

INFO Credential Dependency -5

Skill functionality depends on user providing sensitive API credentials