No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by Doist · MCP Server · ★ 552
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is todoist-mcp safe to install? View the security audit →
Todoist MCP Server Note: This package was previously named . The old name continues to work as a thin shim that re-exports from , but new installs should use directly. Library for connecting AI agents to Todoist. Includes tools that can be integrated into LLMs, enabling them to access and modify a Todoist account on the user's behalf. These tools can be used both through an MCP server, or imported directly in other projects to integrate them to your own AI conversational interfaces. Using tools Add this repository as a dependency Import the tools and plug them to an AI Here's an example using Vercel's AI SDK.
| Stars | 552 |
| Forks | 56 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 72.7681602404142/100 |
| Open Issues | 9 |
| Last Updated | 2026-09-22 |
| Created | 2025-05-21 |
| Platforms | mcp, node |
| Est. Tokens | ~15k |
Explore other popular mcp server tools:
todoist-mcp is A set of tools to connect to AI agents, to allow them to use Todoist on a user's behalf. Includes MCP support.. It is categorized as a MCP Server with 552 GitHub stars.
todoist-mcp is primarily written in TypeScript.
You can find installation instructions and usage details in the todoist-mcp GitHub repository at github.com/Doist/todoist-mcp. The project has 552 stars and 56 forks, indicating an active community.
todoist-mcp is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: