todoist-mcp — security grade SAFE, quality 73/100

Security audit verdict: SAFE · quality 73/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by Doist · MCP Server · ★ 549

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is todoist-mcp safe to install? View the security audit →

About todoist-mcp

Todoist MCP Server Note: This package was previously named . The old name continues to work as a thin shim that re-exports from , but new installs should use directly. Library for connecting AI agents to Todoist. Includes tools that can be integrated into LLMs, enabling them to access and modify a Todoist account on the user's behalf. These tools can be used both through an MCP server, or imported directly in other projects to integrate them to your own AI conversational interfaces. Using tools Add this repository as a dependency Import the tools and plug them to an AI Here's an example using Vercel's AI SDK.

Quick Facts

Stars549
Forks53
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score72.7681602404142/100
Open Issues9
Last Updated2026-09-15
Created2025-05-21
Platformsmcp, node
Est. Tokens~15k

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is todoist-mcp?

todoist-mcp is A set of tools to connect to AI agents, to allow them to use Todoist on a user's behalf. Includes MCP support.. It is categorized as a MCP Server with 549 GitHub stars.

What programming language is todoist-mcp written in?

todoist-mcp is primarily written in TypeScript.

How do I install or use todoist-mcp?

You can find installation instructions and usage details in the todoist-mcp GitHub repository at github.com/Doist/todoist-mcp. The project has 549 stars and 53 forks, indicating an active community.

What license does todoist-mcp use?

todoist-mcp is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools