-
-
Notifications
You must be signed in to change notification settings - Fork 10
Expand file tree
/
Copy pathtodoist-cli.json
More file actions
103 lines (103 loc) · 7.67 KB
/
Copy pathtodoist-cli.json
File metadata and controls
103 lines (103 loc) · 7.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
{
"id": "todoist-cli",
"name": "Todoist CLI",
"summary": "Doist\u0027s official command-line interface for Todoist tasks, projects, comments, and labels; supports a dedicated --read-only OAuth login flow.",
"source_url": "https://github.com/Doist/todoist-cli",
"kind": "connector",
"supported_agents": [
"claude_code",
"codex",
"gemini_cli",
"cursor",
"opencode",
"generic"
],
"installation": {
"automatic": false,
"scope": "project_or_user",
"prerequisites": [
"A Todoist account",
"A current todoist-cli release (e.g. td)",
"OAuth or API token credentials",
"For app-management, backups, or billing commands, a login that requested those opt-in scopes with td auth login --additional-scopes"
]
},
"data_boundary": {
"credentials": [
"OAuth token stored in the OS credential manager by the CLI (plaintext config-file storage only with an explicit --credential-store=plaintext), or an API token provided via the TODOIST_API_TOKEN environment variable, which takes precedence over stored credentials",
"td config view --show-token prints the stored token"
],
"reads": [
"Sensitive Todoist tasks, projects, sections, comments, attachments, reminders, and labels across personal and shared workspaces",
"Workspaces, folders, filters, and shared-label definitions",
"With the app-management scope, registered app metadata; td apps view --include-secrets additionally reveals the client secret, verification token, and test token",
"With the backups scope, a downloadable archive of account data; with the billing scope, subscription, plan, and price information",
"Local files named on the command line: td comment add --file and td template import-file read a local file and upload it"
],
"writes": [
"Creating, updating, completing, closing, and moving tasks, projects, sections, and comments",
"Workspace creation, update, and deletion (admin-only); project sharing, joining, and moving across workspaces, including invitation emails to the addresses named in td project share",
"Deletion of individual tasks, projects, sections, comments, folders, labels (including shared-label removal), filters, and reminders",
"With the app-management scope, editing webhooks and OAuth redirect URIs, and deleting a registered app -- documented as irreversible and immediately breaking that app for everyone who uses it",
"Local files: td backup download and td template export-file write to paths named on the command line; td skill install and td completion install write agent skill directories and shell configuration"
]
},
"capabilities": {
"read": true,
"sensitive_read": true,
"write": true,
"remote_write": true,
"publish": false,
"overwrite": true,
"delete": true,
"arbitrary_execution": false,
"oauth": true,
"destructive": true,
"details": [
"Recommended: start with td auth login --read-only, which requests data:read and blocks mutations in the CLI",
"Write-capable tokens can create, edit, close, move, and delete tasks, projects, workspaces, folders, labels, filters, and reminders",
"Environment-provided API tokens are treated as unknown scope and assumed write-capable; the read-only guarantee comes from the --read-only login flow, not from the CLI generally",
"Mutating commands accept --dry-run to preview without executing, and destructive commands typically require an explicit --yes",
"app-management, backups, and billing are opt-in OAuth scopes requested via td auth login --additional-scopes; app deletion under app-management is irreversible for all users of that app",
"The billing scope grants billing:read_write unless the login also used --read-only (then billing:read); the documented td billing commands only read",
"There is no bulk purge command: deletion is per resource"
]
},
"confirmation": {
"required_for": [
"credential_setup",
"external_install",
"read_sensitive",
"write",
"write_remote",
"overwrite",
"delete",
"oauth",
"destructive"
],
"notes": "Confirm the target account and projects before reading sensitive task state; show proposed task or project changes and deletions before execution."
},
"risk_tags": [
"credentials",
"personal-tasks",
"sensitive-read",
"remote-write",
"overwrite-capable",
"delete-capable",
"oauth",
"destructive-capable",
"local-data",
"prompt-injection"
],
"maturity": "verified",
"last_verified": "2026-09-03",
"evidence": [
"https://github.com/Doist/todoist-cli",
"https://github.com/Doist/todoist-cli/blob/2e32cb86954e11c093493d5f1fed76c002b358ea/skills/todoist-cli/SKILL.md"
],
"health_check": "Log in with td auth login --read-only, verify authenticated user identity, then fetch assigned tasks for today without writing or completing items.",
"uninstall": {
"instructions": "Run td auth logout, remove any installed agent skill with td skill uninstall, remove the CLI binary or client configuration, and revoke the OAuth application or API token in Todoist settings; preserve all remote task and project data.",
"removes_user_data": false
}
}