Omahub
← All plugins
K

Todoist Today

by Kartikeya Chauhan

A theme-native Todoist day calendar for the Omarchy bar, ordered by due time.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
d81b0b6
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs package_manager README.md:33

    Global npm package installation.

    npm install -g @doist/todoist-cli

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d81b0b6
Reviewed
1 month ago

The plugin is a Todoist bar widget that fetches tasks via the official API using a locally stored token, and optionally uses the official `td` CLI for quick add. The only flagged item is a README instruction to globally install the `td` CLI, which is documentation and not executed by the plugin. The scripts are transparent, use HTTPS only, and store credentials with restrictive permissions.

  • README instructs a global npm install (`npm install -g @doist/todoist-cli`), but this is a user-initiated action and not part of the plugin's executable code.
  • The plugin stores a Todoist API token in `~/.config/todoist/omarchy-token` with mode 600; this is acceptable but users should be aware the token persists after plugin removal.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Erscheinung/omarchy-todoist-today --enable
Productivity #bar #quickshell

Todoist Today for Omarchy Quattro

A theme-native Todoist day calendar for the Omarchy bar. It puts date-only tasks in an all-day strip, lays timed tasks onto a day rail, resolves overlaps into lanes, and follows the active Omarchy theme.

Todoist Today calendar preview

Install

omarchy plugin add https://github.com/Erscheinung/omarchy-todoist-today.git --enable

Connect Todoist

Open the new bar widget and paste a Todoist personal API token into its setup card. The token is passed to the local setup helper over stdin and stored in ~/.config/todoist/omarchy-token with mode 600; it is never written inside the plugin checkout or placed in a process argument.

For terminal-only setup, run:

~/.config/omarchy/plugins/io.github.erscheinung.todoist-today/scripts/configure-token

Calendar dependencies are curl and jq, both included with Omarchy. Quick Add uses Todoist's official CLI:

npm install -g @doist/todoist-cli
td auth login

Use

  • Left-click the bar count to toggle the calendar.
  • Middle-click refreshes; right-click opens Todoist Today.
  • Click a task to open it, or its circle to complete it.
  • Click + in the panel to add a task with Todoist Quick Add syntax through the official td CLI. Task text is sent to the helper over stdin. Typing p suggests priorities, while # searches projects fetched through td. Todoist natural-language dates, recurring schedules, deadlines, reminders, and durations are highlighted as you type, with completions for forms such as tom 14:30 for 15m and every day from 10 May until 20 May. Use Up/Down and Tab or Enter to accept a suggestion.
  • Use j/k and Enter in the panel, or r (refresh), n (now), o (open), and Escape.

The panel refreshes every five minutes and when opened after two minutes of inactivity. Completing a recurring task advances it exactly as Todoist does.

Remove

omarchy plugin remove io.github.erscheinung.todoist-today --yes

The credential is intentionally kept when the plugin is removed. To remove it too, delete ~/.config/todoist/omarchy-token.

Privacy and permissions

The calendar helper makes HTTPS requests only to api.todoist.com. Quick Add runs the official td CLI, which manages its own OAuth credential. The plugin reads today's active tasks and project names, and sends a close request only when you click a task's completion circle. Task contents stay in memory and are not cached.

Acknowledgements

The current/next task label is inspired by Gardy Armand's omarchy-todoist. The secure td Quick Add bridge is adapted from David Ojeda Lopez's omarchy-todoist. Both are MIT-licensed; see THIRD_PARTY_NOTICES.md.

Development

omarchy plugin validate .
qmllint -I /usr/share/omarchy/shell BarWidget.qml Panel.qml
bash -n scripts/todoist scripts/configure-token
python -m py_compile scripts/quick-add