Omahub
← All plugins
M

Todoist

by mateusfl

Your Todoist tasks in the bar, with a popup to view, add, and complete them

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
6e6d48f
Scanned
2 weeks ago
  • medium package_manager Strings.js:27

    Global npm package installation.

    npm install -g @doist/todoist-cli",
  • medium package_manager Strings.js:59

    Global npm package installation.

    npm install -g @doist/todoist-cli",
  • Docs external_hosts README.md:41

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/mateusfl/omarchy-todoist.git ~/.config/omarchy/plugins/mateusfl.todoist
  • Docs package_manager README.md:18

    Global npm package installation.

    npm install -g @doist/todoist-cli

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6e6d48f
Reviewed
2 weeks ago

The plugin is a Todoist bar widget that shells out to the official `td` CLI for all data and authentication; it never stores API tokens itself and passes them via stdin to avoid process-list exposure. The deterministic scan's medium findings are all documentation-only (README install instructions and a global npm install hint in Strings.js), not executable code. No obfuscation, persistence, or destructive behavior was found.

  • The README and Strings.js mention `npm install -g @doist/todoist-cli` and a `git clone` from GitHub; these are user-initiated setup steps, not executed by the plugin, so they pose no runtime risk.
  • The plugin relies on the external `td` CLI being present; if missing it shows a message but does not auto-install anything.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/mateusfl/omarchy-todoist --enable
Productivity #bar

Todoist for Omarchy

A bar widget + popup for Todoist, built for the Omarchy shell. Shows a task count in the bar and opens a popup with Inbox/Today/Upcoming tabs, natural-language quick-add, and one-click task completion — styled with the active Omarchy theme, mixed with Todoist's own priority/project colors.

Authentication and data come from the official td CLI: this plugin never sees or stores your API token itself, td keeps it in your OS keyring.

Requirements

  • Omarchy with the Quickshell-based shell (omarchy-shell)
  • td, the official Todoist CLI:
    npm install -g @doist/todoist-cli
    

Log in once before using the widget:

td auth login
td auth status --json

The first command opens Todoist's browser login; the second verifies that it succeeded. The plugin uses this same login, so you do not need to set up a separate token for it.

Install

omarchy plugin add https://github.com/mateusfl/omarchy-todoist.git --enable

Or by hand:

git clone https://github.com/mateusfl/omarchy-todoist.git ~/.config/omarchy/plugins/mateusfl.todoist
omarchy-shell shell rescanPlugins
omarchy plugin enable mateusfl.todoist

The widget lands in the bar's right section by default; move it with omarchy bar move mateusfl.todoist --section <left|center|right>.

Usage

  • Click the bar icon to open the popup.
  • Inbox / Today / Upcoming tabs switch which td list is shown. Today's tab covers overdue + due-today; Upcoming covers overdue + due-today + the next 7 days.
  • Type into the quick-add field and press Enter (or the + button) to create a task. It speaks Todoist's own quick-add syntax — due dates, p1..p4 priority, #project, @label all work.
  • Click a task's checkbox to complete it.
  • Click a task's text to open it in Todoist.
  • The refresh icon re-fetches; the bar icon itself also middle-click refreshes.

First run (authentication)

If td has no stored credential yet, the popup shows a Log in with browser button (opens Todoist's OAuth flow) or a field to paste a personal API token (Todoist → Settings → Integrations → Developer).

You can also run td auth login in a terminal. After logging in outside the plugin, reopen the popup or middle-click the bar icon to check again. The widget also checks for an existing login when it loads.

Configure

Click the settings (gear) icon in the popup header to open the settings pane. Currently that's just the UI language — English or Português (Brasil), more may be added over time. The choice is saved with the widget's own settings in ~/.config/omarchy/shell.json and survives restarts.

Remove

omarchy plugin remove mateusfl.todoist

Adding a language

All UI strings live in Strings.js, keyed by language tag. To add one:

  1. Add { value: "<tag>", label: "<Display name>" } to LANGUAGES.
  2. Add a DICTS["<tag>"] dictionary with the same keys as the existing en-US/pt-BR entries.

Nothing else needs to change — the settings dropdown reads LANGUAGES directly, and every string lookup goes through Strings.t(lang, key).

License

MIT — see LICENSE.