Atlas / MCP servers / chrusic / Todoist Extended

Todoist ExtendedSAFE

mcp/chrusic/todoist-extended

Todoist MCP Server Extended - Enabling natural language management of todoist via Claude, MCP and todoist REST APIv2. Featuring LLM optimized Tools including batch operations and robust error handling.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
19 7r · 9w · 3d
Transport
stdio
License
MIT
Stars
22
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@Chrusic/todoist-mcp-server-extended)

An MCP (Model Context Protocol) server implementation that integrates Claude - or any MCP compatible LLM if you're crafty - with Todoist, enabling natural language task management via MCP tools. The tools in this server allows Claude to interact with your Todoist tasks, projects, sections, and labels using everyday language, while also optimized for LLM workflow efficiency.

Features Overview

  • Task Management: Create, update, complete, and delete tasks using everyday language
  • Label Management: Create, update, and manage personal labels and task labels
  • Project Management: Create, update, and manage Todoist projects
  • Section Organization: Create and manage sections within projects
  • Smart Search: Find tasks and labels using partial name matches
  • Flexible Filtering: Filter tasks by project, section, due date, priority, and labels
  • Rich Task Details: Support for descriptions, due dates, priority levels, and project/section assignment
  • Batch Operations: Tools have built in batch operation support and custom parameters for efficient usage with LLM workflows

For a complete list of available tools as well as their usage, see tools.md.

Quick Installation Guide

Assuming you already have npm installed.

A more comprehensive installation guide can be found in the How-to Guide.

Installing via Smithery

To install Todoist MCP Server Extended for Claude Desktop via Smithery:

  1. Run following command in cmd\pwsh:
Read from source at commit 25811ebb0977OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add todoist-mcp-server-extended --env TODOIST_API_TOKEN=${TODOIST_API_TOKEN} -- npx -y @chrusic/[email protected]
claude-desktop
{
  "mcpServers": {
    "todoist-mcp-server-extended": {
      "command": "npx",
      "args": [
        "-y",
        "@chrusic/[email protected]"
      ],
      "env": {
        "TODOIST_API_TOKEN": "${TODOIST_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (19)

7 read · 9 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
todoist_complete_taskreadMark one or more tasks as complete in Todoist
todoist_create_personal_labelwriteCreate one or more personal labels in Todoist
todoist_create_projectwriteCreate one or more projects with support for nested hierarchies
todoist_create_project_sectionwriteCreate one or more sections in Todoist projects
todoist_create_taskwriteCreate one or more tasks in Todoist with full parameter support
todoist_delete_personal_labeldestructiveDelete a personal label from Todoist
todoist_delete_taskdestructiveDelete one or more tasks from Todoist
todoist_get_personal_labelreadGet a personal label by ID
todoist_get_personal_labelsreadGet all personal labels from Todoist
todoist_get_project_sectionsreadGet sections from one or more projects in Todoist
todoist_get_projectsreadGet projects with optional filtering and hierarchy information
todoist_get_shared_labelsreadGet all shared labels from Todoist
todoist_get_tasksreadGet a list of tasks from Todoist with various filters - handles both single and batch retrieval
todoist_remove_shared_labelsdestructiveRemove one or more shared labels from Todoist tasks
todoist_rename_shared_labelswriteRename one or more shared labels in Todoist
todoist_update_personal_labelwriteUpdate one or more existing personal labels in Todoist
todoist_update_projectwriteUpdate one or more projects in Todoist
todoist_update_taskwriteUpdate one or more tasks in Todoist with full parameter support
todoist_update_task_labelswriteUpdate the labels of one or more tasks in Todoist
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
todoist_delete_personal_label, todoist_delete_task, todoist_remove_shared_labels
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@doist/todoist-api-typescript, @modelcontextprotocol/sdk, @types/node, shx, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 25811ebb0977full audit observations/trust-audit/mcp-server/chrusic__todoist-extended.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0925811ebb0977SAFEB89first audit
06

Questions

What is the Todoist Extended MCP server?

Todoist MCP Server Extended - Enabling natural language management of todoist via Claude, MCP and todoist REST APIv2. Featuring LLM optimized Tools including batch operations and robust error handling.

What tools does Todoist Extended expose?

19 in total: 7 read-only, 9 that write, and 3 that can delete or overwrite (todoist_delete_personal_label, todoist_delete_task, todoist_remove_shared_labels). Every one is listed on this page with its risk.

Is Todoist Extended safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Todoist Extended need?

It reads TODOIST_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Todoist Extended run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @chrusic/todoist-mcp-server-extended at 0.2.5.

How current is this page?

The grade is for one exact copy of the source (25811ebb0977), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement