
Security News
Risky Biz Podcast: Making Reachability Analysis Work in Real-World Codebases
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
@doist/todoist-ai
Advanced tools
Library for connecting AI agents to Todoist. Includes tools that can be integrated into LLMs, enabling them to access and modify a Todoist account on the user's behalf.
These tools can be used both through an MCP server, or imported directly in other projects to integrate them to your own AI conversational interfaces.
npm install @doist/todoist-ai
Here's an example using Vercel's AI SDK.
import { findTasksByDate, addTasks } from "@doist/todoist-ai";
import { streamText } from "ai";
const result = streamText({
model: yourModel,
system: "You are a helpful Todoist assistant",
tools: {
findTasksByDate,
addTasks,
},
});
You can run the MCP server directly with npx:
npx @doist/todoist-ai
For more details on setting up and using the MCP server, including creating custom servers, see docs/mcp-server.md.
A key feature of this project is that tools can be reused, and are not written specifically for use in an MCP server. They can be hooked up as tools to other conversational AI interfaces (e.g. Vercel's AI SDK).
This project is in its early stages. Expect more and/or better tools soon.
Nevertheless, our goal is to provide a small set of tools that enable complete workflows, rather than just atomic actions, striking a balance between flexibility and efficiency for LLMs.
For our design philosophy, guidelines, and development patterns, see docs/tool-design.md.
For a complete list of available tools, see the src/tools directory.
See docs/mcp-server.md for full instructions on setting up the MCP server.
See docs/dev-setup.md for full instructions on setting up this repository locally for development and contributing.
After cloning and setting up the repository:
npm start
- Build and run the MCP inspector for testingnpm run dev
- Development mode with auto-rebuild and restartThis project uses release-please to automate version management and package publishing.
Make your changes using Conventional Commits:
feat:
for new features (minor version bump)fix:
for bug fixes (patch version bump)feat!:
or fix!:
for breaking changes (major version bump)docs:
for documentation changeschore:
for maintenance tasksci:
for CI changesWhen commits are pushed to main
:
After merging the release PR:
publish
workflow is triggeredFAQs
A collection of tools for Todoist using AI
We found that @doist/todoist-ai demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 8 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
Security News
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.