
Research
/Security News
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.
@doist/todoist-mcp
Advanced tools
Note: This package was previously named
@doist/todoist-ai. The old name continues to work as a thin shim that re-exports from@doist/todoist-mcp, but new installs should use@doist/todoist-mcpdirectly.
Library for connecting AI agents to Todoist. Includes tools that can be integrated into LLMs, enabling them to access and modify a Todoist account on the user's behalf.
These tools can be used both through an MCP server, or imported directly in other projects to integrate them to your own AI conversational interfaces.
npm install @doist/todoist-mcp
Here's an example using Vercel's AI SDK.
import { findTasksByDate, addTasks } from '@doist/todoist-mcp'
import { TodoistApi } from '@doist/todoist-sdk'
import { streamText } from 'ai'
// Create Todoist API client
const client = new TodoistApi(process.env.TODOIST_API_KEY)
// Helper to wrap tools with the client
function wrapTool(tool, todoistClient) {
return {
...tool,
execute(args) {
return tool.execute(args, todoistClient)
},
}
}
const result = streamText({
model: yourModel,
system: 'You are a helpful Todoist assistant',
tools: {
findTasksByDate: wrapTool(findTasksByDate, client),
addTasks: wrapTool(addTasks, client),
},
})
You can run the MCP server directly with npx:
npx @doist/todoist-mcp
The Todoist MCP server is available as a streamable HTTP service for easy integration with various AI clients:
Primary URL (Streamable HTTP): https://ai.todoist.net/mcp
https://ai.todoist.net/mcp and complete OAuth authenticationCreate a configuration file:
~/.cursor/mcp.json.cursor/mcp.json{
"mcpServers": {
"todoist": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://ai.todoist.net/mcp"]
}
}
}
Then enable the server in Cursor settings if prompted.
The fastest setup is the official Todoist plugin, which wires up the MCP server for you:
/plugin marketplace add doist/todoist-mcp
/plugin install todoist@doist
OAuth runs in your browser the first time you use a Todoist tool. See Anthropic's plugin docs for more.
If you'd rather configure the MCP server manually, run:
claude mcp add --transport http todoist https://ai.todoist.net/mcp
Then launch claude, execute /mcp, and select the todoist MCP server to authenticate.
{
"servers": {
"todoist": {
"type": "http",
"url": "https://ai.todoist.net/mcp"
}
}
}
npx -y mcp-remote https://ai.todoist.net/mcp
For more details on setting up and using the MCP server, including creating custom servers, see docs/mcp-server.md.
A key feature of this project is that tools can be reused, and are not written specifically for use in an MCP server. They can be hooked up as tools to other conversational AI interfaces (e.g. Vercel's AI SDK).
This project is in its early stages. Expect more and/or better tools soon.
Nevertheless, our goal is to provide a small set of tools that enable complete workflows, rather than just atomic actions, striking a balance between flexibility and efficiency for LLMs.
For our design philosophy, guidelines, and development patterns, see docs/tool-design.md.
For a complete list of available tools, see the src/tools directory.
This server includes search and fetch tools that follow the OpenAI MCP specification, enabling seamless integration with OpenAI's MCP protocol. These tools return JSON-encoded results optimized for OpenAI's requirements while maintaining compatibility with the broader MCP ecosystem.
See docs/mcp-server.md for full instructions on setting up the MCP server.
See docs/dev-setup.md for full setup instructions and CONTRIBUTING.md for contributor workflows and quality checks.
This project includes support for MCP Apps – interactive UI widgets rendered inline in AI chat interfaces. Widgets provide rich visual representations of tool outputs (e.g., task lists) instead of plain text.
See docs/mcp-apps.md for the widget architecture, build pipeline, and development workflow.
After cloning and setting up the repository:
npm start - Build and run the MCP inspector for testingnpm run dev - Development mode with auto-rebuild and restartnpm run tool:list - List available tools for direct executionnpm run tool -- <tool-name> '<json-args>' - Run a tool directly without MCPWhen using npm run tool, include -- before tool arguments so npm forwards them to scripts/run-tool.ts.
Example check before write operations:
npm run tool -- user-info '{}'
This confirms which Todoist account the current TODOIST_API_KEY is connected to.
run-tool uses TODOIST_API_KEY from your .env file (created from .env.example by npm run setup). Use a test account or a temporary project when running write operations to avoid modifying real data.
See CONTRIBUTING.md for:
scripts/run-tool.tsThis project uses release-please to automate version management and package publishing.
Make your changes using Conventional Commits:
feat: for new features (minor version bump)fix: for bug fixes (patch version bump)feat!: or fix!: for breaking changes (major version bump)docs: for documentation changeschore: for maintenance tasksci: for CI changesWhen commits are pushed to main:
After merging the release PR:
publish workflow is triggeredFAQs
The official Todoist MCP server
We found that @doist/todoist-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 12 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A mini Shai-Hulud campaign compromised Red Hat Cloud Services npm packages to steal developer and CI/CD secrets during installation.

Research
/Security News
The North Korean malware loader hides in a Packagist-listed package and its GitHub branch to fetch and execute remote code in a likely Contagious Interview-style lure.

Security News
The Rust project is moving toward formal rules on LLM use in contributions after months of internal debate over maintainer burden, code quality, and contributor experience.