
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
CLI task manager where Markdown is the single source of truth. No database, no server, no GUI.
npm install -g mdtask
Or run without installing:
npx mdtask list
Note:
npx mdtaskwon't work from inside the mdtask source directory — npx conflicts with the local package. Usepnpm mdtaskfor development.
English is the project language — docs, commit messages, code comments, and communication.
It is a structured table:
CLI is only an interpreter, never the owner of data.
Every feature must reduce user effort, not add configuration burden. Derive what you can from existing data in files — don't ask users to maintain mappings, schemas, or config that the tool could figure out on its own.
- [ ] EXMPL-123 Short task title #feature !high @status:doing
Description body goes here.
Can be multi-line.
[A-Z]+-\d+, globally unique#tag — tags!crit / !high / !low — priority (no tag = medium)@key:value — propertiesmdtask list # list open tasks
mdtask list --all # all tasks including done
mdtask list '#backend' # filter by tag (quote: # is a shell comment)
mdtask list '!high' # filter by priority
mdtask view <ID> # print full task block by ID
mdtask done <ID> # toggle task [ ] ↔ [x]
mdtask open <ID> # open task in $EDITOR at line
mdtask move <ID> <file> # move task to another file
mdtask set <ID...> <tokens> # add metadata to tasks
mdtask ids # auto-assign IDs to unidentified tasks
mdtask ids --path <file> --prefix PRJ
mdtask validate # check task integrity
mdtask is three layers, kept deliberately separate:
mdtask) — the task format. It reads and edits Markdown checkbox tasks and knows nothing about methodology: a small, fast interpreter over your files.docs/skills/) — the method. sdd is the spec-driven workflow; mdtask-create writes new tasks; mdtask-next takes one task end to end (pick → plan → build → document → commit).mdtask-next and have it repeat until the backlog is empty. mdtask ships no loop or orchestrator.Node.js + TypeScript. Minimal dependencies.
PolyForm Shield 1.0.0 — free to use, modify, and distribute; competing products prohibited.
docs/skills/mdtask/SKILL.mddocs/mdtask.mddocs/prd/When changing one — check the others for consistency.
Spec-driven development. PRD is both the spec and the manual.
See docs/skills/sdd/SKILL.md for the full workflow with examples.
src/ — source code
test/ — tests (vitest)
docs/ — documentation
Git only. All operations are plain text edits, no auto-commits, conflicts resolved manually.
FAQs
File-first markdown task system
The npm package mdtask receives a total of 22 weekly downloads. As such, mdtask popularity was classified as not popular.
We found that mdtask demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.