
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
opencode-auto-todos
Advanced tools
OpenCode plugin that automatically adds custom todos to every feature's task list
An OpenCode plugin that automatically appends custom todos to every task list. Define your standard workflow items once, and they'll be added to every todowrite call automatically.
# In your project directory
npm install --save-dev opencode-auto-todos
Then add to your opencode.json:
{
"plugin": ["opencode-auto-todos"]
}
Create an auto-todos.json file in your project root or inside .opencode/:
{
"todos": [
{
"content": "Version bump - update version in package.json",
"priority": "medium",
"match": "version bump",
"order": "first"
},
{
"content": "Create branch, commit changes, open PR",
"priority": "medium",
"match": "github",
"order": 2
}
],
"always": false,
"deduplicate": true
}
| Field | Type | Default | Description |
|---|---|---|---|
todos | AutoTodo[] | required | List of todos to automatically add |
always | boolean | false | If true, add todos to every todowrite call. If false, only when the list is first created (empty). |
deduplicate | boolean | true | Skip adding a todo if a similar one already exists in the list. |
| Field | Type | Required | Description |
|---|---|---|---|
content | string | yes | The todo text to display |
priority | "high" | "medium" | "low" | no | Priority level (default: "medium") |
match | string | no | Substring to match against existing todos for deduplication. If omitted, content is used. |
order | "first" | "last" | number | no | Position where the todo is inserted (default: "last"). "first" = beginning, "last" = end, number = 1-based index (e.g., 1 = first, 2 = second). |
tool.execute.before event for the todowrite toolWith this config:
{
"todos": [
{ "content": "Read CLAUDE.md or project docs", "order": "first" },
{ "content": "Version bump", "match": "version" },
{ "content": "Create branch, commit, open PR", "match": "github" }
]
}
Every time you start a new feature, the agent's todo list will automatically include:
✓ [your feature-specific todos]
☐ Read CLAUDE.md or project docs
☐ Version bump
☐ Create branch, commit, open PR
MIT
FAQs
OpenCode plugin that automatically adds custom todos to every feature's task list
We found that opencode-auto-todos demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.