# Security policy ## Supported version Security fixes are applied to the latest release on `main`. ## Reporting a vulnerability Please use GitHub's private vulnerability reporting for this repository. Do not post credentials, task content, account identifiers, exploit details, private data, or sensitive system information in a public issue. Include the affected plugin version, Omarchy version, sanitized symptoms, and the minimum safe reproduction steps. Never include Todoist tokens or raw `td` stderr. ## Runtime boundary Omarchy plugins execute as unsandboxed code inside the long-running `omarchy-shell` process. Review this repository before installing it. This plugin: - invokes its bundled Python bridge with fixed `status`, `projects`, or `add` commands; - invokes the official `td` executable with fixed argument lists and no shell interpreter; - sends task text to `td task quickadd` over standard input, never command-line arguments; - delegates Todoist network access and OAuth credential handling to the official CLI; - stores project names only in shell memory for five minutes; - bounds and normalizes subprocess JSON before rendering it; - shows only allowlisted errors and a content-free success notification; and - uses no elevated privileges, background service, listener, telemetry, analytics, or persistent task cache. The setup screen can open a visible terminal with the fixed command `td auth login`. The plugin never reads, writes, displays, or logs Todoist OAuth credentials. Its external runtime dependency is `@doist/todoist-cli`, installed and authenticated by the user as documented in the README.