things-setup

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is a local Things 3 sync setup, and most local AppleScript/config actions fit that purpose, but the install path is not fully consistent with the privacy claims: it adds an unpinned third-party MCP package via `npx -y things3-mcp` without verified same-org provenance. That makes the skill’s actual trust footprint broader than advertised. No explicit credential theft or malicious endpoint is shown, so this is not confirmed malware, but it is a high supply-chain risk AI skill.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
May 20, 2026, 12:42 AM
Package URL
pkg:socket/skills-sh/davekilleen%2FDex%2Fthings-setup%2F@4ef673f0a450865c005691609772159b89e9b32f
Security Audit — socket — things-setup