things-manager

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose is coherent for task management, but the trust and data-flow model is not: the skill installs an unpinned personal-repo CLI and forwards raw Things credentials to it for an unofficial direct-cloud integration that the vendor does not support. This is better classified as high-risk vulnerable tooling than confirmed malware.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Mar 17, 2026, 03:10 PM
Package URL
pkg:socket/skills-sh/hoangvantuan%2Fclaude-plugin%2Fthings-manager%2F@7c69bd8760cad68bceb5867e8c008aca0ab3a293
Security Audit — socket — things-manager