things-mac
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is mostly purpose-aligned, but it relies on a third-party personal GitHub CLI, asks for Full Disk Access, and forwards a Things auth token to that CLI. Data flows appear consistent with local Things access and the official URL scheme rather than obvious exfiltration, so this is better classified as elevated trust and credential-handling risk than confirmed malware.
Confidence: 84%Severity: 72%
Audit Metadata