things-mac

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is mostly purpose-aligned, but it relies on a third-party personal GitHub CLI, asks for Full Disk Access, and forwards a Things auth token to that CLI. Data flows appear consistent with local Things access and the official URL scheme rather than obvious exfiltration, so this is better classified as elevated trust and credential-handling risk than confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Sep 2, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fthings-mac%2F@5073bc563604d359c0af07bf61eee2047fba067849c0d2580e19cfc033f0bb7c
Security Audit — socket — things-mac