Back to skill

Security audit

Things Mac 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Things 3 helper, with normal setup cautions around its third-party CLI install and optional Full Disk Access.

Install only if you trust the upstream `things3-cli` project, consider pinning or reviewing the exact version before installing, and grant Full Disk Access only to the minimum app needed for local Things database reads. Treat `THINGS_AUTH_TOKEN` like a secret because it enables update operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party CLI Installation from a Mutable Upstream Revision

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 5–13
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"✅","os":["darwin"],"requires":{"bins":["things"]},"install":[{"id":"go","kind":"go","module":"github.com/ossianhempel/things3-cli/cmd/things@latest","bins":["things"],"label":"Install things3-cli (go)"}]}}
shell
GOBIN=/opt/homebrew/bin go install github.com/ossianhempel/things3-cli/cmd/things@latest

Technical Analysis

The Skill installs things3-cli using the mutable Go version selector @latest. This does not bind installation to the specific dependency revision that was reviewed when the Skill was published. Consequently, the effective code installed and executed on a user's machine can change without any corresponding modification to this Skill package.

If the upstream repository, maintainer account, release process, or relevant dependency chain is compromised, a malicious future version could be selected automatically. Because Go installation compiles dependency code into a local executable, the resulting things binary could perform arbitrary actions under the invoking user's permissions whenever it is run.

The Skill also conditionally recommends granting Full Disk Access to the calling application when database reads fail. That recommendation is legitimate for the documented Things database operation, but it can amplify the consequences of a compromised dependency by making additional user files accessible to the process.

Attack Path

  1. An attacker compromises the upstream repository, maintainer credentials, release workflow, or dependency chain for github.com/ossianhempel/things3-cli.
  2. The attacker publishes a malicious revision that is resolved by the mutable @latest selector.
  3. A user or agent follows the Skill installation metadata or setup command.
  4. Go downloads, compiles, an ...[truncated 1197 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with a specific, audited semantic version or immutable commit revision in both the installation metadata and documented setup command.
  2. Record the approved upstream revision and review its source code and transitive dependency versions before publication.
  3. Use reproducible dependency controls, such as a locked Go module dependency graph and verified module checksums.
  4. Establish an explicit upgrade process in which dependency updates are reviewed, tested, and released as new Skill versions rather than selected dynamically during installation.
  5. Document the security implications of Full Disk Access and instruct users to grant it only to the minimum necessary application after verifying the installed CLI.
  6. Advise users to store THINGS_AUTH_TOKEN in a suitably protected credential mechanism and avoid exposing it in command history or process arguments.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: things-mac
description: Manage Things 3 via the `things` CLI on macOS (add/update projects+todos via URL scheme; read/search/list from the local Things database). Use when a user asks Clawdbot to add a task to Things, list inbox/today/upcoming, search tasks, or inspect projects/areas/tags.
homepage: https://github.com/ossianhempel/things3-cli
metadata: {"clawdbot":{"emoji":"✅","os":["darwin"],"requires":{"bins":["things"]},"install":[{"id":"go","kind":"go","module":"github.com/ossianhempel/things3-cli/cmd/things@latest","bins":["things"],"label":"Install things3-cli (go)"}]}}
---

Static analysis

No suspicious patterns detected.