{"generated_at":"2026-08-17T10:36:11+00:00","item":{"added_at":"2025-09-18","analysis_method":"capability_triage","category":"Web Connector","description":"This extension provides seamless integration between Claude Desktop and Things task manager through AppleScript automation. Create, manage, and organize your...","did":"things-applescript","homepage_url":"","icon":"https://claude.ai/api/dxt/extensions/ant.dir.gh.mbmccormick.things/versions/1.3.0/icon.png","id":"things-applescript","installs":0,"last_scanned":"","license":"","long_description":"This extension provides seamless integration between Claude Desktop and Things task manager through AppleScript automation. Create, manage, and organize your tasks directly from Claude conversations. Features include creating to-dos, projects, areas, tags, and managing your task workflow efficiently.","name":"Things (AppleScript)","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=things-applescript&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"","publisher_url":"","repository_url":"","risk":"medium","risk_severity":"medium","security_risks":[{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Connector has 21 tools; permissions on claude.ai/directory: \"unknown\". Data flows out of the connected service into the model.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"medium","title":"Reads your private information"},{"description":"This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.","evidence":"4 state change tools on this connector - e.g. add_todo, add_project, update_todo, update_project.","remediation":{"block_tool_categories":["state_change"],"steps":["Try the connector on a test account first to see what it changes before letting it touch your real records.","Where the connected service supports it, give Claude read-only access and only allow writes for the specific things you need updated.","In the tools list below, turn off any tool you don't actively need - the ones tagged Block are the most important to disable."]},"risk_type":"modifies_data","severity":"medium","title":"Can change or update your information"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["network_access","reads_private_data","database_access"],"tools":[{"description":"Creates a new to-do in Things 3 with optional notes, scheduling, and organization parameters.","name":"add_todo","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Creates a new project in Things 3 with optional notes, deadlines, area assignment, and initial todos.","name":"add_project","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Retrieves all areas from Things 3, optionally including their child items.","name":"get_areas"},{"description":"Retrieves todos from Things 3 with optional filtering by project UUID and item inclusion.","name":"get_todos"},{"description":"Retrieves all projects from Things 3, optionally including their child items.","name":"get_projects"},{"description":"Retrieves all todos currently in the Things 3 Inbox list.","name":"get_inbox"},{"description":"Retrieves all todos scheduled or due for today in Things 3.","name":"get_today"},{"description":"Retrieves all upcoming todos from the Things 3 Upcoming list.","name":"get_upcoming"},{"description":"Retrieves all todos from the Things 3 Anytime list.","name":"get_anytime"},{"description":"Retrieves all todos from the Things 3 Someday list.","name":"get_someday"},{"description":"Retrieves completed todos from the Things 3 Logbook with optional period and limit filters.","name":"get_logbook"},{"description":"Retrieves all trashed todos from Things 3 for review.","name":"get_trash"},{"description":"Retrieves all tags defined in Things 3.","name":"get_tags"},{"description":"Finds all Things 3 items associated with a specific tag name.","name":"get_tagged_items"},{"description":"Searches todos in Things 3 using a required query string.","name":"search_todos"},{"description":"Performs a multi-criteria search across Things 3 items with optional tag, status, and trash filters.","name":"search_advanced"},{"description":"Retrieves recently modified Things 3 items within a configurable number of days (default 7).","name":"get_recent"},{"description":"Updates an existing todo in Things 3 by ID, supporting changes to title, notes, scheduling, tags, and status.","name":"update_todo","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Updates an existing project in Things 3 by ID, supporting changes to title, notes, scheduling, tags, and status.","name":"update_project","risk":{"category":"state_change","level":"medium","recommendation":"Allow only for low-stakes resources; require approval for production data changes.","why":"Creates, modifies, or uploads data on the connected service. Hijacking the tool can pollute records, plant content, or create rogue resources that bill the user."}},{"description":"Shows details for a specific Things 3 item identified by its ID.","name":"show_item"},{"description":"Performs a universal search across all Things 3 items using a required query string.","name":"search_items"}],"tools_count":21,"type":"web_connector","url":"https://claude.ai/directory","uuid":"ad74f6e2-f451-51aa-81ab-830f14da6e0d","version":"1.3.0"},"query_key":"things applescript","schema_version":1,"status":"match"}
