Install
$ agentstack add skill-eugenepyvovarov-things3-agent-skill-things3-agent-skill ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Things 3 Manager (CLI)
Quick start
- Ensure Things 3 is installed and opened at least once.
- In Things → Settings → General: enable “Enable Things URLs”.
- Run the CLI (auto-bootstraps
.skills-data/things3-manager/venvand installs deps on first run): bash .codex/skills/things3-manager/scripts/things --helpbash .codex/skills/things3-manager/scripts/things inboxbash .codex/skills/things3-manager/scripts/things search "weekly review"bash .codex/skills/things3-manager/scripts/things add-todo --title "Book flights" --when today --tag travel --checklist "passport" --checklist "charger"
Operating rules (for Codex)
- Prefer read-only commands first (
inbox,today,search,projects,areas,tags) to discover UUIDs and current state. - Before any write command (
add-todo,add-project,update-todo,update-project), summarize the exact changes and confirm with the user. - If the user provides a project/area/heading by name, resolve it by listing (
projects/areas/headings) before writing.
Local data and env
- Store all mutable state under /.skills-data//.
- Keep config and registries in .skills-data// (for example: config.json, .json).
- Use .skills-data//.env for SKILLROOT, SKILLDATA_DIR, and any per-skill env keys.
- Install local tools into .skills-data//bin and prepend it to PATH when needed.
- Install dependencies under .skills-data//venv:
- Python: .skills-data//venv/python
- Node: .skills-data//venv/node_modules
- Go: .skills-data//venv/go (modcache, gocache)
- PHP: .skills-data//venv/php (cache, vendor)
- Write logs/cache/tmp under .skills-data//logs, .skills-data//cache, .skills-data//tmp.
- Keep automation in /scripts and read SKILLDATADIR (default to /.skills-data//).
- Do not write outside and /.skills-data// unless the user requests it.
Commands (CLI)
- Lists:
inbox,today,upcoming,anytime,someday,logbook,trash,recent- Browsing:
projects,areas,tags,headings,todos,tagged-items- Search:
search,search-advanced- Writes (via Things URL scheme):
add-todo,add-project,update-todo,update-project- Open in Things:
show,search-items
Attribution
- CLI implementation is based on
things_server.py,url_scheme.py, andformatters.pyfromhttps://github.com/hald/things-mcp.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: eugenepyvovarov
- Source: eugenepyvovarov/things3-agent-skill
- License: MIT
- Homepage: https://mcp-bundler.com/skills-marketplace/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.