obsidian-cli

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Anomaly
AnomalyLOW
skill-report.json

No clear embedded malware payload is evident in the provided fragment. However, the document operationalizes a high-impact local automation surface: it can mutate an Obsidian vault, extract potentially sensitive local data (including via clipboard copying and UI/DOM/console inspection), and—most critically—run arbitrary JavaScript in the local Obsidian app context via obsidian eval. In a supply-chain/agent-driven workflow, this should be treated as a high-risk capability document requiring strong input controls and explicit user confirmation/disablement of app-context eval and write operations by default.

Confidence: 68%Severity: 65%
Audit Metadata
Analyzed At
Jul 29, 2026, 03:37 PM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fobsidian-cli%2F@ddec43daefb58ec6bd5df76939418158f3fa132ffccb24554ceef8fcf78e6290
Security Audit — socket — obsidian-cli