obsidian-cli
Warn
Audited by Socket on Jul 29, 2026
1 alert found:
AnomalyAnomalyskill-report.json
LOWAnomalyLOW
skill-report.json
No clear embedded malware payload is evident in the provided fragment. However, the document operationalizes a high-impact local automation surface: it can mutate an Obsidian vault, extract potentially sensitive local data (including via clipboard copying and UI/DOM/console inspection), and—most critically—run arbitrary JavaScript in the local Obsidian app context via obsidian eval. In a supply-chain/agent-driven workflow, this should be treated as a high-risk capability document requiring strong input controls and explicit user confirmation/disablement of app-context eval and write operations by default.
Confidence: 68%Severity: 65%
Audit Metadata