obsidian-second-brain

Warn

Audited by Socket on Aug 7, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core behavior mostly matches its stated Obsidian/research purpose, and install sources appear same-project rather than covert third parties. However, the combination of transitive skill installation, official-but-risky `curl|bash`, autonomous scheduled rewriting, and ingestion of untrusted web content with write/exec permissions makes the overall security posture medium risk.

Confidence: 84%Severity: 56%
AnomalyLOW
scripts/install.sh

No clear indicators of intentional malware (no obfuscation, no exfiltration, no backdoor/persistence beyond an expected jeo hook, no credential theft). However, the script increases supply-chain risk by fetching and executing third-party code (npx from REPO_URL; git clone/pull from UPSTREAM_URL; executing upstream scripts; installing a runtime hook that will execute the resolved adapter). Without version pinning/integrity checks in this script, compromise of those sources could lead to arbitrary code execution in the user’s environment.

Confidence: 68%Severity: 52%
Audit Metadata
Analyzed At
Aug 7, 2026, 09:03 AM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-skills%2Fobsidian-second-brain%2F@0014360078762b4648f829c7e2adf5ed42504b214a70deaa2d58c7d987289d4b
Security Audit — socket — obsidian-second-brain