obsidian-plugins
Fail
Audited by Snyk on Jul 8, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). Most URLs are official Obsidian or standard resources and appear safe, but the example GitHub repository URL (https://github.com/author/plugin-repo) is an unvetted third‑party source referenced for BRAT installs and could be used to distribute malicious plugins.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Required workflow includes installing community plugins and using BRAT, which at runtime ingests outsider-authored plugin files (e.g.,
manifest.json/data.jsonand other text from downloaded GitHub/community sources) into the vault/agent context; this is an outsider source via public/community plugin repositories and GitHub.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata