obsidian-plugins

Fail

Audited by Snyk on Jul 8, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). Most URLs are official Obsidian or standard resources and appear safe, but the example GitHub repository URL (https://github.com/author/plugin-repo) is an unvetted third‑party source referenced for BRAT installs and could be used to distribute malicious plugins.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.75). Required workflow includes installing community plugins and using BRAT, which at runtime ingests outsider-authored plugin files (e.g., manifest.json/data.json and other text from downloaded GitHub/community sources) into the vault/agent context; this is an outsider source via public/community plugin repositories and GitHub.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 8, 2026, 04:25 PM
Issues
2
Security Audit — snyk — obsidian-plugins