hermes-kanban-obsidian-integration

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior matches the stated Obsidian Kanban purpose, but the trust chain is weak. The skill asks users to install and run code from a personal GitHub repo that does not clearly match the claimed publisher, disable Obsidian Safe Mode, and optionally expose a writable REST API on the network with silent trust mode. No clear credential harvesting or malicious exfiltration is shown, so this is not confirmed malware, but the install provenance and remote-control surface make it higher-risk than a normal local productivity skill.

Confidence: 83%Severity: 66%
Audit Metadata
Analyzed At
May 17, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fhermes-kanban-obsidian-integration%2F@498cc819be10172db7b7f462ab15bf4f8c5edbea
Security Audit — socket — hermes-kanban-obsidian-integration