Obsidian Automation
Warn
Audited by Socket on Jun 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s stated purpose is coherent and mostly local-note oriented, but it relies on an undeclared third-party MCP server with unclear provenance and broad potential vault access. There is no direct evidence of malware or credential theft, yet the unverifiable backend dependency creates a meaningful supply-chain and data-exposure risk disproportionate to the sparse installation and trust details.
Confidence: 80%Severity: 74%
Audit Metadata