cc-obsidian

Warn

Audited by Socket on Jun 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core skill is mostly coherent and likely benign: installing same-project MCPVault from npm to connect Claude Code to an Obsidian vault matches its stated purpose. Risk rises because it grants broad read/write access to local notes and, in the advanced path, pulls in an unrelated third-party CLI/install ecosystem that expands trust and execution scope beyond the core integration.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 14, 2026, 02:06 AM
Package URL
pkg:socket/skills-sh/mathruffian-dot%2Fclaude-code-lazy-packs%2Fcc-obsidian%2F@541f9a800c205a0d1771a02ace8c421e1f757c923b088c72c48e80bdb951f470
Security Audit — socket — cc-obsidian