codex-github-obsidian

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated GitHub-Obsidian integration purpose, but it expands trust to a non-official third-party MCP server and performs real write actions including git push. This is not confirmed malware, but the combined local vault access, GitHub auth usage, and unpinned third-party npm execution make it a medium-risk skill that should only run with explicit user approval.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/mathruffian-dot%2Fcodex-lazy-packs%2Fcodex-github-obsidian%2F@e397f91595c331de3cefc4e4ecff9c381c96bb9a27e50927ba1d9127aeac6889
Security Audit — socket — codex-github-obsidian