codex-github-obsidian
Warn
Audited by Socket on Jun 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities mostly match its stated GitHub-Obsidian integration purpose, but it expands trust to a non-official third-party MCP server and performs real write actions including git push. This is not confirmed malware, but the combined local vault access, GitHub auth usage, and unpinned third-party npm execution make it a medium-risk skill that should only run with explicit user approval.
Confidence: 100%Severity: 60%
Audit Metadata