codex-obsidian

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent with Obsidian integration, and the recommended folder-authorization path is low risk. Risk rises because the alternate/advanced paths rely on third-party npm/CLI components with unpinned remote execution and expanded trust, but there is no clear evidence of credential theft or intentionally malicious behavior.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/mathruffian-dot%2Fcodex-lazy-packs%2Fcodex-obsidian%2F@d477171d097c44ca7c94cbfb5f3098de0f965a259102881b00829d83aaa6f141
Security Audit — socket — codex-obsidian