note-promotion

Warn

Audited by Socket on Jun 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s note-promotion behavior is coherent and bounded, with user confirmation before writes, but it relies on an ambiguous community 'obsidian-mcp' dependency whose likely ecosystem involves third-party credential handling, unpinned execution paths, and possible TLS verification disabling. The skill content itself is not malicious; the main risk is external MCP trust and credential/data routing outside official Obsidian-owned infrastructure.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Jun 29, 2026, 06:31 AM
Package URL
pkg:socket/skills-sh/r007b34r%2Fopencode-obsidian-knowledge-workflow%2Fnote-promotion%2F@88acac4a8f13607075b03270b4c69e83d008a39582d42a6f0a6cdb2a0ac8f6df
Security Audit — socket — note-promotion