markdown-vault-sync

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with Obsidian vault syncing, but it expands scope by requiring a second skill and by letting agents synthesize from arbitrary project content while writing into the vault. The main risk is transitive trust plus prompt-injection exposure from untrusted repository text, not overt malware or credential theft.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Mar 30, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/ylt%2Fclaude-plugins%2Fmarkdown-vault-sync%2F@38329d8d0a656b6af600d1d289f04716345c32a7