obsidian-helper

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s note-taking purpose is coherent, and its main API target is local Obsidian rather than an external gateway, but its install and credential model are not proportionate: it tells the agent/user to run an unpinned npm-fetched MCP package whose provenance was not clearly verified, then forwards the Obsidian API key to that package. The main risk is supply-chain compromise and credential forwarding to third-party code, not confirmed malware.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Apr 12, 2026, 03:00 AM
Package URL
pkg:socket/skills-sh/ZhanlinCui%2FAgent-Skills-Hunter%2Fobsidian-helper%2F@78ee2c9df7d754e5f4b551f03138c147b0edefc5