obsidian-project-lifecycle

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches the visible capabilities: local Obsidian lifecycle management with archive/purge/rename flows. However, execution trust is weakened because the core behavior is delegated to an unverified local helper script outside this skill, with no public provenance or release verification in the evidence. No credential handling, network exfiltration, or third-party routing is shown, so the main concern is opaque local code plus destructive filesystem actions rather than confirmed malicious behavior.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/Galaxy-Dawn%2Fclaude-scholar%2Fobsidian-project-lifecycle%2F@445d1319ace90a7dc16f2970ca787f5ac068174d