cc-second-brain
Warn
Audited by Socket on Apr 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core behavior fits a memory-management skill, but it implicitly relies on third-party Obsidian MCP/community plugin infrastructure that can receive vault data and API credentials. The skill is not overtly malicious and has no direct installer payload, yet its trust boundary is under-specified and broader than ideal for a local knowledge tool.
Confidence: 82%Severity: 58%
Audit Metadata