obsidian

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's actual footprint does not match its stated Obsidian purpose: it is a generic third-party AI gateway skill with broad model access plus email/SMS actions. The main security issue is data-flow integrity: prompts, files, phone numbers, and the API credential all flow to api.heybossai.com rather than to the official provider endpoints it claims to abstract. No install chain or obfuscation is present, so this is not confirmed malware, but the purpose-capability mismatch, intermediary routing, and autonomous messaging capabilities make it a high-risk skill.

Confidence: 92%Severity: 78%
Audit Metadata
Analyzed At
Mar 21, 2026, 06:29 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fobsidian%2F@e9f3eef3f328577d0188abc6a78d8e36b4d45d3a