obsidian

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s local note-management behavior is broadly aligned with its purpose, but the trust chain is inconsistent because it presents as an Obsidian skill while installing a third-party CLI from an unrelated publisher instead of Obsidian’s official CLI path. Risk is driven by supply-chain ambiguity, not confirmed malicious behavior or exfiltration.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Mar 29, 2026, 10:39 PM
Package URL
pkg:socket/skills-sh/smallnest%2Fgoclaw%2Fobsidian%2F@545db81b360e2ad9a02f132796ec85fbb759385c