obsidian
Warn
Audited by Snyk on Feb 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's installation step downloads and executes a remote binary (wget https://github.com/obsidianmd/obsidian-releases/releases/download/v1.5.3/Obsidian-1.5.3.AppImage followed by chmod +x and ./Obsidian-1.5.3.AppImage), which fetches and runs remote code required to install/run the tool.
Audit Metadata