NYC

obsidian

Warn

Audited by Socket on Feb 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Download or install from free hosting/deployment platform detected BENIGN with caveats: The Obsidian PKM fragment is coherent and useful for building a local-first knowledge management system. While the content is documentation-rich and includes runnable-like scripts for syncing and integrations, there are no embedded secrets or covert data exfiltration mechanisms. The main risk arises from executing integration samples or backup scripts with insecure secrets or misconfigured endpoints. With proper secret management, restricted access, and secure backend configurations, the material remains appropriate for its stated purpose. LLM verification: This SKILL.md is a benign documentation/instruction file for using Obsidian. I found no embedded malware, obfuscated payloads, credential harvesting, or network exfiltration mechanisms in the provided content. The primary risks are operational: commands that download and execute binaries (legitimate sources in the doc) and mention of destructive commands (rm -rf) which could be dangerous if misused. Use caution: verify URLs and package sources before running install commands, avoid copy-pasting

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 18, 2026, 12:24 AM
Package URL
pkg:socket/skills-sh/vamseeachanta%2Fworkspace-hub%2Fobsidian%2F@27c848b4ef557a3534eb770e36385e2e6b863953