obsidian-devtools

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill exposes arbitrary JavaScript execution in the user's Obsidian context and enables remote debugging connections, which directly enables data exfiltration, credential theft, and remote code execution risks if misused or accessed by an attacker.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 16, 2026, 01:36 AM