viva-llm

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities generally match its stated purpose, but the footprint is very broad and high-impact: recursive agents, terminal execution, dynamic MCP tools, screen capture, and continuous vault-context sharing. There is no clear evidence of outright malware or deceptive credential harvesting in the provided text, but the autonomy and data-flow scope make this a high-risk Obsidian automation skill.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Apr 16, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/zpankz%2Fobsidian-skills%2Fviva-llm%2F@70ce4144a093e027146f004e6cbc9b05742e2ce2