Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThis skill queries a local knowledge base (Obsidian wiki) and requires access to sensitive files like .env and local config folders to resolve the vault path. It executes shell commands using the qmd CLI and interpolates user search terms, which poses a command injection risk. It also processes untrusted markdown content, creating a risk of indirect prompt injection.
Socket
passNo alerts
Snyk
failRisk: CRITICAL · 1 issue
ZeroLeaks
passScore: 93/100 · 2 sections analyzed