@steipete

Obsidian

Work with Obsidian vaults (plain Markdown notes) and automate via obsidian-cli.

Current version
v1.0.0
322 8万All installs 2,360

v1.0.0

2026/01/04

Version

No changelog provided.

Security Scan

Status

suspicious

Open VirusTotal

OpenClaw

gpt-5-mini

suspicious

OpenClaw analysis

The skill's instructions are plausible for automating Obsidian via obsidian-cli, but there are several inconsistencies and privacy-relevant actions (reading a user config file) that aren't declared or explained.

Confidence: medium

VirusTotal

Type: OpenClaw Skill Name: obsidian Version: 1.0.0 The skill is classified as suspicious due to its reliance on installing a third-party command-line tool (`obsidian-cli`) from a custom Homebrew tap (`yakitrak/yakitrak`) as specified in `SKILL.md`. This introduces a supply chain risk, as the integrity of the `obsidian-cli` tool depends on the `yakitrak` maintainer. Additionally, `SKILL.md` explicitly instructs the AI agent to read a local configuration file (`~/Library/Application Support/obsidian/obsidian.json`), which, while necessary for the stated purpose, represents a direct instruction for file system access, a high-risk capability. There is no clear evidence of intentional malicious behavior like data exfiltration or persistence.

Metadata

  • Owner: @steipete
  • Created: 2026/01/04
  • Updated: 2026/04/14
  • Versions: 1
  • Comments: 9
  • Scan checked at: 2026/02/11

Runtime

No runtime requirements are exposed in the official public payload.

Obsidian | ClawHub CN