低风险 — 风险评分 10/100
上次扫描:17 小时前 重新扫描
10 /100
obsidian-litiao
Work with Obsidian vaults (plain Markdown notes) and automate via obsidian-cli
This is a documentation-only skill that describes Obsidian vault management using obsidian-cli. No executable code, scripts, or malicious behavior detected.
技能名称obsidian-litiao
分析耗时26.2s
引擎pi
可以安装
This skill is safe to use. It only contains documentation for Obsidian CLI operations and does not execute any code or access sensitive resources.

安全发现 1 项

严重性 安全发现 位置
提示
External URL reference 文档欺骗
SKILL.md references https://help.obsidian.md as homepage/documentation
homepage: https://help.obsidian.md
→ This is a legitimate Obsidian documentation URL, not a security concern
SKILL.md:4
资源类型声明权限推断权限状态证据
文件系统 READ READ ✓ 一致 SKILL.md describes reading Obsidian vault files and config
命令执行 READ READ ✓ 一致 SKILL.md documents obsidian-cli commands (search, create, move, delete)
网络访问 NONE NONE No network access required or used
环境变量 NONE NONE No environment variable access documented
技能调用 READ READ ✓ 一致 Skill invokes obsidian-cli for vault operations
1 项发现
🔗
中危 外部 URL 外部 URL
https://help.obsidian.md
SKILL.md:4

目录结构

2 文件 · 2.4 KB · 60 行
Markdown 1f · 55L JSON 1f · 5L
├─ 📋 _meta.json JSON 5L · 127 B
└─ 📝 SKILL.md Markdown 55L · 2.3 KB

依赖分析 1 项

包名版本来源已知漏洞备注
obsidian-cli latest brew (yakitrak/yakitrak/obsidian-cli) External CLI tool, declared in metadata.requires.bins

安全亮点

✓ No executable scripts or code files in the package
✓ Skill is purely documentation for Obsidian vault operations
✓ Uses well-known obsidian-cli tool for vault management
✓ No credential harvesting or sensitive data access
✓ No network exfiltration or C2 communication
✓ No obfuscation or anti-analysis techniques
✓ Dependencies declared (obsidian-cli binary via brew)