Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill exposes explicit remote read/write file-sync endpoints, including a write API, but the documentation does not clearly warn users that misconfiguration, token compromise, or unsafe exposure can modify or overwrite local notes and workspace data. Because this is a sync server intended to bridge an agent workspace with an Obsidian vault, the context increases risk: users may treat it as routine tooling while granting it access to sensitive notes.
