Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
obsidian-user-guide
v1.0.0Provides command-line instructions for managing Obsidian vaults, notes, tasks, tags, links, and searches via Obsidian's official CLI tool.
⭐ 0· 343·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
medium confidencePurpose & Capability
Name/description match the SKILL.md: the document is a CLI guide for Obsidian and the commands and installation steps described are consistent with that purpose.
Instruction Scope
Instructions are limited to installing/enabling Obsidian CLI, running obsidian CLI commands, cloning a skills repo into the OpenClaw skills directory, and restarting the gateway. The SKILL.md does not instruct reading unrelated system files or exporting secrets.
Install Mechanism
There is no formal install spec, but the SKILL.md tells users/agents to git clone https://github.com/kepano/obsidian-skills into ~/.openclaw/workspace/skills/. GitHub is a common host, but cloning an external repository into the agent's skills folder will place arbitrary SKILL.md files and possibly other code under the OpenClaw workspace; you should review the repository contents before cloning.
Credentials
The skill does not request environment variables, credentials, or config paths. All commands shown use the local Obsidian CLI and local file paths, which is proportionate to the described functionality.
Persistence & Privilege
always is false and model invocation is allowed by default. The SKILL.md asks the user/agent to restart the gateway so the new SKILL.md files are discovered, which is a normal installation step and does not request privileged system-wide changes.
Assessment
This appears to be a straightforward Obsidian CLI usage guide. Before following the SKILL.md installation steps, especially the git clone, inspect the GitHub repository (https://github.com/kepano/obsidian-skills) to confirm it only contains the SKILL.md files you expect. Prefer copying only the single SKILL.md you trust instead of cloning an entire third‑party repo into ~/.openclaw/workspace/skills/. Be cautious about executing any scripts found in that repo and verify the repo owner and contents if you require a higher assurance level.Like a lobster shell, security has layers — review code before you run it.
latestvk973x9m8ss2frgknc8gzwhw55582e1pv
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
