Audit History
obsidian-bases - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 8, 2026, 01:40 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 8, 2026, 01:40 PM | No confirmed findings | 0 | External commandsNetwork accessFilesystem access |
| v2 | Jul 1, 2026, 02:53 AM | No confirmed findings | 0 | External commandsNetwork accessFilesystem access |
| v1 | Feb 24, 2026, 09:29 AM | No confirmed findings | 0 | Baseline |
Jul 8, 2026, 01:40 PM
Review found the static findings to be false positives caused by Markdown backticks, YAML code fences, formula examples, and official Obsidian documentation links. No evidence found of executable scripts, command execution instructions, data exfiltration, prompt injection, or unsafe network behavior in SKILL.md.
Risk Factors
⚙️ External commands (150)
🌐 Network access (4)
📁 Filesystem access (1)
Jul 8, 2026, 01:40 PM
Review found the static findings to be false positives caused by Markdown backticks, YAML code fences, formula examples, and official Obsidian documentation links. No evidence found of executable scripts, command execution instructions, data exfiltration, prompt injection, or unsafe network behavior in SKILL.md.
Risk Factors
⚙️ External commands (150)
🌐 Network access (4)
📁 Filesystem access (1)
Jul 1, 2026, 02:53 AM
Static analysis reported command execution, network, filesystem, sensitive key, weak crypto, and heuristic risks. Manual review found these are Markdown examples, inline code, Obsidian formula references, and official documentation links, with no executable script, prompt injection, credential handling, or data exfiltration evidence.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Feb 24, 2026, 09:29 AM
Static analyzer detected 259 patterns (233 external_commands, 4 network, 1 filesystem) but all are FALSE POSITIVES. The SKILL.md file is documentation-only describing YAML syntax for Obsidian Bases. Backticks are Markdown code formatting, not shell execution. URLs are reference links to Obsidian documentation. No executable code, network calls, or filesystem operations exist in this skill.