← Back to Scanner

obsidian-wiki Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

obsidian-wiki is an AI agent skill, created by ar9av and published at ar9av/obsidian-wiki. ClawSecure audited obsidian-wiki across 63 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 15 findings concentrate in Malicious Code, Code Injection and ReDoS, including Attempts to access sensitive file: MEMORY.md and Attempts to access sensitive file: MEMORY.md. 12 were rated high or critical severity.

Is obsidian-wiki safe?

ClawSecure audited obsidian-wiki and assigned a security score of 0/100 (High Risk), identifying 15 findings across Malicious Code and Code Injection. Review the findings below before installing.

What did ClawSecure find in obsidian-wiki?

ClawSecure identified 15 findings in obsidian-wiki, concentrated in Malicious Code, Code Injection and ReDoS. 12 were rated high or critical severity. The most severe include Attempts to access sensitive file: MEMORY.md and Attempts to access sensitive file: MEMORY.md.

How was obsidian-wiki audited?

ClawSecure ran obsidian-wiki through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 63 files from ar9av/obsidian-wiki.

What does a score of 0 mean?

ClawSecure assigned obsidian-wiki a security score of 0/100, placing it in the High Risk range. This is driven by 15 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for obsidian-wiki

ClawSecure detected 15 security findings in obsidian-wiki, spanning Malicious Code, Code Injection, ReDoS and Permissions Manifest.

Showing the 12 highest-severity of 15 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for obsidian-wiki

Audit external network connections
obsidian-wiki connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Eliminate dynamic code execution
obsidian-wiki evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Fix ReDoS-prone patterns
obsidian-wiki contains regular expressions vulnerable to catastrophic backtracking (ReDoS). Replace vulnerable patterns, bound input length, and prefer linear-time matching so a crafted input cannot hang the agent.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

invassistantScore 0/100invassistantScore 0/100probe-10-curl-pipeScore 15/100clip-itScore 0/100clickup-skillScore 0/100

Scanned on August 8, 2026. obsidian-wiki is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan