Agent skill

Obsidian Security Basics

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Implement secure Obsidian plugin development practices. An agent skill from jeremylongshore/tons-of-skills-marketplace.

MITAuto-check passedSecurity

Install Obsidian Security Basics

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill obsidian-security-basics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace obsidian-security-basics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/saas-packs/obsidian-pack/skills/obsidian-security-basics .claude/skills/obsidian-security-basics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
obsidian-security-basics
GitHub stars
2.8k
Token cost
~3.3k tokens
SKILL.md length
332 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Implement secure Obsidian plugin development practices. An agent skill from jeremylongshore/tons-of-skills-marketplace.

  • Works in 6 steps: Credential Storage — Never in data.json → Input Validation and XSS Prevention → Secure URI Handler Registration → …
  • Handling user data
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Obsidian Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement secure Obsidian plugin development practices. Covers credential storage, input validation, XSS prevention, network security, URI handler safety, and Electron security. Use when handling user data, storing API keys, making network requests, or preparing for community plugin submission. Trigger with phrases like "obsidian security", "secure obsidian plugin", "obsidian data protection", "obsidian privacy", "obsidian api key storage".

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code

It sits in Security, covering Web application vulnerabilities, Privacy and GDPR and Network security. It works with Obsidian. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Handling user data
  • Storing API keys
  • Making network requests
  • Preparing for community plugin submission

Example prompts

  • “obsidian security”
  • “secure obsidian plugin”
  • “obsidian data protection”
  • “/obsidian-security-basics”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Credential Storage — Never in data.json
  2. Input Validation and XSS Prevention
  3. Secure URI Handler Registration
  4. Secure Network Requests
  5. Permission Minimization
  6. Plugin Review Rejection Checklist

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.obsidian.md
    • electronjs.org
    • cheatsheetseries.owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Obsidian Security Basics loads about 3.3k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 332 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 332 words, ~3,310 tokens.

Download SKILL.mdSave it as .claude/skills/obsidian-security-basics/SKILL.md (or your agent's skills folder).
name
obsidian-security-basics
description
Implement secure Obsidian plugin development practices. Covers credential storage, input validation, XSS prevention, network security, URI handler safety, and Electron security. Use when handling user data, storing API keys, making network requests, or preparing for community plugin submission. Trigger with phrases like "obsidian security", "secure obsidian plugin", "obsidian data protection", "obsidian privacy", "obsidian api key storage".
allowed-tools
Read, Write, Edit, Grep
compatibility
Designed for Claude Code
version
1.13.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
obsidian, security, authentication, privacy, electron

Obsidian Security Basics

Overview

Security practices for Obsidian plugin development. Plugins run with full vault filesystem access and can make arbitrary network requests inside Electron. Responsible development requires protecting credentials, sanitizing external data, validating URI handlers, minimizing permissions, and following Obsidian's plugin guidelines to avoid community submission rejection.

Prerequisites

  • Obsidian plugin development environment
  • Understanding that .obsidian/plugins/<id>/data.json is synced by cloud services
  • Awareness of Obsidian Plugin Guidelines

Instructions

Step 1: Credential Storage — Never in data.json

Plugin settings (data.json) live inside the vault and are synced by iCloud, Dropbox, Obsidian Sync, and Git. API keys stored here are effectively public.

typescript
// BAD: API key stored in plugin settings (synced to cloud, committed to Git)
interface BadSettings {
  apiKey: string; // This ends up in .obsidian/plugins/my-plugin/data.json
}

// GOOD: Use Electron's safeStorage for desktop (encrypted at OS level)
import { Platform } from 'obsidian';

export class SecureStorage {
  private plugin: Plugin;

  constructor(plugin: Plugin) { this.plugin = plugin; }

  async storeSecret(key: string, value: string): Promise<void> {
    if (Platform.isDesktopApp) {
      // Electron's safeStorage uses OS keychain (Keychain on macOS, DPAPI on Windows)
      const { safeStorage } = require('electron').remote || require('@electron/remote');
      if (safeStorage.isEncryptionAvailable()) {
        const encrypted = safeStorage.encryptString(value);
        const data = await this.plugin.loadData() ?? {};
        data[`_encrypted_${key}`] = encrypted.toString('base64');
        await this.plugin.saveData(data);
        return;
      }
    }
    // Fallback for mobile or when encryption unavailable: prompt each session
    // Store only in memory — never persisted
    this.memoryStore.set(key, value);
  }

  async getSecret(key: string): Promise<string | null> {
    if (Platform.isDesktopApp) {
      const { safeStorage } = require('electron').remote || require('@electron/remote');
      const data = await this.plugin.loadData();
      const encrypted = data?.[`_encrypted_${key}`];
      if (encrypted && safeStorage.isEncryptionAvailable()) {
        return safeStorage.decryptString(Buffer.from(encrypted, 'base64'));
      }
    }
    return this.memoryStore.get(key) ?? null;
  }

  private memoryStore = new Map<string, string>();
}

// Alternative: prompt user each session (simplest, most secure)
async onload() {
  if (!this.apiKey) {
    this.apiKey = await this.promptForApiKey();
  }
}
Step 2: Input Validation and XSS Prevention

Data from HTTP responses, clipboard, or URI handlers must be sanitized before rendering.

typescript
// Sanitize HTML content before inserting into Obsidian views
function sanitizeHtml(input: string): string {
  // Strip dangerous elements
  input = input.replace(/<script[^>]*>[\s\S]*?<\/script>/gi, '');
  input = input.replace(/<iframe[^>]*>[\s\S]*?<\/iframe>/gi, '');
  input = input.replace(/<object[^>]*>[\s\S]*?<\/object>/gi, '');
  input = input.replace(/<embed[^>]*>/gi, '');
  // Strip event handlers
  input = input.replace(/\bon\w+\s*=\s*"[^"]*"/gi, '');
  input = input.replace(/\bon\w+\s*=\s*'[^']*'/gi, '');
  // Strip javascript: URIs
  input = input.replace(/href\s*=\s*"javascript:[^"]*"/gi, 'href="#"');
  return input;
}

// For plain text in DOM elements — escape instead of strip
function escapeHtml(text: string): string {
  const div = document.createElement('div');
  div.textContent = text;
  return div.innerHTML;
}

// Safe DOM creation (preferred in Obsidian)
// Use createEl with text content — Obsidian escapes automatically
container.createEl('p', { text: userInput }); // Safe — text is escaped
container.createEl('p').innerHTML = userInput;  // DANGEROUS — raw HTML injection

// For markdown content from external sources
function sanitizeMarkdown(md: string): string {
  // Remove HTML blocks that could contain scripts
  md = md.replace(/<script[\s\S]*?<\/script>/gi, '');
  // Remove image onerror handlers
  md = md.replace(/onerror\s*=\s*["'][^"']*["']/gi, '');
  // Limit length to prevent DoS
  if (md.length > 500_000) md = md.substring(0, 500_000);
  return md;
}
Step 3: Secure URI Handler Registration

Obsidian's registerObsidianProtocolHandler lets external apps trigger plugin actions via obsidian:// URIs. Validate all parameters.

typescript
this.registerObsidianProtocolHandler('myplugin', async (params) => {
  // Whitelist allowed actions
  const ALLOWED_ACTIONS = ['open', 'create', 'search'] as const;
  type Action = typeof ALLOWED_ACTIONS[number];

  const action = params.action as string;
  if (!ALLOWED_ACTIONS.includes(action as Action)) {
    new Notice(`Invalid action: ${action}`);
    return;
  }

  // Sanitize file paths — prevent directory traversal
  const path = params.path?.replace(/\.\./g, '').replace(/^\//, '');
  if (!path) {
    new Notice('Missing path parameter');
    return;
  }

  // Validate path is within vault
  const normalized = normalizePath(path);
  if (normalized.includes('..') || normalized.startsWith('/')) {
    new Notice('Invalid path');
    return;
  }

  // Limit content length
  const content = params.content?.substring(0, 100_000) ?? '';

  switch (action as Action) {
    case 'open': {
      const file = this.app.vault.getAbstractFileByPath(normalized);
      if (file instanceof TFile) {
        await this.app.workspace.getLeaf().openFile(file);
      } else {
        new Notice(`File not found: ${normalized}`);
      }
      break;
    }
    case 'create': {
      await this.app.vault.create(normalized, content);
      new Notice(`Created: ${normalized}`);
      break;
    }
    case 'search': {
      // Use Obsidian's built-in search
      (this.app as any).internalPlugins.plugins['global-search']
        ?.instance.openGlobalSearch(content);
      break;
    }
  }
});
Step 4: Secure Network Requests
typescript
import { requestUrl, RequestUrlParam } from 'obsidian';

// Always use Obsidian's requestUrl — it respects proxy settings and CORS
async function secureFetch(url: string, options?: Partial<RequestUrlParam>): Promise<any> {
  // Enforce HTTPS
  if (!url.startsWith('https://')) {
    throw new Error('Only HTTPS requests are allowed');
  }

  // Allowlist domains (prevents SSRF if URL comes from user input)
  const ALLOWED_DOMAINS = ['api.example.com', 'cdn.example.com'];
  const urlObj = new URL(url);
  if (!ALLOWED_DOMAINS.includes(urlObj.hostname)) {
    throw new Error(`Domain not allowed: ${urlObj.hostname}`);
  }

  const response = await requestUrl({
    url,
    method: 'GET',
    headers: {
      'User-Agent': 'ObsidianPlugin/1.0',
      ...options?.headers,
    },
    ...options,
  });

  if (response.status < 200 || response.status >= 300) {
    throw new Error(`HTTP ${response.status}: ${url}`);
  }

  return response.json;
}

// Never log or display full API responses — they may contain PII
function redactForLogging(data: any): any {
  const redacted = { ...data };
  const sensitiveKeys = ['apiKey', 'token', 'password', 'secret', 'authorization'];
  for (const key of Object.keys(redacted)) {
    if (sensitiveKeys.some(s => key.toLowerCase().includes(s))) {
      redacted[key] = '[REDACTED]';
    }
  }
  return redacted;
}
Step 5: Permission Minimization
typescript
// manifest.json — only set isDesktopOnly if you actually need Electron APIs
{
  "isDesktopOnly": false
  // Obsidian has no granular permission model in manifest.json.
  // The review team evaluates your code for:
  // - Network requests: must be essential to plugin function
  // - Filesystem access outside vault: strongly discouraged
  // - No telemetry/analytics without explicit user consent
  // - No remote code loading (eval, new Function, loading JS from URL)
}

// At runtime: guard platform-specific code
import { Platform, FileSystemAdapter } from 'obsidian';

function getVaultBasePath(): string | null {
  if (this.app.vault.adapter instanceof FileSystemAdapter) {
    return this.app.vault.adapter.getBasePath();
    // IMPORTANT: never access files outside this basePath
  }
  return null; // Mobile — no filesystem access outside vault
}

// Guard Electron APIs
if (Platform.isDesktopApp) {
  // Safe to use: require('electron'), child_process, etc.
} else {
  // Mobile: these APIs don't exist — provide fallback or disable feature
}
Step 6: Plugin Review Rejection Checklist

Obsidian's plugin review team will reject plugins for these violations:

typescript
// REJECTED: eval() or dynamic code execution
eval(userInput);                    // Never
new Function('return ' + code)();  // Never
document.createElement('script');  // Never for external scripts

// REJECTED: remote code loading
const script = document.createElement('script');
script.src = 'https://cdn.example.com/lib.js';  // Load at build time instead

// REJECTED: console.log in production
console.log('user data:', settings);  // Remove before submission

// REJECTED: unencrypted credential storage
this.saveData({ apiKey: 'sk-abc123' });  // Use SecureStorage (Step 1)

// REJECTED: undisclosed network requests
fetch('https://analytics.example.com/track', { body: ... });  // No hidden telemetry

// APPROVED alternatives:
// - Bundle dependencies with esbuild (no runtime loading)
// - Use a debug flag for console statements
// - Document all network requests in README
// - Get explicit consent before any data leaves the device

Output

  • SecureStorage class using Electron's safeStorage for encrypted credential storage
  • HTML and markdown sanitization for all external content
  • URI handler with action whitelist and path validation
  • Secure network request wrapper with HTTPS enforcement and domain allowlist
  • Platform-specific guards for desktop/mobile code paths
  • Plugin review rejection checklist with approved alternatives

Error Handling

IssueCauseSolution
API key synced to cloudStored in data.jsonUse SecureStorage with Electron safeStorage
XSS in note previewUnsanitized external HTMLUse createEl with text property, or sanitizeHtml
Directory traversal via URIUnvalidated path parameterStrip .., normalize, validate within vault
SSRF from user-provided URLNo domain allowlistValidate against ALLOWED_DOMAINS before requestUrl
Plugin rejected on revieweval, console.log, or telemetryFollow rejection checklist (Step 6)
safeStorage unavailableOlder Electron version or mobileFall back to per-session prompt

Examples

Content Security for Custom Views
typescript
// When rendering external content in an ItemView
async onOpen() {
  const externalData = await this.fetchData();
  const container = this.containerEl.children[1];
  container.empty();

  // Safe: text content is escaped by createEl
  container.createEl('h3', { text: externalData.title });
  container.createEl('p', { text: externalData.summary });

  // If you must render HTML, sanitize first
  const safeHtml = sanitizeHtml(externalData.htmlContent);
  const htmlContainer = container.createEl('div');
  htmlContainer.innerHTML = safeHtml;
}
Audit Your Plugin for Security Issues
bash
# Quick security audit of plugin source code
grep -rn 'eval(\|new Function(' src/ --include="*.ts" && echo "FAIL: dynamic code execution"
grep -rn 'innerHTML\s*=' src/ --include="*.ts" && echo "WARN: check for XSS"
grep -rn 'console\.log' src/ --include="*.ts" | grep -v '// DEBUG' && echo "WARN: console.log in prod"
grep -rn 'apiKey\|secret\|password' src/ --include="*.ts" && echo "CHECK: credential handling"
echo "Done."

Resources

Next Steps

For production readiness checks, see obsidian-prod-checklist. For deployment and community submission, see obsidian-deploy-integration.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/saas-packs/obsidian-pack/skills/obsidian-security-basics of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Obsidian Security Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Obsidian Security Basics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Obsidian Security Basics this skilljeremylongshore/tons-of-skills-marketplace2.8k—~3.3kAutomated safety check: PassMIT
Expert SecurityReJeCtAll/ExpertTeam-Codex113—~780Automated safety check: PassMIT
Security and Hardeningaddyosmani/agent-skills105k1 repos~4.4kAutomated safety check: NotesMIT
Performing Ssl Tls Inspection Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: NotesApache-2.0
Google Cloud Waf Securitygoogle/skills21k1 repos~4.2kAutomated safety check: PassApache-2.0
Security Auditoraiskillstore/marketplace4336 repos~2.6kAutomated safety check: PassNone

Similar skills

  • Expert Security

    ReJeCtAll/ExpertTeam-Codex

    安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

    113 GitHub stars~780 tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    105k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Performing Ssl Tls Inspection Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Configure SSL/TLS break-and-inspect on next-generation firewalls and forward proxies to decrypt, inspect, and re-encrypt HTTPS traffic for malware and exfiltration detection, including deploying…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Official

    Generates security-focused guidance for Google Cloud workloads based on the design principles and recommendations in the Google Cloud Well-Architected Framework (WAF).

    21k GitHub starsUsed in 1 repo~4.2k tokens
    SecurityAuto-check passed
  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    433 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Security Auditor

    curiositech/some_claude_skills

    Security vulnerability scanner and OWASP compliance auditor for codebases.

    244 GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Obsidian Security Basics

What does Obsidian Security Basics do?

Implement secure Obsidian plugin development practices. An agent skill from jeremylongshore/tons-of-skills-marketplace. Obsidian Security Basics is an agent skill from jeremylongshore/tons-of-skills-marketplace. Implement secure Obsidian plugin development practices.

When should I use Obsidian Security Basics?

Obsidian Security Basics fits situations like: handling user data; storing API keys; making network requests; preparing for community plugin submission.

How do I install Obsidian Security Basics in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill obsidian-security-basics -a claude-code`. Or copy the skill folder (plugins/saas-packs/obsidian-pack/skills/obsidian-security-basics in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/obsidian-security-basics in your project. Claude Code loads it when a task matches its description.

How do I install Obsidian Security Basics in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill obsidian-security-basics -a codex`. Or copy the skill folder (plugins/saas-packs/obsidian-pack/skills/obsidian-security-basics in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/obsidian-security-basics in your project. Codex loads it when a task matches its description.

Can I use Obsidian Security Basics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill obsidian-security-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/obsidian-security-basics, .gemini/skills/obsidian-security-basics, .github/skills/obsidian-security-basics and .opencode/skills/obsidian-security-basics in your project.

What does Obsidian Security Basics need to run?

SKILL.md names no scripts, command-line tools or credentials: Obsidian Security Basics is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Obsidian Security Basics access the network?

SKILL.md names 3 domains. As links in the text: docs.obsidian.md, electronjs.org and cheatsheetseries.owasp.org. This is read from the text; nothing was executed.

Is Obsidian Security Basics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Obsidian Security Basics use?

Obsidian Security Basics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Obsidian Security Basics use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Obsidian Security Basics?

Skills that share tags, products or a category with Obsidian Security Basics: Expert Security (ReJeCtAll/ExpertTeam-Codex, 113 stars), Security and Hardening (addyosmani/agent-skills, 105k stars), Performing Ssl Tls Inspection Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Google Cloud Waf Security (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Obsidian Security Basics?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.