2026-04-17 05:20 UTC
@secupriv
Interesting, I had a conversation just yesterday about how to sensibly scan the plugins in an #Obsidian vault.
Even the official ones come without a package.json (which could be tampered anyway). Are we back to scanning every file on opening, or is there something more efficient for plain javascript snippets?
Replies (1)
-
@secupriv@mastodon.nl 2026-04-17 12:08
@schmidt_fu I expect the plugins to exactly do what they are made for. If you don’t think from a risk perspective it can probably do really wonderful things 😇 The question remains whether you should even want this kind of plugin in an app like Obsidian in the first place.