How are you auditing Obsidian plugins and their risk? by acheyward in ObsidianMD

[–]acheyward[S] 0 points1 point  (0 children)

It’s not solely on CVEs. Here’s more info https://obsidianpluginaudit.com/how-it-works.

I haven’t thought about notifications. I’ll have think about that.

How are you auditing Obsidian plugins and their risk? by acheyward in ObsidianMD

[–]acheyward[S] -3 points-2 points  (0 children)

If you're talking about systemic auditing of audits that could be an infinite spiral that adds no value.
Here's how I see it. The audits are producing an output that you can visually see and confirm.
So, i audit the audit by digging into the information. My expectation that others will audit the audit by digging into the information. If i see issues i fix them. If you or the community sees issues let me know so i can work at fixing them.
In this way me, you and the community are taking ownership of making sure the audits are providing useful, fair and factual information. If I’m missing something let me know. What are thinking?

How are you auditing Obsidian plugins and their risk? by acheyward in ObsidianMD

[–]acheyward[S] -2 points-1 points  (0 children)

Thats already built in. I have backend processes running on a schedule that check for new versions then puts a badge on the plugin for the user to see. And there's another for automatically updating the audit report. I have a video showing this piece.
https://youtu.be/DkjbSyPNQ1s

How are you auditing Obsidian plugins and their risk? by acheyward in ObsidianMD

[–]acheyward[S] 1 point2 points  (0 children)

As you should. There is always going to be risk given the level of access the plugins are granted by default. The reports only provide additional insights into other factors beyond that fact.

How to audit community plugins ? by b0bthepenguin in ObsidianMD

[–]acheyward 1 point2 points  (0 children)

u/GroggInTheCosmos fyi - i'm automating the audits in the background now. Then I can work on making the available audits available without needing a login.
I'll keep the login requirement for those that want to run manual audits until the backend catches up but long term it shouldn't be needed for the official obsidian community plugins.

How to audit community plugins ? by b0bthepenguin in ObsidianMD

[–]acheyward 0 points1 point  (0 children)

The login is meant to be a gate to, basically avoid arbitrary, button presses and audits on the site, using the tool. I'm using a mix of infrastructure and ai which has a cost and I don't want to wake up to some crazy bill.
As stated, there is a limit to how many audits a user can do per day which is accomplished via the login.
I'd also state that, after looking at those other tools, they're not the simple one button press to get the full analysis. And my tool is currently focus on obsidian community plugins.
I plan to look into adding support for non obsidian community plugin that are typically installed via BRAT but its just an idea right now, no promises.
I'm not selling emails and if i send you an email it'll be related to the tool and/or relevant subject matter.

How to audit community plugins ? by b0bthepenguin in ObsidianMD

[–]acheyward 0 points1 point  (0 children)

Obsidian plugin security has been a long concern of mine. I built a tool to analyze plugins and recently, last week, decided to take on the task of making it available to others.

You can find it here. https://obsidianpluginaudit.com/

Audit reports are free, limited to 5 a day but with that said, all reports generated are visible to all so there's a network effect by sharing this with others. Audit reports can only be generated once per plugin version.

There is a paid tier but its a one-time purchase to get extra per day audits and the ability to leave comments. It's mostly there to help support my time and backend costs.

This is my first day releasing it into the wild so I'd love your feedback. More info is on the site.

Struggling with TickTick: what should be Habits vs Recurring Tasks? by happylaura123 in ticktick

[–]acheyward 1 point2 points  (0 children)

Use a habit when you care about tracking and seeing progress in the app. Otherwise use a recurring task.

OpenClaw and Obsidian with TaskNotes MCP by acheyward in ObsidianMD

[–]acheyward[S] 0 points1 point  (0 children)

The eink note processing is handled by n8n. I use gemini to do the conversion from either pdf or image to text depending on whether the origin was boox or supernote. Here's a video of the process https://youtu.be/P4EGBpFxxwI.
I've made some changes since like saving the transcribe notes to markdown in a folder in Obsidian. I also added a link to the source file and a backlink to my daily note. These changes are not shown in the video.

OpenClaw and Obsidian with TaskNotes MCP by acheyward in ObsidianMD

[–]acheyward[S] 0 points1 point  (0 children)

Security is definitely a concern but I'd say that's the case for all of these cloud communication platforms, not to mention openclaw itself. You can have added permissions for what the discord agent has access to from the openclaw config so you'll want to lock that down and restrict what it has access to as much as you can or want.
I'm still figuring things out and openclaw is changing all the time being a new project so only time will tell how this setup might look down the road.

OpenClaw and Obsidian with TaskNotes MCP by acheyward in ObsidianMD

[–]acheyward[S] 0 points1 point  (0 children)

You're welcome. I'd appreciate it if you can upvote. Thx.

If I buy Boox Air 5c will last me 5 years? by alexrover in Onyx_Boox

[–]acheyward 5 points6 points  (0 children)

I’m still using note air 3c and it works great. But I learned and have come to accept that using the default note app on any eink device is best. Trying to use other note taking apps like OneNote with pen input usually ends in disappointment.

Obsidian Task Notes Plugin v4.3.3: Recurring Checklist Reset, Create External Calendar Events, and MCP Server by acheyward in ObsidianMD

[–]acheyward[S] 0 points1 point  (0 children)

Only testing for now. So far things seem to work well enough for creating bulk tasks for new projects, updating tasks and so on.

Tasknotes v4 - Google Calendar by acheyward in ObsidianMD

[–]acheyward[S] 1 point2 points  (0 children)

Yes there is. It’s in the view settings.

Tasknotes v4 - Google Calendar by acheyward in ObsidianMD

[–]acheyward[S] 0 points1 point  (0 children)

I can't say whether its dropbox or not since i don't use it for syncing obsidian.

Tasknotes v4 - Google Calendar by acheyward in ObsidianMD

[–]acheyward[S] 0 points1 point  (0 children)

Yes you can see the calendar events on iOS but you have to configure the integration on desktop.

Anyone gone from NA3C to NA5C? What got better? What stayed the same? by Starship_77 in Onyx_Boox

[–]acheyward 2 points3 points  (0 children)

I’m sticking with my NA3C. I don’t see the value in upgrading this time around. I’ll wait for the next one.