Obsidian Deploy IntegrationSAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: obsidian-deploy-integration description: 'Publish Obsidian plugins to the community plugin directory. Use when releasing your first plugin, updating existing plugins, or managing the community plugin submission process. Trigger with phrases like "publish obsidian plugin", "obsidian community plugins", "submit obsidian plugin", "obsidian plugin directory". ' allowed-tools: Read, Write, Edit, Bash(git:*), Bash(gh:*) version: 1.13.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - obsidian - obsidian-deploy compatibility: Designed for Claude Code --- # Obsidian Plugin Deploy Integration ## Overview Release and distribute Obsidian plugins through multiple channels: the official community plugin directory, GitHub releases, BRAT beta testing, and manual installation. Covers the full lifecycle from building release assets to submitting your PR to the `obsidian-releases` repo. ## Prerequisites - Obsidian plugin with `main.ts`, `manifest.json`, and `styles.css` (if applicable) - GitHub repository for your plugin (public) - `gh` CLI authenticated (`gh auth status`) - Plugin passes `obsidian-prod-checklist` validation ## Instructions ### Step 1: Build Release Assets ```bash set -euo pipefail # Clean build for production rm -f main.js npm ci npm run build # Verify the three release files exist for f in main.js manifest.json; do test -f "$f" || { echo "MISSING: $f"; exit 1; } done test -f styles.css && echo "styles.css included" || echo "No styles.css (OK if no custom styles)" echo "Release assets ready" ``` ### Step 2: Version Bump with version-bump.mjs ```javascript // version-bump.mjs import { readFileSync, writeFileSync } from 'fs'; const targetVersion = process.env.npm_package_version; // Sync manifest.json const manifest = JSON.parse(readFileSync('manifest.json', 'utf8')); const { minAppVersion } = manifest; manifest.version = targetVersion; writeFileSync('manifest.json', JSON.stringify(manifest, null, '\t')); // Sync versions.json — maps each plugin version to its minimum Obsidian version const versions = JSON.parse(readFileSync('versions.json', 'utf8')); versions[targetVersion] = minAppVersion; writeFileSync('versions.json', JSON.stringify(versions, null, '\t')); console.log(`Bumped to ${targetVersion} (requires Obsidian >= ${minAppVersion})`); ``` Wire it into package.json so `npm version` triggers it automatically: ```json { "scripts": { "version": "node version-bump.mjs && git add manifest.json versions.json" } } ``` ### Step 3: Create GitHub Release ```bash set -euo pipefail # Bump version, commit, and tag npm version patch # or minor / major git push origin main --tags # Create release with assets (or let the release workflow from obsidian-ci-integration handle it) gh release create "$(node -p 'require("./manifest.json").version')" \ main.js manifest.json styles.css \ --title "v$(node -p 'require("./manifest.json").version')" \ --generate-notes ``` The release must include these files at the root level (not nested in folders): - `main.js` — compiled plugin code - `manifest.json` — plugin metadata - `styles.css` — only if your plugin has custom styles ### Step 4: Submit to Community Plugins First-time submission requires a PR to the [obsidian-releases](https://github.com/obsidianmd/obsidian-releases) repo: ```bash set -euo pipefail # Fork and clone the releases repo gh repo fork obsidianmd/obsidian-releases --clone cd obsidian-releases # Add your plugin entry to community-plugins.json node -e " const fs = require('fs'); const plugins = JSON.parse(fs.readFileSync('community-plugins.json', 'utf8')); const entry = { id: 'your-plugin-id', name: 'Your Plugin Name', author: 'Your Name', description: 'Brief description of what your plugin does.', repo: 'your-github-username/your-plugin-repo' }; // Insert alphabetically by id const idx = plugins.findIndex(p => p.id.localeCompare(entry.id) > 0); plugins.splice(idx >= 0 ? idx : plugins.length, 0, entry); fs.writeFileSync('community-plugins.json', JSON.stringify(plugins, null, '\t') + '\n'); console.log('Added', entry.id, 'at index', idx >= 0 ? idx : plugins.length); " git checkout -b add-your-plugin-id git add community-plugins.json git commit -m "Add your-plugin-id" git push origin add-your-plugin-id gh pr create --repo obsidianmd/obsidian-releases \ --title "Add your-plugin-id" \ --body "## Plugin submission - **Repo:** https://github.com/your-username/your-plugin-repo - **Description:** Brief description - **I have tested on:** Desktop (macOS/Windows/Linux), Mobile (iOS/Android)" ``` Review requirements the Obsidian team checks: - `manifest.json` has all required fields (`id`, `name`, `version`, `minAppVersion`, `description`, `author`) - `id` in manifest matches the `id` in your community-plugins.json entry - No `console.log` in production code - No `eval()` or dynamic code execution - No remote code loading at runtime - Plugin works on mobile if `isDesktopOnly` is not set ### Step 5: BRAT for Beta Testing Before submitting to community plugins, test your distribution via [BRAT](https://github.com/TfTHacker/obsidian42-brat): 1. Users install BRAT from community plugins 2. In BRAT settings, they click "Add Beta Plugin" 3. They enter your GitHub repo URL: `your-username/your-plugin-repo` 4. BRAT installs the latest release (including pre-releases) To push a beta: ```bash set -euo pipefail npm version prerelease --preid=beta git push origin main --tags gh release create "$(node -p 'require("./manifest.json").version')" \ main.js manifest.json styles.css \ --title "Beta: v$(node -p 'require("./manifest.json").version')" \ --prerelease ``` ### Step 6: Manual Installation For users who prefer manual install or for testing outside BRAT: ```bash set -euo pipefail # Users copy files to their vault's plugin directory VAULT_PATH="/path/to/vault" PLUGIN_ID="your-plugin-id" DEST="$VAULT_PATH/.obsid
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__obsidian-deploy-integration.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Obsidian Deploy Integration skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Obsidian Deploy Integration safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Obsidian Deploy Integration access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Obsidian Deploy Integration work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.