Obsidian Notes

Security checks across malware telemetry and agentic risk

Overview

This Obsidian helper is a documentation-only skill for finding and editing local notes, with a disclosed delete command that users should handle carefully.

Install this only if you trust the obsidian-cli Homebrew tap and want an agent to access your local Obsidian vault. Before allowing deletes or moves, verify the active vault and exact note path, and prefer backups or non-destructive archive moves for important notes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents `obsidian-cli delete "path/note"` without any warning, confirmation guidance, or recommendation to verify the target vault/path first. In a note-management skill that operates on real user files, normalizing destructive deletion as a standard action increases the chance of accidental or unsafe data loss, especially when multiple vaults or ambiguous note names exist.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal