Back to skill

Security audit

Obsidian Sync

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its sync server has a real file-containment flaw and optional boot persistence that users should review before installing.

Review before installing. Use only with trusted clients and a strong token, keep the bind address on localhost unless you understand the exposure, avoid syncing directories containing symlinks, keep backups of notes, and prefer running the service under a dedicated low-privilege account. Do not enable the systemd linger service unless you want the sync server to keep running after logout and at boot.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/sync-server.mjs:47
Finding

Symlink-Based Workspace Escape Permits Access Outside Allowed Directories

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sync-server.mjs:223
Finding

Unbounded Request Buffering and File Writes Enable Resource Exhaustion

Content
View full analysis
Remediation
View remediation
MAX_BODY_BYTES) { req.destroy(); throw new Error('Request body too large'); } chunks.push(chunk); } const body = Buffer.concat(chunks).toString('utf8'); ``` 4. Return HTTP status `413 Payload Too Large` when the limit is exceeded. 5. Apply request timeouts and rate limits to authenticated clients. 6. Enforce per-file and total workspace quotas. 7. Prefer streaming content to a restricted temporary file, followed by validation and atomic rename, instead of retaining the complete payload in memory. 8. Calculate hashes incrementally while streaming rather than reading the complete file again. 9. Handle aborted connections and remove incomplete temporary files. 10. Consider host-level memory, process, and filesystem quotas as defense-in-depth controls. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
SYNC_TOKEN="your-gateway-token" node scripts/sync-server.mjs

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill exposes capabilities that rely on environment variables and network access, but it does not declare any tool scope or permissions boundaries. That makes the operational trust assumptions implicit, increases the chance of over-broad execution in agent frameworks, and can mislead users about what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes two-way synchronization and write operations against workspace files, but it does not prominently warn users that enabling the service can modify or overwrite notes and agent workspace data. In this context, the server is specifically designed to read and write files, so missing risk disclosure can lead to unintended data loss, corruption, or unsafe deployment assumptions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

User systemd service

bash
mkdir -p ~/.config/systemd/user

cat > ~/.config/systemd/user/openclaw-sync.service << 'EOF'
[Unit]

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

EOF

systemctl --user daemon-reload systemctl --user enable --now openclaw-sync loginctl enable-linger $USER # Start on boot

text

Static analysis

No suspicious patterns detected.