Back to skill

Security audit

Obsidian Vault Writer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a straightforward Obsidian note writer, but it needs review because it uses unsafe command templates for note content and relies on an unpinned third-party CLI install.

Install only if you trust the notesmd-cli source and are comfortable with an agent modifying your Obsidian vault. Prefer a pinned, verified CLI version installed in a user-owned path, keep vault backups or version control, and ensure the agent invokes notesmd-cli without shell string interpolation for user-supplied content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:56
Finding

Shell Command Injection Through Unescaped Dynamic Arguments

Content
View full analysis
" ``` ```bash notesmd-cli daily --content "" --vault "{vault-name}" ``` ```bash # Create a new note (leaves existing notes unchanged if no flag) notesmd-cli create "{note-path}" --content "..." --vault "{vault-name}" # Append to an existing note notesmd-cli create "{note-path}" --content "..." --append --vault "{vault-name}" # Overwrite an existing note (only with explicit user consent) notesmd-cli create "{note-path}" --content "..." --overwrite --vault "{vault-name}" ``` The vault-registration workflow uses the same unsafe command-template pattern: ```bash notesmd-cli add-vault /path/to/vault --set-default ``` ### Technical Analysis The Skill instructs an agent to interpolate dynamic note content, note paths, vault names, and vault paths directly into shell command strings. Surrounding values with double quotes does not make arbitrary input safe for shell interpretation. If a substituted value contains a double quote, it can terminate the quoted argument. Shell metacharacters can then introduce additional commands. Command substitutions such as `$(command)` and backtick expressions may also be evaluated inside double-quoted shell arguments. For example, if note content is inserted without shell-safe argument handling, a value conceptually shaped like the following can escape the intended argument: ```text "; attacker-command; # ``` This risk applies especially to content received from users, external documents, or the output of another skill. The Skill does not require use of an argument-array API, define an escaping procedure, reject shell metacharacters, or provide a standard-input/file-based mechanism for arbitrary content. ### Attack Path 1. ...[truncated 1401 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/notesmd-cli.md:9
Finding

Unpinned Third-Party Dependency Installation and Privileged System-Wide Deployment

Content
View full analysis
Remediation
View remediation
``` Verify the checked-out commit and source integrity before building. 5. Pin the Homebrew formula to a known release where supported, and document the expected formula and artifact hashes. 6. Avoid `sudo` and system-wide installation when unnecessary. Install the reviewed binary in a user-owned directory with restricted permissions. 7. Record the expected `notesmd-cli` version and verify it with `notesmd-cli --version` before use. 8. Add a dependency-update process requiring review of upstream changes, refreshed hashes, and security testing before changing the pinned version. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly promotes writing and appending content to an Obsidian vault but does not warn users that the skill can modify existing files, append unintended content, or overwrite note data depending on how it is invoked. In an agent setting, missing safety guidance increases the chance of unintended file modification or destructive writes, especially on remote servers and headless environments where changes may be less visible.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/notesmd-cli.md (reported line 22)May include surrounding context.

git clone https://github.com/yakitrak/notesmd-cli.git cd notesmd-cli go build -o notesmd-cli . sudo install -m 755 notesmd-cli /usr/local/bin/

text

**Verify:**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes a delete command that can remove notes from an Obsidian vault, which affects user data. While the command is listed, the documentation does not include any warning about permanence, recovery, or the need for caution before deletion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.