Back to skill

Security audit

Obsidian Canvas Creator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a prompt-only Obsidian Canvas generator with no hidden code, credential handling, or destructive behavior.

Install this only if you want Claude Code to generate Obsidian Canvas JSON. Be aware that broad visualization requests may activate it, so ask explicitly for Obsidian Canvas or .canvas output when you want this skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Excalidraw trigger list includes broad terms such as "diagram," "flowchart," and "mind map," which are common user requests not uniquely tied to this skill. In an agent environment that auto-selects skills based on trigger words, this can cause unintended activation, misrouting user intent, and unnecessary access to the skill's transformation logic even when a more appropriate skill should handle the request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Mermaid trigger list uses vague activators like "visualize" and "flowchart," which are highly generic and likely to appear in many unrelated requests. This increases the chance of accidental skill invocation, creating prompt-routing ambiguity and allowing the skill to intercept requests outside its intended scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Canvas trigger words include generic phrases like "mind map" and "visual diagram," which overlap with normal requests that could apply to multiple visualization skills. In a multi-skill system, this broad matching can unintentionally activate the Obsidian Canvas creator, leading to incorrect outputs, reduced predictability, and potential chaining into file-creation behavior the user did not explicitly request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Excalidraw trigger phrases include very generic terms such as '画图', '流程图', and '思维导图', which can match many ordinary user requests outside the narrow intended scope of this specific skill. Overbroad activation increases the chance that the skill is invoked unexpectedly, causing prompt-scope confusion, unnecessary file generation, or unintended takeover of requests that should be handled by a different tool or safer default behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Mermaid trigger list uses broad activators like '可视化' and '流程图', which are common in many unrelated requests and do not clearly constrain activation to Mermaid-specific output. In an agentic environment, this can cause unintended skill routing and prompt injection surface expansion by making the skill eligible for too many contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Canvas trigger phrases include ambiguous terms like '思维导图' and '可视化图表', which overlap with normal brainstorming and note-organization requests and may collide with other visualization skills in the same package. Because this skill produces structured files, accidental activation can lead to unexpected workspace modifications or incorrect output formats being generated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is broad enough to match generic requests for visualization or spatial organization, which can cause the agent to invoke this skill when a more appropriate tool or a plain-text response would be safer and more accurate. Over-broad routing increases the chance of unintended file generation, user confusion, and misuse of downstream references or formatting rules outside the intended Obsidian Canvas context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The section titled 'Character Encoding for Chinese Content' instructs users to transform Chinese quotation marks and content formatting in a language-specific way. This is a natural-language locale policy issue because it singles out one language and prescribes special behavior without offering choice or documenting a clear region-specific requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The invocation guidance lists positive triggers but does not define boundaries or counterexamples, so the agent may select the skill for loosely related requests like general note organization or visualization. This ambiguity is dangerous because it can produce the wrong output format, unnecessary file creation, or mishandling of requests that should instead be answered conversationally or routed to another skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.