Back to skill

Security audit

Obsidian via notesmd-cli (obsidian-cli)

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Obsidian note-management skill, with disclosed commands that can modify or delete notes and an unpinned third-party CLI dependency.

Install only if you are comfortable using the third-party notesmd-cli tool with access to your Obsidian vault. Verify the target vault and note paths before running move, frontmatter delete, or note delete commands, and keep backups or Obsidian sync/history enabled for important notes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party Homebrew Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Mutable third-party dependency
Risk Level: Medium

Vulnerable Code Snippet

yaml
metadata: {"clawdbot":{"emoji":"💎","requires":{"bins":["notesmd-cli"]},"install":[{"id":"brew","kind":"brew","formula":"yakitrak/yakitrak/notesmd-cli","bins":["notesmd-cli"],"label":"Install notesmd-cli (brew)"}]}}

Technical Analysis

The Skill directs users or the Agent environment to install notesmd-cli from the third-party Homebrew tap yakitrak/yakitrak. The dependency is not pinned to a reviewed version, immutable commit, or verified artifact checksum. Consequently, the code retrieved during installation can change after the Skill has been audited.

This creates a supply-chain trust boundary: compromise of the tap, its maintainer account, the referenced source archive, or the dependency's release infrastructure could replace the expected package with malicious code. Homebrew formula logic can execute during package resolution, build, or installation, while the resulting CLI executes whenever the Skill performs an Obsidian operation.

No evidence shows that the current dependency is malicious. The vulnerability is the use of a mutable, unverified third-party installation source.

Attack Path

  1. An attacker compromises the third-party Homebrew tap, its maintainer credentials, or an artifact location referenced by its formula.
  2. The attacker modifies the formula or replaces a referenced release artifact with a malicious version.
  3. A user or Agent installs the declared dependency using the Skill metadata.
  4. Homebrew resolves the mutable dependency and downloads the attacker-controlled formula or artifact.
  5. Malicious logic executes during installation or when notesmd-cli is subsequently invoked.
  6. The payload acts with the privileges of the installing or invoking user.

Impact Assessment

Successful exploitation could ...[truncated 564 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin notesmd-cli to a reviewed release or immutable source commit rather than relying on the mutable latest formula.
  2. Verify downloaded artifacts with a cryptographic checksum maintained in a trusted configuration.
  3. Prefer an official, authenticated distribution channel if one is available.
  4. Document explicitly that notesmd-cli and its Homebrew tap are third-party components.
  5. Review the Homebrew formula, its transitive dependencies, and its artifact URLs before approving updates.
  6. Use automated dependency monitoring and require manual security review when the pinned version or checksum changes.
  7. Run installation and CLI operations without administrative privileges and restrict the runtime account to only the vaults and files required for the task.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown explicitly instructs users to run notesmd-cli delete "path/note", which is a destructive operation affecting user data. Nearby sections do not provide any warning about permanence, caution about targeting the correct vault/note, or advice to confirm before deletion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.