Back to skill

Security audit

Obsidian Semantic Search

Security checks for vulnerabilities and agentic risk

Overview

The skill’s local Obsidian search purpose is coherent, but its install guidance asks users to run unverified remote shell scripts and bypass a security warning.

Review the upstream repository and installer before running anything, prefer a pinned release or commit with checksum/signature verification, and do not rely on the `--force` guidance as proof of safety. Only point it at vaults you are comfortable indexing locally, and keep backups or version control before enabling AI-assisted write tools such as overwrite.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:55
Finding

Unverified Remote uv Installer Executed Directly by a Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 55
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
curl -LsSf https://astral.sh/uv/install.sh | sh

Technical Analysis

The installation instruction pipes network-delivered content directly into sh. The effective code is not included in the reviewed Skill and is not pinned to an immutable version. No checksum or cryptographic signature is verified before execution.

Although astral.sh is presented as the uv package manager's source, the command establishes a mutable remote-code execution channel. A compromise of the hosting infrastructure, DNS or TLS trust chain, or upstream installer could cause different commands to execute after the Skill has been reviewed. The use of HTTPS reduces interception risk but does not provide payload immutability or protect against an upstream compromise.

Remote shell execution is not the minimum capability necessary to install a package manager. A versioned artifact can instead be downloaded and authenticated before installation.

Attack Path

  1. An attacker compromises the remote installer, its hosting account or infrastructure, or another trusted delivery component.
  2. The attacker modifies install.sh to include malicious shell commands.
  3. A user follows the prerequisite instruction in SKILL.md.
  4. curl retrieves the current attacker-controlled response.
  5. The pipe passes the response directly to sh without inspection or integrity verification.
  6. The malicious commands execute with all permissions available to the invoking user.

Impact Assessment

Successful exploitation provides arbitrary command execution in the user's security context. The payload could read or modify user files, access credentials available to the process, alter shell configuration, install additional software, or establish persistence. If a user executes the i ...[truncated 154 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the pipe-to-shell instruction with installation from a specific, immutable uv release.
  • Download the release artifact as a separate step and verify a publisher-provided cryptographic signature or trusted SHA-256 checksum before execution.
  • Pin the expected version and digest in SKILL.md.
  • Prefer an authenticated operating-system package manager where supported.
  • If a script remains necessary, save it locally, verify its integrity, and instruct the user to inspect it before running it.
  • Document the files and configuration that the installer is expected to modify.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Mutable GitHub Installer Downloaded and Executed with Vault Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 61
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

bash
bash <(curl -fsSL https://raw.githubusercontent.com/celstnblacc/obsidian-semantic-mcp/main/install.sh) --mode 2 --vault /path/to/your/vault

Technical Analysis

This command retrieves a shell script from the mutable main branch of a repository under a personal GitHub account and executes it immediately through Bash process substitution. The package contains only SKILL.md; consequently, the installer implementation and its effective behavior are outside the audited artifact.

The URL is not pinned to a commit hash or signed release, and the command performs no checksum or signature validation. Repository updates or account compromise can therefore change the payload without changing the reviewed Skill. Process substitution also prevents the ordinary workflow of saving and reviewing the script before execution.

According to the documentation, the installer clones a repository into the user's home directory, installs an osm CLI, runs a Docker setup wizard, modifies MCP client configuration, and receives the path to an Obsidian vault. These capabilities provide a compromised installer with access to sensitive local notes and substantial ability to modify the user's environment. While vault access and Docker setup support the advertised functionality, executing an unauthenticated mutable installer is not necessary to provide those features.

Attack Path

  1. An attacker compromises the GitHub account, repository, main branch, or a trusted delivery component.
  2. The attacker changes install.sh to perform malicious actions while optionally preserving the expected installation behavior.
  3. A user copies the documented one-line installation command.
  4. curl retrieves the current script from the mutable branch.
  5. Bash executes the retr ...[truncated 998 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not execute installer content directly from a mutable branch.
  • Vendor the reviewed installer into the Skill package, or reference an immutable release artifact tied to a specific commit.
  • Publish and verify a cryptographic signature or trusted checksum before execution.
  • Separate download, verification, inspection, and execution into distinct commands.
  • Avoid Bash process substitution for installation.
  • Clearly enumerate every expected filesystem, Docker, vault, and client-configuration change.
  • Request the vault path only after installer integrity has been established.
  • Apply least privilege: avoid unnecessary Docker socket exposure, mount the vault only where needed, and use read-only vault access unless file-modification tools are explicitly enabled by the user.

other

Warning
Location
SKILL.md:174
Finding

Documentation Encourages Users to Override a Security Warning

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 174
Vulnerability Type: Security control bypass guidance
Risk Level: Medium

Vulnerable Code:

text
| VirusTotal "suspicious" warning on install | This is a false positive — the skill *describes* searching vault content, which triggers pattern detection. Use `clawhub install obsidian-semantic-search --force` to proceed. The skill is MIT-0 licensed and contains no executable code beyond documentation. |

Technical Analysis

The troubleshooting guidance categorically labels a security warning as a false positive and instructs the user to bypass the installation gate with --force. This assurance is not adequately supported by the audited artifact. Although the Skill package contains only documentation, that documentation directs users to execute two mutable remote shell scripts. The absence of bundled executable code therefore does not eliminate execution or supply-chain risk.

Security warnings should be investigated rather than broadly disabled. The statement may reduce informed user consent by implying that documentation-only packaging is inherently safe, even though instructions can initiate external code execution.

Attack Path

  1. The platform or security scanner raises a suspicious-installation warning.
  2. The user consults the Skill's troubleshooting section.
  3. The documentation assures the user that the warning is a false positive and recommends --force.
  4. The user bypasses the platform's protective installation gate.
  5. The user subsequently reaches and follows the remote installer instructions.
  6. If either mutable remote source has been compromised, attacker-controlled code executes with the user's permissions.

Impact Assessment

This instruction does not independently grant privileges, but it weakens a protective control and increases the probability that users will install the Skill and execute its unverified remote ...[truncated 208 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the blanket claim that the warning is a false positive.
  • Do not direct users to use --force as the default resolution.
  • Explain the specific detected behaviors, including both remote shell-execution commands.
  • Require users to verify immutable versions, checksums, signatures, and source provenance before overriding any warning.
  • Eliminate the remote pipe-to-shell patterns so the underlying warning can be resolved rather than bypassed.
  • If an override remains necessary, provide a narrowly scoped, evidence-based review procedure and clearly disclose residual risks.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description emphasizes semantic search features but does not clearly warn that the vault contents will be indexed into a local database and monitored for file changes by a watcher. This matters because users may not realize that potentially sensitive notes are being continuously processed, stored in derived form, and observed for updates.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises append and overwrite file operations on an Obsidian vault without a prominent warning that using these tools can modify or destroy local note contents. In an AI-assisted context, write capabilities materially increase the risk of accidental data corruption, unintended edits, or destructive actions from ambiguous prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The one-liner installation flow executes a remote script directly from the network using process substitution and bash, without an explicit safety warning or integrity verification guidance. This is dangerous because any compromise of the remote source, DNS, TLS trust chain, or upstream account could lead to arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The troubleshooting text explicitly tells users to disregard a security warning and falsely states the skill contains no executable code, even though the document instructs users to run shell commands, install packages, clone a repo, and execute an external installer. This is dangerous because it conditions users to override security controls and trust misleading safety claims around code execution.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The prerequisite command pipes a remotely fetched installer script directly into sh, which is a classic arbitrary code execution pattern. Even though this is common for developer tooling, it remains risky because users are instructed to trust and execute unaudited network content immediately.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
### Prerequisites

- **Docker Desktop** (running)
- **uv** (Python package manager): `curl -LsSf https://astral.sh/uv/install.sh | sh`
- **An Obsidian vault** on your local filesystem

### One-Liner Install

Static analysis

No suspicious patterns detected.