Back to skill

Security audit

obsidian-consulting-notes

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Obsidian note-organizing skill that can alter notes, but its file changes are disclosed, purpose-aligned, and gated by user confirmation.

Install only if you want an agent to reorganize an Obsidian consulting vault. Back up the vault first, confirm the target folder, review the previewed file changes, and approve only batches whose paths, tags, and rename or move actions match your intended structure.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to write, modify, rename, and relocate user notes, including bulk processing and duplicate marking, but it does not require a prominent upfront warning about the risk of altering an existing Obsidian vault. Even though later text suggests showing an operation list and waiting for confirmation, the lack of an early, explicit safety gate increases the chance of unintended destructive or hard-to-reverse changes during note reorganization.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal