Back to skill

Security audit

Obsidian Core Notes

Security checks for vulnerabilities and agentic risk

Overview

This Obsidian organization skill is mostly purpose-aligned, but it can persist raw file previews into generated notes and delete marked Markdown files across a vault without strong safeguards.

Install only if you are comfortable letting it scan the selected vault/workspace and create persistent generated Markdown notes. Run `scan` and `refresh --dry-run` first, avoid roots containing secrets or credentials, review generated previews before syncing or committing them, and use `clean-generated --dry-run` before any deletion because the delete command is marker-based and permanent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/obsidian_core_notes.py:365
Finding

Unredacted Sensitive File Content Is Copied into Generated Markdown Notes

Content
View full analysis
tuple[list[str], list[str], str, str]: data, truncated = read_limited_bytes(path, limit) text, encoding, error = decode_text(data) lines = text.splitlines() nonempty = [line.strip()[:180] for line in lines if line.strip()][:8] summary = [f"{label} sample: {len(lines)} lines, {len(text)} chars."] if nonempty: summary.append("Opening: " + nonempty[0]) key_terms = keywords(text) if key_terms: summary.append("Keywords: " + ", ".join(key_terms)) notes = [f"encoding={encoding}"] if truncated: notes.append("sampled beginning only") if error: notes.append("decode fallback used") return summary, notes, text[:MAX_PREVIEW_CHARS], "text" ``` ```python def summarize_json(path: Path) -> tuple[list[str], list[str], str, str]: data, truncated = read_limited_bytes(path, MAX_JSON_BYTES) text, encoding, error = decode_text(data) notes = [f"encoding={encoding}"] summary: list[str] = [] preview = text[:MAX_PREVIEW_CHARS] try: parsed = json.loads(text) if isinstance(parsed, dict): keys = list(parsed.keys()) summary.append(f"JSON object with {len(keys)} top-level keys.") if keys: summary.append("Top keys: " + ", ".join(map(str, keys[:15]))) elif isinstance(parsed, list): summary.append(f"JSON array with {len(parsed)} items.") else: summary.append(f"JSON scalar: {type(parsed).__name__}") preview = json.dumps(parsed, ensure_ascii=False, indent=2)[:MAX_PREVIEW_CHARS] except Exception as error_json: summary.append(f"JSON parse ...[truncated 3340 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The clean-generated command recursively deletes every Markdown file under the target root containing one of the marker strings, with no confirmation prompt or allowlist beyond content matching. If run against the wrong workspace or if a legitimate user-authored note contains the marker text, the script can irreversibly remove large numbers of files, causing destructive data loss.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is broad enough to trigger on many normal file-management and writing tasks across an Obsidian vault or general workspace. That can cause the agent to invoke this skill in situations beyond the user's intent, leading to unnecessary scans, bulk edits, or organizational changes across many files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill prescribes Chinese-language filenames such as 专题综合.core.md, 资料索引.md, and 核心文件索引.md without indicating that naming is configurable or dependent on user locale. In non-Chinese workspaces this can create unexpected files, break naming conventions, reduce discoverability, and cause accidental duplication alongside existing English-language indexes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default prompt tells the agent to "scan this vault" and broadly "update core notes and indexes" without defining boundaries, approval requirements, or limiting scope to specific files or paths. In a workspace containing sensitive or unrelated files, this can trigger unnecessary mass read/write behavior and cause unintended modification, disclosure, or reorganization of user content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file instructs the user to create or rewrite 专题综合.core.md, and later provides a required structure using Chinese headings. That imposes a specific language/locale convention without opt-in or an explicit region-specific justification, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Core generated filenames and labels such as 资料索引.md, 核心文件索引.md, and 工作区 are fixed in Chinese. This imposes a specific language/locale on generated artifacts without opt-in or explanation, which matches the language/locale policy concern for natural-language behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The refresh command writes sidecar notes, folder indexes, and a root index across the workspace via write_core_note, write_folder_indexes, and write_root_index. Although the command name implies generation, there is no confirmation prompt or explicit user-facing warning at the point of execution that running this command will create or overwrite Markdown files throughout the target tree.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.