Back to skill

Security audit

Obsidian

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Obsidian note-management skill, with normal but real caution needed around the third-party CLI install and destructive delete command.

Install only if you trust the yakitrak/yakitrak Homebrew tap or have reviewed the obsidian-cli source you will install. Before running delete or move operations, confirm the active vault and exact note path, and keep backups for important vaults.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party Homebrew Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Supply-chain exposure through an unpinned third-party Homebrew tap
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"clawdbot":{"emoji":"💎","requires":{"bins":["obsidian-cli"]},"install":[{"id":"brew","kind":"brew","formula":"yakitrak/yakitrak/obsidian-cli","bins":["obsidian-cli"],"label":"Install obsidian-cli (brew)"}]}}

Technical Analysis

The skill directs the environment to install obsidian-cli from the third-party Homebrew tap yakitrak/yakitrak without pinning the dependency to a reviewed version, formula revision, commit, or artifact checksum. Consequently, the code installed at a later date can differ from the code that existed when this skill was audited.

Homebrew formulas can download and install external artifacts and execute formula-defined build or installation operations. If the tap repository, its maintainer account, its release infrastructure, or an upstream artifact is compromised, an attacker could replace a future version or modify the formula. A subsequent installation initiated through this skill would then trust and execute the modified supply-chain content.

The available files contain no evidence that this tap or package is currently malicious. The security issue is the lack of reproducibility and integrity controls around an externally mutable installation source.

Attack Path

  1. An attacker compromises the third-party tap repository, a maintainer account, the upstream release process, or an artifact hosting location used by the formula.
  2. The attacker publishes a modified formula or replaces an artifact referenced by a formula version that is not protected by an effective integrity check.
  3. A user loads the skill on a system where obsidian-cli is absent and follows or authorizes the declared Homebrew installation action.
  4. Homebrew retrieves the then-current formula and associated ...[truncated 1002 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically reviewed release and, where supported, a fixed tap commit or immutable artifact.
  2. Verify downloaded artifacts with a cryptographic checksum sourced from a trusted and independently authenticated channel.
  3. Prefer an official package source maintained by the upstream project over a third-party tap when one is available.
  4. Document the exact expected obsidian-cli version and validate it after installation before allowing the agent to invoke it.
  5. Review the Homebrew formula, upstream source, release provenance, and transitive dependencies before approving installation.
  6. Use signed releases or provenance attestations where the upstream project provides them.
  7. Perform installation and execution as an unprivileged user in a restricted environment, granting access only to the intended Obsidian vault.
  8. Avoid automatic dependency installation. Require explicit user approval that identifies the external source and selected version.
  9. Periodically re-audit the pinned release before deliberately updating it rather than automatically tracking the latest formula.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly documents obsidian-cli delete "path/note" with no warning about permanence, confirmation, backups, or validating the target vault/path first. In a note-management skill where vaults are normal folders on disk and multiple vaults may exist, this can lead to unintended data loss if an agent or user issues the command against the wrong note or vault.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.