Back to skill

Security audit

Obsidian Clipper

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Obsidian clipping purpose is legitimate, but its file-writing instructions are too loosely scoped and it ships a personal local configuration.

Review before installing. Configure your own vault path and collector name, and only use this with trusted or user-chosen destination categories until the skill adds path sanitization and confirms that every saved file stays inside the Obsidian vault.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:126
Finding

Insufficient Path Validation Enables Writes Outside the Obsidian Vault

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
config.json:2
Finding

Distributed Configuration Exposes Personal Identity and Local Filesystem Information

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that the skill will automatically fetch external content and save it into the user's Obsidian vault, but it does not prominently warn users that invoking the skill causes both network access and local filesystem writes. In an agent setting, this can lead to unexpected data ingestion, accidental storage of malicious or sensitive content, and reduced user awareness of side effects when processing untrusted URLs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to activate on common words like “收藏”, “归档”, “clip”, or “save to obsidian”, which can cause the skill to run in contexts where the user did not intend external fetching or file writes. In this skill, accidental activation is more dangerous because execution can lead to network access, content extraction, automatic classification, and persistence into the user's Obsidian vault without a strong confirmation boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow directs the agent to fetch external pages, search third-party content, open pages in a browser, and then write generated Markdown files into the user's vault, but the skill does not prominently warn about these side effects at invocation time. This reduces informed consent and increases the risk of users unintentionally causing outbound requests, ingesting untrusted content, or persisting misleading/sensitive material into local files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The configuration hard-codes Chinese collector and category names, which indicates the skill is tailored to a specific language/locale without any visible mechanism for user selection. Under the policy, locale-specific behavior should either offer user choice or be explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.