T09 · Insecure Skill Coding Practices
- Location
SKILL.md:126- Finding
Insufficient Path Validation Enables Writes Outside the Obsidian Vault
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s Obsidian clipping purpose is legitimate, but its file-writing instructions are too loosely scoped and it ships a personal local configuration.
Review before installing. Configure your own vault path and collector name, and only use this with trusted or user-chosen destination categories until the skill adds path sanitization and confirms that every saved file stays inside the Obsidian vault.
SKILL.md:126Insufficient Path Validation Enables Writes Outside the Obsidian Vault
config.json:2Distributed Configuration Exposes Personal Identity and Local Filesystem Information
The README states that the skill will automatically fetch external content and save it into the user's Obsidian vault, but it does not prominently warn users that invoking the skill causes both network access and local filesystem writes. In an agent setting, this can lead to unexpected data ingestion, accidental storage of malicious or sensitive content, and reduced user awareness of side effects when processing untrusted URLs.
The trigger phrases are broad enough to activate on common words like “收藏”, “归档”, “clip”, or “save to obsidian”, which can cause the skill to run in contexts where the user did not intend external fetching or file writes. In this skill, accidental activation is more dangerous because execution can lead to network access, content extraction, automatic classification, and persistence into the user's Obsidian vault without a strong confirmation boundary.
The workflow directs the agent to fetch external pages, search third-party content, open pages in a browser, and then write generated Markdown files into the user's vault, but the skill does not prominently warn about these side effects at invocation time. This reduces informed consent and increases the risk of users unintentionally causing outbound requests, ingesting untrusted content, or persisting misleading/sensitive material into local files.
The configuration hard-codes Chinese collector and category names, which indicates the skill is tailored to a specific language/locale without any visible mechanism for user selection. Under the policy, locale-specific behavior should either offer user choice or be explicitly justified as region-specific.
No suspicious patterns detected.