Back to skill

Security audit

Obsidian Wiki Manager

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Obsidian knowledge-base manager, but it needs review because ordinary questions can trigger local commands and persistent vault edits.

Install only if you want an agent to read your Obsidian raw/wiki content, write wiki pages and reports, and run local qmd maintenance commands. Use explicit command phrases, review generated destinations before saving, and ensure any qmd invocation passes user queries as literal arguments rather than through shell interpolation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:126
Finding

Potential Command Injection Through Unescaped Search Query

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 126
Vulnerability Type: OS command injection caused by unsafe command construction
Risk Level: High

Vulnerable Code

markdown
**Step Q1**:执行 `qmd search "<query>" -n 5 --json`(本机环境 `qmd query` 的 LLM 扩充会超时,故用 search 替代)

Technical Analysis

The skill instructs the agent to insert a direct user query into a shell-style command. Although the placeholder is enclosed in double quotes, the document does not require shell-free execution, argument-array invocation, validation, or escaping.

If an implementing agent substitutes untrusted input into this command and invokes it through a command shell, a query containing a double quote and shell control operators could terminate the intended argument and introduce an additional command. Quoting alone is not a sufficient defense because shell parsing occurs before qmd receives its arguments.

The project contains only SKILL.md; therefore, no concrete execution wrapper is available to determine whether the command is ultimately passed through a shell. The finding applies to implementations that follow this instruction using shell interpolation.

Attack Path

  1. An attacker submits a direct knowledge-base question containing a closing quote, shell control syntax, and an unintended command.
  2. The skill selects the QUERY workflow and substitutes the attacker-controlled text for <query>.
  3. An agent or integration constructs the documented command as a single shell command string.
  4. The shell treats the injected syntax as executable command structure rather than as part of the search term.
  5. The injected command executes with the operating-system privileges and filesystem access of the agent process.

Impact Assessment

Successful exploitation could permit arbitrary local command execution under the agent's account. The attacker could potentially read files accessible to that acc ...[truncated 467 chars]

Remediation
View remediation

Remediation Suggestions

  • Invoke qmd through a structured process API with a fixed executable and argument array, for example:
    text
    ["qmd", "search", query, "-n", "5", "--json"]
    
  • Disable shell evaluation explicitly; do not construct a single command string or use shell invocation options such as shell=true.
  • Treat the complete question as opaque data passed in one argument.
  • If the available tool accepts only command strings, use a platform-appropriate, well-tested escaping library rather than manual quoting.
  • Reject control characters and enforce a reasonable maximum query length as defense-in-depth measures.
  • Update the skill instruction to state that user input must never be interpreted as shell syntax.
  • Add tests using embedded quotes, command separators, command substitutions, redirection operators, and newline characters to verify that all such values reach qmd only as literal search text.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Using "直接提问,或『根据我的知识库』" as a QUERY trigger is overly broad because it effectively captures ordinary user questions. In this skill, QUERY may execute local commands and may write artifacts to wiki/outputs, so a casual question could cause unintended filesystem access and persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrase "处理这个" is so generic that normal conversation can unintentionally activate destructive or state-changing ingest behavior. In this skill, activation can lead to reading files, generating derived content, and writing into the wiki, so accidental invocation is materially risky even without malicious intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The URL ingestion flow writes fetched external content into raw/clippings/ without a clear user-facing warning or confirmation that remote material will be stored locally. This can create privacy, compliance, copyright, or storage risks, especially if the fetched content contains sensitive or unexpected data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger word "检查" is too generic and can easily match ordinary requests for review or verification. Because LINT runs scripts and may update indexes, accidental activation could execute maintenance actions the user did not intend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The phrase "发现规律" is vague and semantically broad, so many reflective or analytical conversations could trigger the REFLECT workflow. In context, REFLECT performs bulk reads and writes synthesis and gap-analysis files, making unintended activation a real state-change risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The phrase "我想搞清楚" is a natural-language expression common in normal chat, making accidental ADD-QUESTION activation likely. Since the workflow appends to QUESTIONS.md and log.md, ordinary discussion could silently become persistent modifications to the knowledge base.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The "Wiki 语言规范" section mandates that the wiki layer be written uniformly in Chinese, which is a language policy constraint. The file does not present this as a user choice or justified region-specific requirement, so it constitutes a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The QUERY section states that answers with reuse value may be written into wiki/outputs, but this side effect is not surfaced as a clear warning at activation time. Users may expect a read-only query and instead get persistent artifacts created on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.