Obsidian Manager

Security checks across malware telemetry and agentic risk

Overview

This is a local Obsidian note helper that creates and searches markdown files, with disclosed but somewhat brittle vault-path handling.

Before installing, verify that the research vault path points to the notes you intend the agent to read and modify. Do not point it at sensitive markdown collections unless you are comfortable with search results being surfaced to the agent, and avoid note titles or direction values containing path traversal such as ../ or absolute paths.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
93% confidence
Finding
The README discloses a specific local Windows filesystem path (`D:\Personal\OpenClaw\research\`), which leaks environment-specific information about the author's machine and directory layout. While not directly exploitable by itself, such disclosure can aid fingerprinting, reveal personal naming conventions, and encourage unsafe assumptions that the skill should operate against a fixed host path.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal