Back to skill

Security audit

Obsidian Official Cli 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent and not deceptive, but it gives an agent broad live access to private Obsidian vault operations without enough safety scoping or confirmation guidance.

Install only if you want an agent to operate your live Obsidian vault through the official CLI. Use explicit prompts and confirm before deletes, overwrites, sync restores, plugin/theme installs, screenshots, exports, or eval/debug commands, especially on private or business vaults.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The changelog highlights destructive capabilities such as edit, move, and delete, but provides no accompanying warning about confirmation, backups, dry-run behavior, or least-privilege constraints. In the context of an Obsidian CLI skill with broad vault access, omission of these safety disclosures increases the risk of accidental data loss or unsafe automation being treated as routine.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The changelog advertises 'auto-triggering based on Obsidian-related queries' without defining clear scope, guardrails, or confirmation requirements. In an agent skill that can perform file operations, search, plugin management, and sync actions, vague invocation criteria can cause the skill to activate unexpectedly and influence actions on user vaults without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README prominently advertises destructive and privacy-impacting capabilities such as deleting notes, plugin/theme management, sync operations, screenshots, and developer-console access without clearly warning users about data loss, credential exposure, or sensitive-content access. In a skill that can operate on a live Obsidian instance and vault, this omission increases the risk that users invoke powerful actions without informed consent or understanding of consequences.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The statement that the skill will 'automatically trigger' on Obsidian-related mentions implies broad activation and session persistence around sensitive vault operations, including searching notes, toggling tasks, exporting databases, and plugin changes. In the context of a live note-taking environment that may contain private or proprietary content, automatic invocation can cause unintended actions or disclosure beyond what a user explicitly confirmed.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

md
Once installed, the skill will automatically trigger when you mention Obsidian operations:

- "Create a new note called 'Meeting Notes' using Obsidian CLI"
- "Search for all notes containing 'project' with Obsidian's search engine"
- "Show me all incomplete tasks and toggle their status via CLI"
- "Query my Books database and export to CSV"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description is broad enough to auto-activate for nearly any Obsidian-related task, including sensitive vault operations, plugin management, sync restoration, and developer commands. Over-broad activation increases the chance an agent will invoke this skill in contexts where destructive or privacy-sensitive commands are unnecessary or unsafe.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
obsidian read                          # Read active file
obsidian read file=Recipe --copy       # Read and copy to clipboard

# Create new notes
obsidian create name="New Note"
obsidian create name="Note" content="# Title Body"
obsidian create path="Inbox/Idea.md" template=Daily

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section documents move/delete/overwrite operations without prominent warnings or confirmation requirements, which can normalize destructive actions in automated use. In an agent context, omission of safety guidance materially increases the risk of accidental data loss or irreversible modification of user notes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The plugin/theme/dev sections include commands that install third-party components, alter execution environment, inspect DOM, take screenshots, and evaluate code, but provide no privacy or integrity warnings. In an agent setting, these capabilities can expose vault contents, change trusted software state, or execute arbitrary app-context code with potentially high impact.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 296)May include surrounding context.

Linux: Symlink at /usr/local/bin/obsidian

bash
# Manual creation if needed:
sudo ln -s /path/to/obsidian /usr/local/bin/obsidian

Windows: Requires Obsidian.com terminal redirector (Catalyst Discord)

Static analysis

No suspicious patterns detected.