Obsidian WSL

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned Obsidian vault management skill, but users should be careful with its note-editing, overwrite, move, and delete operations.

Install if you want an agent to manage files in an Obsidian vault. Before using delete, move, overwrite, or direct edit actions, confirm the exact target notes and keep a backup or version control enabled for the vault.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill documents multiple state-changing and destructive operations such as overwrite, move, direct file edits, and delete, but does not place a prominent safety warning before or alongside these commands. In an agent setting, this increases the chance of unintended data loss or broad modifications to a user's Obsidian vault, especially because the skill normalizes direct filesystem writes as acceptable.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal