Back to skill

Security audit

Obsidian Sheet Plus

Security checks for vulnerabilities and agentic risk

Overview

This markdown-only skill is coherent for Obsidian Sheet Plus automation, but it exposes high-impact workbook read/write operations through an unauthenticated local REST API and lacks strong confirmation guidance for destructive actions.

Install only if you intentionally use Obsidian Sheet Plus and understand that an agent may read or change the active workbook through the local API. Enable the API key option if available, keep the service bound to localhost, verify sheet names and ranges before use, and require explicit confirmation before full-workbook export, overwrites, clears, deletes, merges, or bulk formatting changes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:29
Finding

Spreadsheet REST API Allows Unauthenticated Access by Default

Content
View full analysis
` | | Content-Type | `application/json` | Base URL can be overridden via environment variable: `OBSIDIAN_SHEET_PLUS_BASE_URL=http://127.0.0.1:3000` ``` ### Technical Analysis The Skill documents that the Obsidian Sheet Plus REST API does not require authentication in its default configuration. This API exposes operations that can read complete workbook data and perform destructive modifications, including clearing cell contents, deleting rows or columns, and overwriting spreadsheet data. Binding the service to `127.0.0.1` reduces exposure to remote hosts but does not establish an authorization boundary. Any local process, compromised application, or other execution context capable of making loopback HTTP requests can invoke the API as the user. The risk would increase substantially if the configurable base address caused the service itself to be exposed on a broader interface. The audit found no evidence of remote payload execution, embedded malicious scripts, persistence mechanisms, dependency attacks, tool spoofing, memory poisoning, or instruction hijacking. ### Attack Path 1. The user starts Obsidian with the Sheet Plus REST API enabled under its default unauthenticated configuration. 2. An untrusted or compromised process running in the same user environment connects to `http://127.0.0.1:3000`. 3. The process calls a read endpoint such as `GET /get_workbook` to retrieve workbook contents without credentials. 4. Alternatively, it submits requests to mutating endpoints such as `/set_sheet_data`, `/delete_rows`, or `/clear_all`. 5. The plugin processes the requests because API-key enf ...[truncated 818 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (39)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger description is broad enough to match generic spreadsheet and data-analysis tasks, which can cause this skill to activate outside its intended Obsidian Sheet Plus context. That increases the chance an agent will route unrelated spreadsheet requests to a local unauthenticated REST API, leading to unintended reads or writes against the user's active workbook.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents multiple write, clear, delete, and formatting endpoints but does not prominently warn that these actions can modify or irreversibly remove spreadsheet data. In an agent setting, that omission can lead to unsafe automation where destructive operations are performed without adequate user awareness or confirmation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/add-conditional-formatting/SKILL.md (reported line 60)May include surrounding context.

Numeric highlight (mark red if greater than 100)

bash
curl -X POST http://127.0.0.1:3000/add_conditional_formatting \
  -H "Content-Type: application/json" \
  -d '{
    "sheetName": "Sheet1",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/add-filter/SKILL.md (reported line 39)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/add_filter \
  -H "Content-Type: application/json" \
  -d '{
    "sheetName": "Sheet1",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/auto-resize-columns/SKILL.md (reported line 42)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/auto_resize_columns \
  -H "Content-Type: application/json" \
  -d '{"sheetName":"Sheet1","startColumn":0,"numberOfColumns":5}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/auto-resize-rows/SKILL.md (reported line 42)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/auto_resize_rows \
  -H "Content-Type: application/json" \
  -d '{"sheetName":"Sheet1","startRow":0,"numberOfRows":10}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documents a bulk destructive action that removes all conditional formatting rules from a sheet, but it does not prominently warn that the action is wide-ranging and may be difficult to undo. In an automation context, this increases the risk of accidental loss of spreadsheet logic or visual cues that users rely on for validation and review.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/clear-all-conditional-formatting/SKILL.md (reported line 38)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/clear_all_conditional_formatting \
  -H "Content-Type: application/json" \
  -d '{"sheetName": "Sheet1"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents a destructive operation that removes both contents and formatting, but it does not explicitly warn that the action may be irreversible or require confirmation before use. In an agent-driven workflow, this increases the chance of accidental bulk data loss because users or downstream agents may invoke it without understanding the consequences.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/clear-all/SKILL.md (reported line 39)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/clear_all \
  -H "Content-Type: application/json" \
  -d '{
    "sheetName": "Sheet1",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes a destructive operation that removes cell contents but does not explicitly warn about irreversibility, scope validation, or the risk of wiping unintended ranges. In an agent setting, this increases the chance of accidental data loss because a user request could be interpreted too broadly and executed without confirmation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/clear-contents/SKILL.md (reported line 39)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/clear_contents \
  -H "Content-Type: application/json" \
  -d '{
    "sheetName": "Sheet1",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/clear-data-validation/SKILL.md (reported line 39)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/clear_data_validation \
  -H "Content-Type: application/json" \
  -d '{
    "sheetName": "Sheet1",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/clear-format/SKILL.md (reported line 39)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/clear_format \
  -H "Content-Type: application/json" \
  -d '{
    "sheetName": "Sheet1",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/create-sheet/SKILL.md (reported line 40)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/create_sheet \
  -H "Content-Type: application/json" \
  -d '{"sheetName": "Dashboard"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/delete-columns/SKILL.md (reported line 44)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/delete_columns \
  -H "Content-Type: application/json" \
  -d '{"sheetName":"Sheet1","columnIndex":1,"numberOfColumns":2}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/delete-rows/SKILL.md (reported line 44)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/delete_rows \
  -H "Content-Type: application/json" \
  -d '{"sheetName":"Sheet1","rowIndex":2,"numberOfRows":3}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly enables exporting the entire workbook, including all sheets, styles, and formulas, but provides no warning that this can expose all spreadsheet contents in one request. In an agent context, this increases the risk of bulk data exfiltration because a model may choose the endpoint for convenience without obtaining clear user confirmation or scoping the export to only necessary data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/insert-columns/SKILL.md (reported line 44)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/insert_columns \
  -H "Content-Type: application/json" \
  -d '{"sheetName":"Sheet1","columnIndex":1,"numberOfColumns":2}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/insert-rows/SKILL.md (reported line 45)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/insert_rows \
  -H "Content-Type: application/json" \
  -d '{"sheetName":"Sheet1","rowIndex":2,"numberOfRows":3}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents a destructive merge operation where only the top-left cell value is preserved and all other cell contents are lost, but it is presented as a brief note rather than a prominent caution or required confirmation step. In an automation context, this can lead to accidental irreversible data loss if an agent invokes the endpoint on populated ranges without explicit user awareness.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/merge-cells/SKILL.md (reported line 42)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/merge_cells \
  -H "Content-Type: application/json" \
  -d '{"sheetName":"Sheet1","range":"A1:B2"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/remove-conditional-formatting/SKILL.md (reported line 39)May include surrounding context.

Example

bash
curl -X POST http://127.0.0.1:3000/remove_conditional_formatting \
  -H "Content-Type: application/json" \
  -d '{
    "sheetName": "Sheet1",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/remove-filter/SKILL.md (reported line 41)May include surrounding context.

Remove filter from a specific range

bash
curl -X POST http://127.0.0.1:3000/remove_filter \
  -H "Content-Type: application/json" \
  -d '{
    "sheetName": "Sheet1",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · tools/set-data-validation/SKILL.md (reported line 75)May include surrounding context.

Dropdown List

bash
curl -X POST http://127.0.0.1:3000/set_data_validation \
  -H "Content-Type: application/json" \
  -d '{
    "sheetName": "Sheet1",

Static analysis

No suspicious patterns detected.