Back to skill

Security audit

Obsidian Assistant

Security checks for vulnerabilities and agentic risk

Overview

This Obsidian helper is mostly purpose-aligned, but it automatically builds and updates a persistent profile of the user's vault structure and habits without clear opt-in, retention, or deletion controls.

Install only if you are comfortable with the assistant keeping a long-lived local profile of your Obsidian vault path, folders, tags, plugins, workflow habits, and pain points. Avoid pasting sensitive directory names or raw command output unless you have redacted it, and review or clear habit-patterns.md if you do not want those details reused later.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (18)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This flow asks the user to provide command output such as ls results, infer organizational logic from it, and then mandates storing all gathered details in a profile file. Directory listings and plugin inventories can contain highly sensitive metadata, and combining collection with mandatory persistence substantially increases exposure and downstream misuse risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The rules require updating a persistent user profile after every interaction with newly discovered habit information, including pain points and workflow metadata. Mandatory continuous profiling is dangerous because it creates a cumulative dossier of potentially sensitive operational behavior without meaningful user awareness, choice, or retention controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README defines very broad activation contexts such as generic Obsidian, note-taking, vault, tagging, and workflow questions, which can overlap with normal user conversation and cause the skill to trigger unexpectedly. Unintended invocation can expose persistent memory, cause profile reads/writes, and steer conversations into file-analysis behavior without the user explicitly requesting it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises a persistent profile that grows with every conversation and says it 'remembers' vault details, but it does not clearly warn users about retention duration, sensitivity of stored content, or when writes occur. This creates a consent and privacy risk because users may disclose filesystem paths, plugin inventories, organizational schemes, and workflow habits without understanding they will be stored and reused.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Persistent accumulation of vault paths, sync methods, directory structures, tags, and plugin usage creates a natural-language memory store containing operationally sensitive information about the user's local environment. If later surfaced in responses, accessed by other skills, or included in logs, this profile could leak private metadata or enable more targeted social engineering and local-environment attacks.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic write-back of 'new habits' encourages continuous collection of user behavioral data without clear classification of sensitive versus nonsensitive information. Because the process is framed as automatic and ongoing, users may unknowingly build a detailed long-term profile that can later be overexposed, misused, or retained beyond their expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly states it will record the user's Obsidian habits, vault structure, and workflow patterns over time, but it provides no notice, consent flow, or retention boundaries. This creates a privacy and profiling risk because users may reveal sensitive workspace metadata without understanding it will be persistently stored and reused.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description directs the assistant to persistently collect detailed information about the user's knowledge base structure, tagging logic, and high-frequency behaviors. Even if intended for personalization, this is sensitive metadata that can reveal project names, organizational patterns, and work habits, making the profiling more dangerous in a note-taking and knowledge-management context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions mandate immediately reading and building context from a persistent habits file, then enriching it with user-specific details, without warning the user that cross-session memory is being used. This is dangerous because it silently transforms a one-off support interaction into ongoing behavioral profiling and may expose prior stored personal workflow data in future sessions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow tells the assistant to solicit vault paths, directory structure, and tag systems, then store them persistently. Those details can expose usernames, filesystem layout, client/project names, or confidential topic areas, so collecting and retaining them without strong warning or minimization is risky.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the assistant to convert newly observed user behavior into persistent records after answering questions. This is risky because it expands storage from explicitly provided facts to inferred behavioral patterns, which users are less likely to expect or consent to.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill requires automatic updates to habit-patterns.md after each interaction, including newly inferred user habits and pain points, with no user notification that their inputs will be written to disk. This creates a covert data retention risk and can accumulate sensitive operational details over time beyond the user's expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly states that the assistant will gradually accumulate and append records of the user's actual Obsidian operation patterns and preferences, but it provides no notice, consent flow, retention limits, or minimization guidance. Because this data can reveal work habits, vault structure, plugin usage, and knowledge-management behavior over time, it creates a privacy and profiling risk if stored unnecessarily or exposed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very generic verbs such as ‘新建’, ‘整理’, ‘分类’, ‘搜索’, and ‘写作’, which can appear in many unrelated user requests. In an agent routing context, this can cause the Obsidian skill to activate outside its intended scope, leading to unnecessary collection of user workflow details and inappropriate responses based on wrong assumptions about the user’s tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The daily note template uses Chinese section headings and instructional text throughout, which imposes a specific language on users. The policy allows locale or language constraints only when users are given a choice or when the constraint is clearly documented and justified, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown template presents all user-facing headings and instructions in Chinese, which imposes a specific language by default. Under the policy, forcing a language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title and operational instructions are entirely in Chinese, which can constitute a language-policy issue when the skill enforces a specific language without opt-in or explanation. There is no indication that the user can choose another language or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This reference file presents all instructional content and labels exclusively in Chinese, which may effectively force a specific language experience for users. There is no indication that the skill supports user language choice or that the Chinese-only constraint is intentional and justified for a region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.