Back to skill

Security audit

Obsidian-CLI-official-for-1.13+

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-style Obsidian CLI skill whose powerful vault actions are disclosed and aligned with its purpose, but users should review destructive or plugin/developer commands before running them.

Install this only if you want an agent to operate your Obsidian vault through the official CLI. Review requests before allowing permanent delete, history restore, plugin/theme installation, eval, CDP, or broad search/read operations, and keep backups for important vaults.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (31)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README repeatedly encourages autonomous creation, editing, and organization of notes but does not warn that these commands modify user vault contents and may overwrite or append sensitive data. In an agent skill context, omission of review/confirmation guidance increases the chance that an AI executes state-changing operations on behalf of a user without adequate approval.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

The CLI registers as /usr/local/bin/obsidian → /Applications/Obsidian.app/Contents/MacOS/obsidian-cli. Requires admin privileges.

If the symlink is missing or you want to (re)create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples include commands that can revert content history, install/enable plugins, and change themes/snippets without explaining reversibility, trust, or side effects. In an agent-execution setting, these operations can alter content integrity and expand functionality in ways the user did not explicitly authorize.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README prominently encourages automation that can read, write, and reorganize a user's Obsidian vault, but it does not clearly warn that these commands may modify or overwrite user data. In an agent-executed skill context, missing mutation warnings increase the risk of unintended destructive actions because users may assume examples are safe to run verbatim.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · README.md (reported line 46)May include surrounding context.

md
|------|----------|
| macOS | `ls -l /usr/local/bin/obsidian` |
| Windows | `Test-Path "$env:LOCALAPPDATA\Obsidian\Obsidian.com"` |
| Linux | `ls -l ~/.local/bin/obsidian` |

### 平台配置

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · README.zh.md (reported line 43)May include surrounding context.

md
|------|----------|
| macOS | `ls -l /usr/local/bin/obsidian` |
| Windows | `Test-Path "$env:LOCALAPPDATA\Obsidian\Obsidian.com"` |
| Linux | `ls -l ~/.local/bin/obsidian` |

### 平台配置

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
|------|----------|
| macOS | `ls -l /usr/local/bin/obsidian` |
| Windows | `Test-Path "$env:LOCALAPPDATA\Obsidian\Obsidian.com"` |
| Linux | `ls -l ~/.local/bin/obsidian` |

### 平台配置

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 337)May include surrounding context.

md
|------|----------|
| macOS | `ls -l /usr/local/bin/obsidian` |
| Windows | `Test-Path "$env:LOCALAPPDATA\Obsidian\Obsidian.com"` |
| Linux | `ls -l ~/.local/bin/obsidian` |

### 平台配置

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.zh.md (reported line 109)May include surrounding context.

📝 会议记录

bash
obsidian create name="会议 2026-03-01" content="# 团队同步\n\n..."
obsidian property:set name="类型" value="会议" file="会议 2026-03-01"
obsidian bookmark file="会议 2026-03-01.md"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 309)May include surrounding context.

md
# Linux:如果 ~/.local/bin/obsidian 不存在
cp /path/to/Obsidian/obsidian-cli ~/.local/bin/obsidian
chmod 755 ~/.local/bin/obsidian

# 或者直接用全路径
/Applications/Obsidian.app/Contents/MacOS/obsidian-cli version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.zh.md (reported line 258)May include surrounding context.

md
# Linux:如果 ~/.local/bin/obsidian 不存在
cp /path/to/Obsidian/obsidian-cli ~/.local/bin/obsidian
chmod 755 ~/.local/bin/obsidian

# 或者直接用全路径
/Applications/Obsidian.app/Contents/MacOS/obsidian-cli version

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

ls -l /usr/local/bin/obsidian

text

If missing, create it manually:
```bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 57)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 64)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 305)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.zh.md (reported line 54)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.zh.md (reported line 61)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.zh.md (reported line 254)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 342)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 364)May include surrounding context.

If missing, create it manually:

bash
sudo ln -sf /Applications/Obsidian.app/Contents/MacOS/obsidian-cli /usr/local/bin/obsidian

⚠️ Pitfall: The CLI binary changes between Obsidian versions. After updating Obsidian, the existing symlink may break or point to a stale binary. Two ways to fix:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 90)May include surrounding context.

If missing, copy it manually:

bash
cp /path/to/Obsidian/obsidian-cli ~/.local/bin/obsidian
chmod 755 ~/.local/bin/obsidian

Windows

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.zh.md (reported line 87)May include surrounding context.

If missing, copy it manually:

bash
cp /path/to/Obsidian/obsidian-cli ~/.local/bin/obsidian
chmod 755 ~/.local/bin/obsidian

Windows

Static analysis

No suspicious patterns detected.