Obsidian Local REST API

Security checks across malware telemetry and agentic risk

Overview

This Obsidian skill is purpose-aligned, but it gives an agent broad note-reading, note-modifying, deletion, and command-execution authority without clear confirmation guardrails.

Install only if you are comfortable giving the agent API-key access to your Obsidian vault. Before use, narrow the triggers, require confirmation before overwrites, deletes, patches, or command execution, keep the API key scoped and protected, and avoid exposing the REST API beyond trusted local networks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very broad phrases such as 'note this', 'create a note', 'append to', and especially 'sv', which can cause the skill to activate in unrelated conversations. Because this skill can read, overwrite, append, delete notes, and execute Obsidian commands, accidental invocation could lead to unintended data access or modification.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documents destructive and privileged capabilities, including deleting notes and executing arbitrary Obsidian commands, without strong user-facing guardrails such as explicit consent, confirmation, or command allowlisting. In a conversational agent context, this materially increases the chance of unsafe actions being performed from ambiguous or malicious prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal