Back to skill

Security audit

obsidian-quartz-blog-setup

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for setting up an Obsidian-to-Quartz blog, but it can publish broad private vault content and includes a self-modification mechanism that users should review carefully.

Review this skill before installing if your Obsidian vault contains private notes, credentials, client data, personal information, or sensitive attachments. Use a dedicated public-notes vault or allowlist, inspect the exact files to be copied, confirm the destination repository and visibility, and require a final manual approval before git add, commit, or push. Consider removing the self-evolution section and pinning Quartz/npm execution to reviewed versions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

other

Error
Location
SKILL.md:96
Finding

Bulk Publication of Unreviewed Obsidian Vault Content

Content
View full analysis
" "/content" *.md /S /XO /XD .obsidian .trash .git node_modules /XF ".*" ``` ```bash rsync -av --update \ --exclude='.obsidian/' --exclude='.trash/' --exclude='.git/' \ --exclude='node_modules/' --exclude='.*' \ --include='*.md' --include='*/' --exclude='*' \ "/" "/content/" ``` The instructions also direct the agent to copy attachment directories such as `attachments/`, `assets/`, and `images/`. The resulting project is then published with: ```bash cd "" git add . git commit -m "init quartz blog" git branch -M v4 git push -u origin v4 ``` ### Technical Analysis The workflow uses broad file-selection rules rather than a user-reviewed publication allowlist. Excluding hidden files and directories such as `.obsidian`, `.git`, and `.trash` does not protect sensitive information stored in ordinary Markdown documents or attachments. The subsequent use of `git add .` stages all files under the project, including files that may not have originated from the expected synchronization operation. There is no required publication manifest, secret scan, content review, repository-visibility check, or final consent checkpoint before the push. Although network publication is part of the declared blogging functionality, publishing the whole vault and all recognized attachment directories exceeds minimum privilege when only selected public notes are necessary. ### Attack Path 1. A vault contains private notes, credentials, API tokens, personal information, internal URLs, or confidential attachments. 2. The Skill recursively copies matching files in ...[truncated 1057 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:69
Finding

Execution of Unpinned Third-Party Repository and npm Content

Content
View full analysis
" cd "" npm install ``` It subsequently executes the installed Quartz command: ```bash cd "" npx quartz create ``` The generated GitHub Actions workflow also installs and runs repository dependencies: ```yaml - name: Install Dependencies run: npm ci - name: Build Quartz run: npx quartz build ``` ### Technical Analysis A plain `git clone` retrieves the current default branch rather than a specific reviewed commit or signed release. The effective code obtained by the Skill can therefore change after the Skill itself has been audited. `npm install` resolves dependencies and can execute npm lifecycle scripts with the permissions of the user running the agent. The Skill does not require commit verification, release-signature validation, checksum verification, dependency review, or lifecycle-script restrictions. The CI use of `npm ci` is safer when a trustworthy lockfile is present, but the lockfile itself originates from the unpinned external repository. Consequently, it does not independently establish that the downloaded dependency graph was reviewed or trusted. ### Attack Path 1. The external Quartz repository, one of its dependencies, or a maintainer account is compromised, or the mutable default branch gains unsafe code. 2. The Skill clones the affected current revision because no reviewed commit hash is specified. 3. `npm install` resolves packages and may execute package lifecycle scripts. 4. `npx quartz create` executes the retrieved code on the local machine. 5. Malicious code runs with the filesystem, environment, and network ...[truncated 697 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:302
Finding

Persistent Self-Modification Based on Execution-Derived Feedback

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The skill instructs unconditional rm deletion of workflow files derived from a user-controlled <project-dir> path. If the path is wrong, maliciously supplied, or insufficiently validated, the agent could delete unintended files; even in the intended directory, destructive file operations should not occur without existence checks and explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

创建 deploy.yml 后,删除这些无用 workflow:

bash
rm "<project-dir>/.github/workflows/ci.yaml"
rm "<project-dir>/.github/workflows/build-preview.yaml"
rm "<project-dir>/.github/workflows/deploy-preview.yaml"
rm "<project-dir>/.github/workflows/docker-build-push.yaml"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This command removes a workflow file using a path parameter that may be influenced by user input and is executed without repository-root validation or confirmation. The danger is amplified because the skill is otherwise focused on setup, so hidden destructive actions against .github/workflows may be unexpected and could remove legitimate automation if the project already differs from the assumed template.

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

bash
rm "<project-dir>/.github/workflows/ci.yaml"
rm "<project-dir>/.github/workflows/build-preview.yaml"
rm "<project-dir>/.github/workflows/deploy-preview.yaml"
rm "<project-dir>/.github/workflows/docker-build-push.yaml"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The skill deletes deploy-preview.yaml with a raw rm command and no guardrails. Destructive commands tied to configurable paths are hazardous because path mistakes, symlink tricks, or preexisting customized workflows could lead to unintended loss of repository automation or other files.

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

bash
rm "<project-dir>/.github/workflows/ci.yaml"
rm "<project-dir>/.github/workflows/build-preview.yaml"
rm "<project-dir>/.github/workflows/deploy-preview.yaml"
rm "<project-dir>/.github/workflows/docker-build-push.yaml"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Unconditional deletion of docker-build-push.yaml is a destructive filesystem action that assumes both repository provenance and file safety without validation. In the context of a setup skill, this increases risk because a user may point the skill at an existing project where these files are not expendable, causing loss of CI/CD configuration.

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

rm "/.github/workflows/ci.yaml" rm "/.github/workflows/build-preview.yaml" rm "/.github/workflows/deploy-preview.yaml" rm "/.github/workflows/docker-build-push.yaml"

text

向用户说明:每次推送到 `v4` 分支时,GitHub Actions 会自动构建并部署网站到 GitHub Pages。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This README describes cloning repositories, running package installation, copying large sets of files, modifying configuration, cleaning workflows, and pushing to a Git branch, but it does not clearly warn that these actions alter the local filesystem and remote repository state. In an autonomous agent context, lack of explicit warnings and confirmation gates increases the chance of unintended file overwrites, workflow changes, or accidental publication of private notes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The README instructs agents to run npx quartz without pinning a specific package version, which means execution may resolve to the latest published package at runtime. In an agentic setup that automates installation and initialization, this creates a supply-chain risk: behavior can change unexpectedly or a compromised upstream package/version could execute arbitrary code during setup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description and instructions are written to operate in Chinese, but there is no indication that the user can choose another language or that the locale restriction is required for a region-specific purpose. This can violate language/locale policy when the skill implicitly enforces one language without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough to activate on generic requests like building a personal blog or putting notes online, which can cause the agent to enter a high-impact workflow involving cloning code, writing files, changing git remotes, and pushing to GitHub without strong intent verification. In this skill's context, accidental invocation is more dangerous because the workflow performs state-changing operations on local and remote resources.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill invokes npx quartz create without pinning a specific package/version, so execution behavior depends on whatever package/version npx resolves at runtime. This creates a supply-chain risk: a compromised upstream package, typo-squatted dependency, or breaking version change could execute unintended code on the user's machine during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The unpinned npx quartz build --serve command may resolve different code over time or from an unexpected package source, which means a local preview step can become an arbitrary code execution path. Because this step is run on the user's workstation, any malicious upstream change would execute with the user's local permissions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

Lines L155-L166 frame the GitHub setup portion as a manual, user-only operation, but the workflow then proceeds to execute git remote set-url origin and git push in L168-L268. While not a direct contradiction about the repository creation itself, the surrounding documentation presents this phase as guidance-only even though the skill performs consequential remote publication actions afterward.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

Using npx quartz build inside the GitHub Actions workflow without version pinning introduces non-deterministic and potentially unsafe package resolution in CI. If package resolution changes or a malicious package version is served, the workflow could build or execute attacker-controlled code in the repository context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The self-evolution section instructs the agent to append failure cases to diary files and submit PRs modifying SKILL.md, which goes beyond the user's requested Quartz setup task and grants the skill a pathway to alter its own behavior. This is dangerous because it enables persistent, unauthorized state changes and prompt/instruction drift across future runs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.