other
- Location
SKILL.md:96- Finding
Bulk Publication of Unreviewed Obsidian Vault Content
- Content
View full analysis
" "/content" *.md /S /XO /XD .obsidian .trash .git node_modules /XF ".*" ``` ```bash rsync -av --update \ --exclude='.obsidian/' --exclude='.trash/' --exclude='.git/' \ --exclude='node_modules/' --exclude='.*' \ --include='*.md' --include='*/' --exclude='*' \ "/" "/content/" ``` The instructions also direct the agent to copy attachment directories such as `attachments/`, `assets/`, and `images/`. The resulting project is then published with: ```bash cd "" git add . git commit -m "init quartz blog" git branch -M v4 git push -u origin v4 ``` ### Technical Analysis The workflow uses broad file-selection rules rather than a user-reviewed publication allowlist. Excluding hidden files and directories such as `.obsidian`, `.git`, and `.trash` does not protect sensitive information stored in ordinary Markdown documents or attachments. The subsequent use of `git add .` stages all files under the project, including files that may not have originated from the expected synchronization operation. There is no required publication manifest, secret scan, content review, repository-visibility check, or final consent checkpoint before the push. Although network publication is part of the declared blogging functionality, publishing the whole vault and all recognized attachment directories exceeds minimum privilege when only selected public notes are necessary. ### Attack Path 1. A vault contains private notes, credentials, API tokens, personal information, internal URLs, or confidential attachments. 2. The Skill recursively copies matching files in ...[truncated 1057 chars]- Remediation
View remediation
