Back to skill

Security audit

obsidian

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but it can install an unpinned third-party CLI and lets an agent change or delete Obsidian notes without clear safety boundaries.

Review this skill before installing. Use it only with vaults you are comfortable exposing to the agent, keep backups or version control for notes, require explicit confirmation before delete, move, or bulk link updates, and consider separately vetting or pinning the Homebrew dependency.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:7
Finding

Unpinned Third-Party Homebrew Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 7
Vulnerability Type: Third-party dependency supply-chain risk
Risk Level: Medium

Affected code:

yaml
metadata: {"clawdbot":{"emoji":"💎","requires":{"bins":["notesmd-cli"]},"install":[{"id":"brew","kind":"brew","formula":"yakitrak/yakitrak/notesmd-cli","bins":["notesmd-cli"],"label":"Install notesmd-cli (brew)"}]}}

Technical Analysis

The Skill instructs the environment to install notesmd-cli from the third-party Homebrew tap yakitrak/yakitrak. The dependency is not pinned to an immutable source revision, and the package contains no checksum, signature requirement, or vendored source through which the installed implementation can be independently reviewed.

Consequently, the code installed when the formula is resolved may differ from the implementation originally reviewed. If the tap, formula, upstream artifact, or maintainer account is compromised, an attacker could substitute malicious installation logic or a malicious notesmd-cli executable.

This finding does not establish that the current dependency is malicious. It identifies an unsafe, mutable trust boundary that can permit supply-chain compromise.

Attack Path

  1. An attacker compromises the third-party Homebrew tap, its maintainer account, the formula source, or an artifact downloaded by the formula.
  2. The attacker modifies the formula or referenced artifact to install and execute a malicious version of notesmd-cli.
  3. A user installs the dependency through the Skill's declared Homebrew installation mechanism.
  4. Homebrew retrieves the attacker-controlled mutable content and runs the associated installation steps with the invoking user's privileges.
  5. When the Skill invokes notesmd-cli, the substituted executable can access the user's Obsidian configuration and vault data in the process's permission scope.
  6. The malicious executable could read, alter, delete, or ex ...[truncated 851 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer an audited dependency distributed through an official or otherwise strongly governed package source.
  2. Pin the dependency to an immutable release and source commit rather than relying only on a mutable formula name.
  3. Verify downloaded artifacts with cryptographic checksums or signatures whose expected values are maintained in a trusted location.
  4. Review and record the Homebrew formula, its installation hooks, and all upstream artifacts before approving installation.
  5. Use Homebrew lockfiles, an internal package mirror, or a vetted vendored binary where operationally appropriate.
  6. Run the CLI under a least-privileged account or sandbox with access restricted to the intended Obsidian vault.
  7. Require explicit confirmation before destructive operations such as note deletion or bulk link rewrites.
  8. Monitor dependency ownership and release changes, and repeat the security review whenever the pinned version is updated.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: obsidian
description: "Work with Obsidian vaults (plain Markdown notes) and automate via notesmd-cli"
tags: [automation, general, file-based, cli, api-integration]

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises broad file-based automation over Obsidian vaults without clearly constraining when it should be invoked or what paths/actions are in scope. In an agent setting, that ambiguity can cause over-broad activation and unintended read/write operations across a user's note repository, especially because the skill includes commands that create, move, edit, and delete files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes a direct deletion command for notes without any warning, confirmation requirement, or mention of recovery/backup behavior. In an autonomous or semi-autonomous agent workflow, this creates a realistic risk of irreversible data loss from mistaken note selection, prompt injection, or overly broad task interpretation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.