Back to skill

Security audit

Kg Obsidian Mini

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Obsidian note-organization skill, but it grants broad note editing, deletion, renaming, and web-search behavior that deserves user review before installation.

Install only if you want an agent to reorganize an Obsidian vault and you are prepared to review a dry-run checklist before any edits. Keep backups or version control enabled, require explicit approval before rename/delete/move operations, and avoid web enrichment unless you are comfortable sending note-derived search terms externally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This is another valid description-behavior mismatch: the skill claims broad note-processing, completion, and preview capabilities while apparently only supporting a much smaller YAML/frontmatter validation subset. Such overclaiming is dangerous because it obscures operational boundaries and can mislead users into trusting automation decisions that are not actually backed by code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This is another valid description-behavior mismatch: the skill claims broad note-processing, completion, and preview capabilities while apparently only supporting a much smaller YAML/frontmatter validation subset. Such overclaiming is dangerous because it obscures operational boundaries and can mislead users into trusting automation decisions that are not actually backed by code.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest emphasizes local YAML validation and preview, yet the documented enrichment plan expands into network search. That broadens data exposure and capability scope beyond what a user would reasonably infer from the description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation reassures users that notes will not be proactively rewritten, but later operational steps direct routine creation, modification, renaming, and deletion. This contradiction is materially risky because it lowers user caution while enabling irreversible changes to personal knowledge files.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger terms include broad everyday words like '概念' and '笔记', which can cause accidental invocation in unrelated conversations. Overbroad activation is dangerous because it may activate file-inspecting or file-modifying workflows without the user intending to use this skill at all.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill describes operational file access and workflow automation but does not declare an explicit tool scope such as allowed-tools or permissions. That makes its effective capabilities ambiguous and increases the chance an agent can invoke broader file operations than a reviewer or user would expect.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest emphasizes local YAML validation and preview, yet the documented enrichment plan expands into network search. That broadens data exposure and capability scope beyond what a user would reasonably infer from the description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow includes deletions, renames, relation rewrites, and content moves, but the user-facing description does not prominently warn about these destructive operations. Without clear disclosure, users may not realize the skill can alter or remove notes and links in ways that are hard to reverse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions include external HTTP checks for images and web searching, which create outbound network activity unrelated to minimal local note organization. This can leak note-derived terms, reveal user interests or file content context, and introduce unnecessary remote dependencies.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The enrichment plan authorizes open-ended web search, expanding the skill from local file organization into external data gathering. Open-ended search increases privacy risk, capability creep, and the chance of unreviewed content being introduced into notes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language instructions and descriptions exclusively in Chinese, which imposes a specific language on users. The policy allows locale constraints only when documented and justified or when users are offered a choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file returns a Chinese-only error message for missing files, which is a user-facing language restriction. Because no opt-in or documented locale justification is present, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The command-line usage message is presented only in Chinese, forcing a locale on users. The stated policy requires either user choice or a clearly justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and CLI usage/output messages are written only in Chinese, which imposes a specific language on users without any opt-in or locale selection. The policy explicitly flags language or locale requirements when the skill forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.