Back to skill

Security audit

Kg Obsidian Mini

Security checks across malware telemetry and agentic risk

Overview

This note-management skill appears useful, but it can modify or delete local notes and send note-derived context to the web without enough explicit user control.

Review carefully before installing. Use it only on a backed-up vault, require dry-run previews before any delete, move, rename, or replacement action, and approve each external search or remote image check only when you are comfortable exposing the related note topic or URL.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
82% confidence
Finding
The manifest advertises YAML validation and enrichment preview, but the workflow also instructs network searching for completion. This expands the operational boundary from local note maintenance to external data access, which can expose note topics, filenames, or sensitive context to third parties without users expecting that behavior.

Description-Behavior Mismatch

Medium
Confidence
82% confidence
Finding
The manifest advertises YAML validation and enrichment preview, but the workflow also instructs network searching for completion. This expands the operational boundary from local note maintenance to external data access, which can expose note topics, filenames, or sensitive context to third parties without users expecting that behavior.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
Broad external search for note enrichment is not tightly scoped to the stated organizational purpose and can leak sensitive note subjects, entities, or internal project terms to search providers. In a knowledge-base context, even seemingly harmless titles or concepts may reveal private research, clients, health topics, or proprietary work.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are extremely broad and overlap with normal conversation about concepts, notes, knowledge graphs, and Obsidian. Over-broad activation increases the chance that the skill runs unexpectedly in unrelated contexts, which is especially risky because the documented workflow includes later file-modifying actions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The markdown directs deletion, renaming, and movement of files/content but does not pair those destructive operations with clear user-facing warnings or explicit confirmation requirements. In a note vault, mistaken execution can cause irreversible data loss, broken links, and corruption of organizational structure, especially when operations are driven from heuristic classification steps.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
Network-based image validation and replacement can disclose embedded URLs, browsing patterns, and note contents to remote servers without clear privacy notice. If notes contain private or internal image links, checking HTTP status or searching alternatives may leak sensitive infrastructure details or user interests.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs broad network searches for enrichment without a clear privacy or external-data disclosure. Because note enrichment naturally uses note text as query material, this can leak sensitive personal, organizational, or research information to external providers and may also introduce untrusted data back into the notes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.