Back to skill

Security audit

Obsidian

Security checks for vulnerabilities and agentic risk

Overview

This skill is intended to manage an Obsidian wiki, but it can modify and sync a real Nextcloud vault from broad or ambiguous prompts without explicit confirmation.

Install only if this is the intended Rodion/Rodrigo Nextcloud Obsidian vault and you want the agent to read, create, update, log, and sync wiki notes there. Use explicit commands for ingest/write/sync operations and review intended file changes before allowing them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes very broad terms such as "wiki" and "knowledge base," which can cause the skill to activate in contexts unrelated to the user's intent to access or modify this specific Obsidian/Nextcloud vault. Because the skill operates on a real filesystem path and provides commands for reading, creating, and syncing notes, unintended invocation could lead to unauthorized note exposure or unintended content changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Treating any time the user "shares a link/article" as an ingest trigger is ambiguous and risky, since users often share links for discussion rather than permanent storage. In this skill's context, that ambiguity is more dangerous because the workflow automatically converts external content into structured local notes and synchronizes them, increasing the chance of unintended data modification and persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Treating any time the user "shares a link/article" as an ingest trigger is ambiguous and risky, since users often share links for discussion rather than permanent storage. In this skill's context, that ambiguity is more dangerous because the workflow automatically converts external content into structured local notes and synchronizes them, increasing the chance of unintended data modification and persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to create pages, update index and log files, and run sync without any user-facing warning that local content will be modified. This can lead to silent changes to a personal knowledge base, including propagation through Nextcloud sync, which raises the impact beyond a simple local edit because unintended or low-quality content may be replicated across devices.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The directory structure and inline comments mix Russian-language labels such as "База знаний" with English descriptions, implying a fixed language choice for the knowledge base naming convention. The file does not offer any language choice, opt-in, or justification for this locale constraint, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.