Back to skill

Security audit

Obsidian Official CLI Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is not overtly malicious, but it gives an agent broad ability to inspect and change a live Obsidian vault without clear safety guardrails.

Install only if you want an agent to have broad control over your live Obsidian environment. Use explicit prompts for vault-changing actions, require confirmation before permanent deletion, overwrites, restores, plugin/theme changes, eval, screenshots, or DOM inspection, and keep backups of important vaults.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The changelog explicitly advertises 'auto-triggering based on Obsidian-related queries,' which suggests broad invocation criteria for a skill that can perform file operations, plugin/theme management, sync actions, and other state-changing CLI commands. In an agent environment, overly broad trigger conditions increase the chance the skill activates on loosely related prompts and performs sensitive vault actions without sufficiently deliberate user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The feature list advertises destructive and system-affecting capabilities such as deleting notes, installing/enabling plugins, theme changes, sync operations, developer tools, and screenshots, but does not warn about the risks of data loss, privacy exposure, or environment changes. In a live note-taking environment connected to a running Obsidian instance, users may not realize that ordinary natural-language requests could alter content, configuration, or synced state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states the skill will 'automatically trigger when you mention Obsidian operations,' which is an overly broad activation condition for a skill that can create, move, delete notes, manage plugins, and perform sync operations. Broad triggering increases the chance the agent invokes powerful actions from ambiguous user requests or unrelated context, leading to unintended modification of a live vault.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

md
Once installed, the skill will automatically trigger when you mention Obsidian operations:

- "Create a new note called 'Meeting Notes' using Obsidian CLI"
- "Search for all notes containing 'project' with Obsidian's search engine"
- "Show me all incomplete tasks and toggle their status via CLI"
- "Query my Books database and export to CSV"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is unusually broad and encourages invocation for virtually any Obsidian-related task, including file management, plugins, themes, sync, and command-line interaction. In an agent setting, overbroad routing increases the chance the skill is selected for routine requests and then performs sensitive or destructive operations without sufficient narrowing or user confirmation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
obsidian read                          # Read active file
obsidian read file=Recipe --copy       # Read and copy to clipboard

# Create new notes
obsidian create name="New Note"
obsidian create name="Note" content="# Title Body"
obsidian create path="Inbox/Idea.md" template=Daily

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

These examples document move and delete operations, including permanent deletion and overwrite behavior, without any warning about irreversible data loss. In a tool-using agent context, presenting destructive commands as normal patterns can lead to accidental or overly eager execution against a user's vault.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section exposes powerful capabilities such as plugin install/enable, theme changes, sync/history restore, developer debugging, screenshots, DOM inspection, and especially eval, but provides no safety boundaries. In an agent environment, these commands can alter the application state, roll back data, expose sensitive content, or execute arbitrary JavaScript within Obsidian's context.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 296)May include surrounding context.

Linux: Symlink at /usr/local/bin/obsidian

bash
# Manual creation if needed:
sudo ln -s /path/to/obsidian /usr/local/bin/obsidian

Windows: Requires Obsidian.com terminal redirector (Catalyst Discord)

Static analysis

No suspicious patterns detected.