Back to skill

Security audit

Obsidian 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Obsidian note-management helper, but it can modify or delete notes if the user runs those commands.

Install only if you trust the obsidian-cli Homebrew package and are comfortable letting it access your Obsidian vault. Confirm the active vault and exact note path before moving or deleting notes, and keep backups or version control for important vaults.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents `obsidian-cli delete "path/note"` with no confirmation, warning, backup guidance, or recommendation to verify the target path first. In an agent context, this can normalize or automate irreversible note deletion in a user's vault, increasing the chance of accidental data loss from prompt misunderstanding, path confusion, or unsafe autonomous actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal