Back to skill

Security audit

Obsidian 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Obsidian helper, but users should be careful with note deletion and the third-party Homebrew dependency.

Install only if you trust the obsidian-cli Homebrew tap, and treat delete or bulk-edit operations as destructive: confirm the target vault and note path first, keep backups or version control for important vaults, and prefer move/archive workflows when possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party Homebrew Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

yaml
metadata: {"clawdbot":{"emoji":"💎","requires":{"bins":["obsidian-cli"]},"install":[{"id":"brew","kind":"brew","formula":"yakitrak/yakitrak/obsidian-cli","bins":["obsidian-cli"],"label":"Install obsidian-cli (brew)"}]}}

Technical Analysis

The installation metadata directs users or an automated installer to obtain obsidian-cli from the third-party Homebrew tap yakitrak/yakitrak. The dependency is not pinned to an immutable release, commit, or verified artifact checksum. Consequently, the package installed in the future may differ from the package that existed when this Skill was reviewed.

This creates a supply-chain trust boundary: control of the tap, its formula, its source archive, or the associated maintainer account could allow an attacker to distribute altered installation logic or a malicious replacement executable. Homebrew formula installation may execute build and installation procedures, while the resulting CLI operates with the invoking user's permissions.

No evidence in the audited files establishes that the referenced package is currently malicious. The risk arises from the mutable, unverified third-party dependency.

Attack Path

  1. An attacker compromises the third-party tap, its maintainer account, the formula repository, or an upstream artifact referenced by the formula.
  2. The attacker publishes a modified formula or package under the existing obsidian-cli name.
  3. A user or automated environment installs the dependency using the Skill's Homebrew installation metadata.
  4. Malicious logic executes during installation or is placed on the system as the expected obsidian-cli executable.
  5. When the Skill invokes the executable, it runs with the user's permissions and can access resources available to that user, includ ...[truncated 681 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer an official, trusted distribution channel for obsidian-cli where one is available.
  • Pin the dependency to an immutable version or audited source commit rather than tracking a mutable third-party formula.
  • Verify downloaded artifacts with a cryptographic checksum or signature tied to the approved release.
  • Record the expected package version and integrity value in installation metadata or a reviewed lock mechanism.
  • Review the Homebrew formula, its source URLs, and installation hooks before approving updates.
  • Restrict automated dependency updates and require security review when the pinned version or checksum changes.
  • Perform installation and execution as a non-privileged user with access limited to the intended vault whenever operationally feasible.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly documents a delete command for notes without any caution, confirmation guidance, or recovery advice. In an agent-executed context, this increases the chance that a model or user will invoke irreversible deletion on real vault content, especially because Obsidian vaults are ordinary filesystem folders containing user knowledge and notes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.