Back to skill

Security audit

笔记CLI工具箱

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a disclosed Obsidian note automation helper, but its broad trigger language, inconsistent API/network claims, and routine bulk file mutations need human review before installation.

Review before installing. Use this only for clearly requested Obsidian vault tasks, keep backups or version control enabled, run dry-run previews before bulk edits or moves, and do not provide API keys, callback URLs, or Git push credentials unless you specifically intend a networked CI workflow.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The document presents the tool as a local file-processing utility with no API-key requirement, but later discusses API connection setup, network checks, and network-dependent behavior. This inconsistency obscures whether the skill performs network actions, which is dangerous because users may approve execution under false assumptions about outbound access and data exposure.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The document presents the tool as a local file-processing utility with no API-key requirement, but later discusses API connection setup, network checks, and network-dependent behavior. This inconsistency obscures whether the skill performs network actions, which is dangerous because users may approve execution under false assumptions about outbound access and data exposure.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance is overly broad, saying to use the skill for loosely defined analytics, reporting, visualization, and workflow scenarios. In an agent environment with exec, read, and write permissions, ambiguous activation criteria can cause the skill to be selected in contexts where users did not intend filesystem-modifying or command-executing behavior.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documents bulk frontmatter changes, status rewrites, and file moves as routine operations without a prominent upfront safety warning, despite using direct disk writes and exec. In this context, destructive or large-scale note modifications can be triggered with little friction, leading to data loss, unintended edits, or mass corruption of a vault.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.