Back to skill

Security audit

Obsidian Cli Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Obsidian note-management helper that can read and modify a user's local vault, with one scope note users should watch.

Install only if you want an agent to operate on your Obsidian vault. Before allowing write actions, confirm the target vault, file, and operation, especially for append, property changes, task toggles, or bulk note updates.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill advertises a very broad activation scope using vague phrases like project management, task planning, progress tracking, and team collaboration, while also exposing direct file and command execution capabilities. This can cause an agent to invoke the skill in contexts where the user did not explicitly intend local note or file operations, increasing the chance of unintended reads, writes, or destructive modifications to an Obsidian vault.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill enables direct command-line operations that can create, append, modify, and manage local notes, but it does not prominently warn users that it performs file-modifying actions on a local knowledge base. Without a clear warning, users and agents may treat it like a read-only search utility, leading to accidental data alteration, overwrites, or privacy-sensitive access to local notes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.