Back to skill

Security audit

Obsidian Essentials Free

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Obsidian beginner guide, but it requests broad command execution authority that is not clearly scoped to the tutorial tasks.

Review before installing. The content is not deceptive or destructive, but only use this skill if you are comfortable with an Obsidian guide that can ask the agent to run local commands. Prefer confirming every command manually, especially package installs, sudo commands, diagnostics, or any operation outside the vault folder.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a beginner Obsidian guide, but it also describes operational execution semantics such as structured inputs, processing, outputs, and use of exec-backed actions. This mismatch can cause an agent to perform system actions users would not reasonably expect from a note-taking tutorial, increasing the risk of unintended command or environment interaction.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill declares `allowed-tools: read exec` even though its stated purpose is beginner onboarding for Obsidian. Granting exec capability without clear necessity violates least privilege and could let the agent run local commands unrelated to the tutorial workflow if prompted or if the skill is invoked broadly.

Context-Inappropriate Capability

Low
Confidence
87% confidence
Finding
The troubleshooting section instructs running ping and network diagnostics, which extends the skill into host and network operations outside the expected scope of an Obsidian basics guide. Even simple diagnostics normalize unnecessary system interaction and can expose environment details or encourage broader command execution.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation/scope language claims broad capability coverage across many keywords and generic operational support, without clear trigger boundaries. In combination with tool-use capability, this can cause over-activation and execution in contexts beyond safe Obsidian onboarding, making misuse or accidental action more likely.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.