Back to skill

Security audit

Obsidian

Security checks for vulnerabilities and agentic risk

Overview

This skill gives an agent Obsidian note-management guidance that is coherent with its stated purpose, with ordinary caution needed for commands that change or delete notes.

Before installing, remember that this skill can guide an agent to read and modify your Obsidian vault. Use it with a vault you trust, verify the selected vault path, and require explicit confirmation before move, rename, delete, or bulk-edit actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly documents destructive and state-changing operations such as create, move, and delete against an Obsidian vault, but it does not include safeguards like confirmation requirements, backup guidance, scope restrictions, or a warning that these commands modify user data. In an agent context with exec capability, this increases the chance of unintended data loss or unsafe automation, especially if the model acts on ambiguous user requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document is primarily written in English, but the core capability and usage-description sections are presented in Chinese with no opt-in or explanation. This can impose a language expectation on users and conflicts with the requirement to avoid forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.