Back to skill

Security audit

知识库大师

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Obsidian vault management skill that can modify or delete local notes and attachments, so it should be used carefully but does not show hidden or malicious behavior.

Install only if you want an agent to manage local Obsidian vault files. Before move, rename, delete, or orphan-cleanup operations, preview paths, keep a backup or Git history, and require explicit confirmation for any real deletion.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger keywords are broad terms like "obsidian", "笔记", "移动", and "重命名", which are common in benign conversations and can cause the skill to activate outside the user's intended scope. In an exec-capable skill that can move or delete local files, unintended activation increases the chance of unauthorized or surprising filesystem actions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill includes destructive commands for deleting notes and orphan attachments, including examples that progress from dry-run to real deletion, but it does not enforce a consistent confirmation or safety interlock before irreversible actions. Because the skill has exec access and operates on local vault files, a mistaken interpretation, false orphan classification, or accidental trigger could lead to permanent data loss.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.