T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:119- Finding
Scheduled execution of remotely mutable repository code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Obsidian sync skill is mostly coherent, but it asks agents to run broad Git sync commands and create a recurring scheduled script that can repeatedly push private vault contents and later execute remotely changed code.
Review carefully before installing. Use this only for an Obsidian vault you intend to version-control, inspect staged files before every commit, add sensitive .obsidian plugin configuration exclusions before the first git add, and do not schedule a sync script from inside a Git-synchronized vault. Prefer an explicit, locally stored script outside the vault with clear logs, removal steps, and manual approval before publishing private notes.
SKILL.md:119Scheduled execution of remotely mutable repository code
SKILL.md:82Broad Git staging can publish sensitive Obsidian plugin configuration
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| LLM API | API | 必需 | 由 Agent 内置 LLM 提供 |
### API Key 配置
- Git 远程仓库认证(SSH key 或 Personal Access Token)
- Obsidian Sync 订阅账号(若使用付费方案)
- 无需第三方 API Key
The listed trigger keywords include very generic terms such as "sync", "同步", and "git", which commonly appear in ordinary user requests outside the narrow scope of this skill. The description does not provide constraints, exclusion conditions, or negative examples to clarify when the skill should or should not activate.
The skill includes exec-driven Git operations that modify local repositories and can transmit vault contents to remote repositories, but it does not consistently require explicit user confirmation or warn about side effects before push/pull/merge actions. In an agent environment with exec enabled, this can lead to unintended repository mutation, sync of sensitive notes, or conflict-resolution actions affecting user data.
The skill metadata and description are written in Chinese, and the file does not indicate that this is a region-specific skill or provide an opt-in language choice. Under the stated policy, forcing a specific language without user choice can be a natural-language policy issue.
No suspicious patterns detected.