Back to skill

Security audit

知识库同步引擎

Security checks for vulnerabilities and agentic risk

Overview

This Obsidian sync skill is mostly coherent, but it asks agents to run broad Git sync commands and create a recurring scheduled script that can repeatedly push private vault contents and later execute remotely changed code.

Review carefully before installing. Use this only for an Obsidian vault you intend to version-control, inspect staged files before every commit, add sensitive .obsidian plugin configuration exclusions before the first git add, and do not schedule a sync script from inside a Git-synchronized vault. Prefer an explicit, locally stored script outside the vault with clear logs, removal steps, and manual approval before publishing private notes.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:119
Finding

Scheduled execution of remotely mutable repository code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:82
Finding

Broad Git staging can publish sensitive Obsidian plugin configuration

Content
View full analysis
git init cat > .gitignore <<'EOF' .obsidian/workspace.json .obsidian/workspace-mobile.json .obsidian/cache .trash/ *.tmp .DS_Store EOF git add . ``` The recurring workflow repeats the same broad operation: ```bash git add . git commit -m "docs: update " git push ``` The document later identifies the following plugin configuration as something that should be excluded, but it is absent from the initial ignore template: ```text .obsidian/plugins/local-rest-api/data.json ``` ### Technical Analysis `git add .` stages every unignored file beneath the vault. The supplied initial `.gitignore` excludes workspace state, cache data, temporary files, and operating-system metadata, but it does not exclude plugin configuration by default. The document itself recognizes that plugin `data.json` files can contain device-specific or sensitive configuration and specifically identifies the Local REST API plugin configuration for exclusion. However, that exclusion is not incorporated into the initialization template before the first `git add .`. As a result, an existing vault can commit such configuration during repository initialization, and later synchronization runs can commit newly created sensitive files. Once a secret enters Git history, adding it to `.gitignore` does not remove it from prior commits. Pushing the repository may expose the data to repository administrators, collaborators, automated integrations, compromised accounts, or unintended public access. ### Attack Path 1. An Obsidian plugin writes a token, endpoint, password, local path, or other sensitive value into its configuration under `.obsidian/plugins/`. 2. The configuration path is not covered by the initial `.gitignore`. 3. The user or Agent runs `git add .`. 4. Git stages the ...[truncated 1028 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 316)May include surrounding context.

md
| LLM API | API | 必需 | 由 Agent 内置 LLM 提供 |

### API Key 配置
- Git 远程仓库认证(SSH key 或 Personal Access Token)
- Obsidian Sync 订阅账号(若使用付费方案)
- 无需第三方 API Key

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The listed trigger keywords include very generic terms such as "sync", "同步", and "git", which commonly appear in ordinary user requests outside the narrow scope of this skill. The description does not provide constraints, exclusion conditions, or negative examples to clarify when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill includes exec-driven Git operations that modify local repositories and can transmit vault contents to remote repositories, but it does not consistently require explicit user confirmation or warn about side effects before push/pull/merge actions. In an agent environment with exec enabled, this can lead to unintended repository mutation, sync of sensitive notes, or conflict-resolution actions affecting user data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill metadata and description are written in Chinese, and the file does not indicate that this is a region-specific skill or provide an opt-in language choice. Under the stated policy, forcing a specific language without user choice can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.