Back to skill

Security audit

Plugin Orchestration Protocol

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a coherent Obsidian automation guide, but it asks for broad vault, environment, external API, and bridge authority without enough authentication, scoping, or user-confirmation controls.

Install only if you are comfortable giving the bridge broad control over an Obsidian vault. Before use, require authentication enforcement, an environment-variable allowlist, explicit approval before delete/export/external-AI/template steps, pinned and verified host dependencies, and clear handling/redaction rules for ATOM tokens and vault content.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/protocol-spec.md:47
Finding

Unrestricted Environment-Variable Expansion in Pipeline Parameters

Content
View full analysis

Vulnerability Details

File Location: references/protocol-spec.md, lines 47-51
Vulnerability Type: Arbitrary environment-variable access
Risk Level: High

Vulnerable Code

markdown
## Variable Reference Syntax

Steps can reference outputs from previous steps:

- `$step_id.output.field` — Access a specific field from a step's output
- `$step_id.output` — Access the entire output object
- `$step_id.wave_score` — Access the WAVE score from a step
- `$ENV_VAR` — Access environment variables (prefixed with no dot)

Technical Analysis

The protocol permits pipeline parameters to reference arbitrary process environment variables. No variable allowlist, secret-name filtering, authorization check, or user-confirmation boundary is specified.

Environment variables commonly contain API keys, access tokens, signing secrets, cloud credentials, database connection strings, and private paths. Generic environment access exceeds the minimum privileges needed for ordinary Obsidian note orchestration.

Because resolved parameters can be consumed by actions such as create_note, ai_expand, wave_check, and template execution, a secret may be written into the vault, submitted to an AI provider, included in pipeline output, or forwarded through progress telemetry.

Attack Path

  1. An attacker or compromised local bridge client submits an EXECUTE_PIPELINE request.
  2. An action parameter references a sensitive variable, such as an API-key environment variable.
  3. The pipeline resolver substitutes the environment variable's value.
  4. The substituted value is passed to a note, AI, template, or telemetry-producing action.
  5. The attacker recovers the secret from vault content, action output, logs, or pipeline notifications.

Impact Assessment

Successful exploitation can disclose any environment variable visible to the bridge process. The resulting scope depends on the process environment and may ...[truncated 183 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove generic $ENV_VAR expansion from remotely supplied pipelines.
  • If environment substitution is essential, use an explicit allowlist of non-sensitive variables configured by the vault owner.
  • Reject variable names associated with secrets, tokens, credentials, keys, passwords, cookies, and connection strings.
  • Require explicit user approval before resolving each allowed variable.
  • Resolve variables only after authentication and action-level authorization.
  • Mark resolved secrets as sensitive and prevent them from entering notes, logs, telemetry, error messages, or AI-provider requests.
  • Run the bridge with a minimal sanitized environment and retrieve necessary secrets from a scoped secret manager.
  • Add tests proving that unknown and sensitive variable references are rejected.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/protocol-spec.md:148
Finding

Privileged WebSocket Requests Are Dispatched Without Authentication or Authorization

Content
View full analysis

Vulnerability Details

File Location: references/protocol-spec.md, lines 148-169
Vulnerability Type: Missing authentication, authorization, validation, and replay protection
Risk Level: High

Vulnerable Code

typescript
this.ws.onmessage = (event) => {
  const msg = JSON.parse(event.data);
  this.handleMessage(msg);
};

this.ws.onclose = () => {
  console.log('POP: Disconnected, reconnecting in 5s...');
  setTimeout(() => this.startWebSocketServer(), 5000);
};
}

private async handleMessage(msg: any) {
  switch (msg.method) {
    case 'EXECUTE_PIPELINE':
      await this.executePipeline(msg.params, msg.id);
      break;
    case 'CANCEL_PIPELINE':
      this.cancelPipeline(msg.params.pipeline_id);
      break;
    case 'GET_PIPELINE_STATUS':
      this.sendPipelineStatus(msg.params.pipeline_id, msg.id);
      break;
  }
}

Technical Analysis

The documented TypeScript handler parses untrusted WebSocket data and dispatches privileged methods without first validating the claimed ATOM token. It does not verify an HMAC signature, timestamp freshness, session binding, nonce, request identity, permitted method, or action-level permissions. It also uses any and does not validate the JSON-RPC schema or parameter types.

This contradicts the protocol's authentication claim and is particularly dangerous because the documented action catalog includes reading, updating, deleting, searching, and exporting vault data, as well as invoking templates and AI integrations.

Although the included implementation is a stub, it is presented as the implementation model. Implementing the documented handler as shown would establish an unauthenticated privileged command channel.

Attack Path

  1. An attacker gains access to the local WebSocket bridge, compromises another local process, or causes the bridge to relay a crafted message.
  2. The attacker sends a forged JSON-RPC `EXECUTE_PI ...[truncated 967 chars]
Remediation
View remediation

Remediation Suggestions

  • Authenticate every message before method dispatch.
  • Verify the ATOM token's HMAC using constant-time comparison.
  • Validate token timestamps, session binding, agent identity, intended method, and coherence constraints.
  • Introduce cryptographically random nonces and maintain a replay cache for used tokens and request IDs.
  • Apply strict JSON-RPC and per-method schemas; reject unknown fields, invalid types, oversized messages, and unsupported methods.
  • Enforce action-level authorization rather than treating possession of one token as permission for every vault operation.
  • Require interactive confirmation for destructive or high-impact operations such as deletion, export, external AI submission, and template execution.
  • Restrict the bridge to an authenticated local endpoint and reject unexpected peers.
  • Add rate limits, message-size limits, audit logging with secret redaction, and fail-closed error handling.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:44
Finding

Authentication Token Is Transmitted over an Unencrypted WebSocket

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 44-57; transport documented at lines 15-18 and 133-138
Vulnerability Type: Plaintext transmission of authentication material
Risk Level: Medium

Vulnerable Code

json
{
  "jsonrpc": "2.0",
  "method": "EXECUTE_PIPELINE",
  "params": {
    "pipeline": "idea-to-publish",
    "steps": [
      {"id": "spark", "action": "create_note", "params": {"title": "...", "content": "..."}},
      {"id": "expand", "action": "ai_expand", "params": {"note_id": "$spark.output.id"}},
      {"id": "visual", "action": "generate_figure", "params": {"note_id": "$expand.output.id"}},
      {"id": "verify", "action": "wave_check", "params": {"content": "$expand.output.content"}},
      {"id": "assemble", "action": "merge_notes", "params": {"ids": ["$spark", "$expand", "$visual"]}},
      {"id": "export", "action": "export_pdf", "params": {"note_id": "$assemble.output.id"}}
    ],
    "coherence_threshold": 0.85,
    "atom_token": "$ATOM_TOKEN_RESONANCE"
  },
  "id": 2
}

The same file defines the transport as:

text
via JSON-RPC over WebSocket at ws://127.0.0.1:8088.

Technical Analysis

The protocol includes an authentication token in an EXECUTE_PIPELINE message sent over plaintext ws://. Loopback binding reduces exposure to remote network observers, but it does not provide confidentiality or peer authentication.

A hostile local process, debugging proxy, compromised bridge, or accidentally non-loopback-bound service may observe the token. The documented token contains session and agent identity information and an HMAC signature. No complete single-use-token or replay-defense mechanism is shown.

Sending authentication material is necessary for authentication, but sending it over an unauthenticated plaintext transport is not the least-privilege or minimum-exposure design.

Attack Path

  1. An attacker gains the ability to ...[truncated 741 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer an authenticated operating-system local IPC mechanism with filesystem or process-level access controls.
  • If WebSocket transport is required, use wss:// with certificate or mutually authenticated TLS validation.
  • Bind the server strictly to 127.0.0.1 and verify at runtime that it is not exposed on external interfaces.
  • Use short-lived, method-bound, audience-bound, single-use tokens.
  • Include a nonce and narrow expiration window, and reject all replayed tokens.
  • Avoid transmitting a reusable shared secret; use challenge-response authentication or derived session credentials.
  • Redact tokens from logs, error messages, telemetry, crash reports, and monitoring interfaces.
  • Rotate credentials immediately after suspected bridge or local-host compromise.

T08 · Insecure Dependencies

Warning
Location
references/plugin-catalog.md:45
Finding

Unpinned Third-Party Package Installation on the Bridge Host

Content
View full analysis

Vulnerability Details

File Location: references/plugin-catalog.md, lines 45-49
Vulnerability Type: Unverified and mutable software dependency
Risk Level: Medium

Vulnerable Code

markdown
### Figure Generation — `generate_figure`
**Plugin:** AutoFigure (external tool repo) via POP bridge
**Requires:** `pip install autofigure` on the bridge host
**Action params:**

Technical Analysis

The installation instruction resolves the current package named autofigure from the installer's configured Python package index. It does not pin a version, require hashes, identify a verified publisher, provide a lock file, or specify an audited source repository.

Python packages may execute code during build or installation, and their runtime code executes when imported or invoked. The effective dependency can therefore change after this Skill has been reviewed. Name ambiguity also creates dependency-confusion or typosquatting risk if the intended external repository and package-index identity do not correspond.

Attack Path

  1. A user follows the documented pip install autofigure instruction.
  2. pip resolves the package from its configured package index or mirror.
  3. A compromised, replaced, or unintended package version is downloaded.
  4. Package build hooks or installation logic execute on the bridge host, or malicious code executes when figure generation is invoked.
  5. The package accesses files, environment credentials, vault data, or network resources with the installer or bridge process's privileges.

Impact Assessment

A malicious dependency may obtain code execution with the privileges used to install or run the bridge. This may expose the Obsidian vault, process credentials, API keys, local files, and network-accessible services. If installation is performed with elevated privileges, the compromise scope may extend beyond the project environment.

Remediation
View remediation

Remediation Suggestions

  • Verify the package's official publisher, repository, and package-index identity.
  • Pin an audited exact version rather than installing the latest mutable release.
  • Require cryptographic hashes using a locked requirements file and hash-checking mode.
  • Record and review transitive dependencies.
  • Install the package in a dedicated, non-privileged virtual environment or isolated container.
  • Disable unnecessary network and filesystem access for figure generation.
  • Use a trusted internal mirror after malware and provenance scanning.
  • Document reproducible installation and update procedures, including security review before version changes.
  • Avoid invoking pip with administrator or root privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

ai_expand is presented as a note-expansion feature, but the catalog does not prominently warn that note content may be sent to an external API when no local plugin is installed. In this Obsidian knowledge-pipeline context, notes may contain sensitive research, personal data, or unpublished material, so undisclosed external transmission creates a significant confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes a protocol that can execute multi-step pipelines against an Obsidian vault, including creating notes, merging content, and exporting PDFs, but it does not warn that these actions can modify local data and exfiltrate content through exports or plugin actions. In a skill intended for orchestration over a local WebSocket bridge, omission of a user-facing warning increases the chance of unsafe execution without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The authentication section introduces an ATOM token used on all POP messages but provides no handling guidance for secrets, such as avoiding logging, redaction in telemetry, secure storage, or rotation. Because the protocol also forwards telemetry across multiple components, careless credential handling could expose tokens and allow unauthorized pipeline execution or session impersonation on the local bridge.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template advertises PDF export and publication-style workflow outcomes without clearly warning that running it will create derivative content and persist an exported artifact in the vault. In an orchestration skill, silent side effects matter because users may trigger multi-step automation expecting analysis only, leading to unintended document creation or disclosure of sensitive notes into exportable outputs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes this skill as an Obsidian integration for plugin orchestration, websocket bridge workflows, and note-to-paper style knowledge pipelines. The 'quantum-circuit' template instead generates Minecraft .mcfunction/redstone content, a distinct domain that is not an obvious implementation detail of Obsidian orchestration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The purpose text and JSON description say the pipeline will publish a blog post to a platform using ATOM authentication. However, the final 'publish' step is only a 'create_note' action writing content to the 'Published' folder, with no publishing or authentication behavior shown.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Resonance Cascade template describes generating and 'publishing' content into a Published folder without a prominent warning that new generated material will be stored under a publication-oriented location. Given this skill's orchestration context, generated summaries may incorporate sensitive vault material, so silent placement into a publish-designated area increases the chance of accidental downstream sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The paper-draft pipeline generates submission-ready academic content and exports a PDF, but the template does not clearly warn about these substantial side effects or the risk of producing authoritative-looking artifacts from vault data. In this context, users could unintentionally create sharable research outputs containing sensitive, inaccurate, or unreviewed material.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file states the manifest is filtered to installed plugins, but several actions are described as always available despite depending on an external bridge, local service, or optional binaries. This mismatch can cause callers to over-trust availability and safety guarantees, leading them to invoke operations that rely on undeclared components or expanded privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The catalog exposes destructive and state-modifying actions such as update_note and delete_note without any warning, confirmation, or safe-use guidance. In an orchestration skill, where actions may be chained or triggered automatically, missing confirmation expectations increases the chance of unintended data loss or silent modification of vault content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The catalog explicitly documents that ai_expand can fall back to a direct Claude API call and that generate_figure can invoke a host-side package, which expands the trust boundary beyond Obsidian plugin orchestration into external network and host execution behavior. In this skill context, that is dangerous because users may expect a constrained in-vault plugin action, while note content could be transmitted externally or processed by software installed on the bridge host without prominent disclosure or gating.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The protocol text says the transport is a WebSocket server at ws://127.0.0.1:8088, while the stub says the Obsidian plugin connects out as a client to a Rust bridge server. This mismatch can cause implementers to build the wrong trust boundary and expose a local control channel in an unsafe way, increasing the chance of unauthorized local process interaction or accidental network exposure during real implementation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The specification declares ATOM token authentication, but the provided plugin stub accepts messages and dispatches EXECUTE_PIPELINE, CANCEL_PIPELINE, and GET_PIPELINE_STATUS without any token validation. In this skill context, that means any process able to talk to the local bridge channel could potentially trigger note reads, writes, deletions, exports, or templated execution without authentication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The variable reference syntax permits direct access to $ENV_VAR values but gives no restrictions on which variables may be accessed or how secrets are protected. In a pipeline orchestration context that also supports exports, templating, and AI expansion, this can enable credential exfiltration, accidental secret insertion into notes, or leakage through downstream actions and logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented action set includes destructive operations such as update_note, delete_note, merge_notes, export, and linking/tagging workflows, but the spec provides no warning, confirmation model, or permission boundaries. In an orchestration skill designed for automated multi-step execution, omission of safety constraints materially increases the risk of silent data loss, unintended vault modification, or bulk destructive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The research-digest pipeline performs write operations by creating a digest note and tagging content, but the documentation does not clearly warn users about those modifications. In Obsidian automation, even low-risk vault mutations can have privacy, organization, and workflow consequences if they happen without clear user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The export_pdf and export_docx entries return file paths and sizes, indicating that new output files are created, but the markdown does not mention that these actions write documents to disk. For markdown skill descriptions, file-creating behavior that affects user data or workspace state should be disclosed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The compliance section makes universal claims about runtime behavior for all content-producing and mutating actions. However, earlier action definitions such as create_note, update_note, merge_notes, run_templater, and export actions do not consistently include WAVE score or ATOM trail information in their documented returns, creating a documentation-level contradiction about what the system actually provides.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.