jb-obsidian-sync
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The runtime workflow ingests and edits note text from an Obsidian Sync vault by searching and reading Markdown files under the explicitly resolved
VAULT_PATH(which can include outsider-authored note content), via filesystem search/read steps likerg ... "$VAULT_PATH"and subsequent “Inspect the target notes” before writing and syncing.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata