obsidian-vault-audit-framework

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill is composed of instructional markdown and local Dataview Query Language (DQL) examples for vault maintenance.\n- [DATA_EXPOSURE]: The skill analyzes metadata internal to the Obsidian vault (frontmatter, tags, and link structures) but does not include any tools or commands for transmitting this data to external services.\n- [COMMAND_EXECUTION]: The audit methodology relies entirely on built-in Obsidian search operators and the Dataview plugin. No shell commands, subprocesses, or administrative privileges are requested.\n- [INDIRECT_PROMPT_INJECTION]: Although the skill processes data from a user's vault, it has no exploitable capabilities such as network access or file-system writing, rendering the surface for indirect prompt injection functionally inert.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 03:58 PM
Security Audit — agent-trust-hub — obsidian-vault-audit-framework