obsidian-bases
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for creating dynamic views that ingest data from external sources within an Obsidian vault, such as note frontmatter, tags, and file properties. This constitutes a vulnerability surface where untrusted content in a user's notes could be processed by the described formulas. The skill mitigates this risk by documenting the
escapeHTML()function for sanitization. - [NO_CODE]: The skill consists entirely of Markdown documentation, YAML schema definitions, and usage examples. There are no executable scripts (Python, Node.js), shell commands, or binary files included in the skill package.
Audit Metadata