Obsidian Automation
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines workflows that ingest untrusted data from external sources, which could contain malicious instructions designed to influence the agent's behavior during note creation or summarization.
- Ingestion points: The
web_clipperfunctionality ingests{{selection}}from browser pages, and theresearch_workflowprocesses data fromgather_sourcesbased on a user-provided{{topic}}. - Boundary markers: The YAML-based note templates do not include clear delimiters or "ignore instructions" markers to separate untrusted external content from the agent's primary instructions.
- Capability inventory: The skill utilizes
notes-mcptools, specificallyobsidian_create_note,obsidian_search, andobsidian_link, allowing the agent to write to and modify the user's local knowledge base. - Sanitization: There are no explicit sanitization or filtering steps defined to process the ingested web content before it is used to generate or populate notes.
Audit Metadata