obsidian-bases
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill involves reading note frontmatter properties, tags, and file metadata to generate or update
.basefiles. This creates an ingestion surface where malicious instructions placed in note properties could attempt to influence the agent's logic during the configuration process. - Ingestion points: file.properties, file.tags, note frontmatter (processed in workflow step 2).
- Boundary markers: No specific boundary markers or instruction-ignoring delimiters are mandated for the agent when processing these properties.
- Capability inventory: Writing .base files, accessing vault files via
file(), and rendering HTML viahtml()functions. - Sanitization: While an
escapeHTML()function is documented in the reference, there are no instructions requiring the agent to apply it to external note data during view configuration. - [DYNAMIC_EXECUTION]: The skill uses a custom formula language for computing properties at runtime. This DSL includes functions like
html(string)for rendering arbitrary HTML andfile(path)for retrieving file objects. While these are core features of the Obsidian Bases tool, the dynamic evaluation of logic based on vault data represents a runtime execution surface.
Audit Metadata