obsidian-bases

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves reading note frontmatter properties, tags, and file metadata to generate or update .base files. This creates an ingestion surface where malicious instructions placed in note properties could attempt to influence the agent's logic during the configuration process.
  • Ingestion points: file.properties, file.tags, note frontmatter (processed in workflow step 2).
  • Boundary markers: No specific boundary markers or instruction-ignoring delimiters are mandated for the agent when processing these properties.
  • Capability inventory: Writing .base files, accessing vault files via file(), and rendering HTML via html() functions.
  • Sanitization: While an escapeHTML() function is documented in the reference, there are no instructions requiring the agent to apply it to external note data during view configuration.
  • [DYNAMIC_EXECUTION]: The skill uses a custom formula language for computing properties at runtime. This DSL includes functions like html(string) for rendering arbitrary HTML and file(path) for retrieving file objects. While these are core features of the Obsidian Bases tool, the dynamic evaluation of logic based on vault data represents a runtime execution surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — obsidian-bases