obsidian-cli
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documentation includes an
evalcommand (obsidian eval code="...") which allows the execution of arbitrary JavaScript within the context of the running Obsidian application. This capability can be leveraged to execute complex logic, modify app state, or interact with the underlying system through the Obsidian API. - [DATA_EXFILTRATION]: Several developer commands provide direct access to potentially sensitive information within the application environment, including
obsidian dev:screenshot(visual capture of the workspace),obsidian dev:dom(inspection of UI elements which may contain note text), andobsidian dev:console(reading application logs which might leak internal data or plugin information). - [INDIRECT_PROMPT_INJECTION]: The skill possesses a high-risk attack surface for indirect prompt injection due to its combined capabilities:
- Ingestion points: The skill reads untrusted data from the user's vault using
obsidian read,obsidian search, andobsidian daily:readinSKILL.md. - Boundary markers: No boundary markers or instructions are provided to distinguish between legitimate note content and embedded malicious instructions.
- Capability inventory: The skill allows for high-impact actions including arbitrary JavaScript execution (
obsidian eval), file modification (obsidian append,obsidian property:set), and data exposure (dev:screenshot,dev:dom). - Sanitization: There is no evidence of sanitization or validation of the data retrieved from the vault before it is used to inform subsequent actions or command arguments.
Audit Metadata