skills/ethan-rio/skills/obsidian-cli/Gen Agent Trust Hub

obsidian-cli

Warn

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documentation includes an eval command (obsidian eval code="...") which allows the execution of arbitrary JavaScript within the context of the running Obsidian application. This capability can be leveraged to execute complex logic, modify app state, or interact with the underlying system through the Obsidian API.
  • [DATA_EXFILTRATION]: Several developer commands provide direct access to potentially sensitive information within the application environment, including obsidian dev:screenshot (visual capture of the workspace), obsidian dev:dom (inspection of UI elements which may contain note text), and obsidian dev:console (reading application logs which might leak internal data or plugin information).
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a high-risk attack surface for indirect prompt injection due to its combined capabilities:
  • Ingestion points: The skill reads untrusted data from the user's vault using obsidian read, obsidian search, and obsidian daily:read in SKILL.md.
  • Boundary markers: No boundary markers or instructions are provided to distinguish between legitimate note content and embedded malicious instructions.
  • Capability inventory: The skill allows for high-impact actions including arbitrary JavaScript execution (obsidian eval), file modification (obsidian append, obsidian property:set), and data exposure (dev:screenshot, dev:dom).
  • Sanitization: There is no evidence of sanitization or validation of the data retrieved from the vault before it is used to inform subsequent actions or command arguments.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — obsidian-cli