obsidian-vault
Warn
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The helper script
scripts/new_note.shis vulnerable to path traversal through the--titleargument. - For note types
source,wiki, andindex, the script constructs the output filename directly from the$TITLEvariable without sanitization or slugification. - Evidence in
scripts/new_note.sh(lines 92-108): Forsourceorwikitypes,FILENAME="${PREFIX} -- ${TITLE}.md". Forindextypes,FILENAME="${TITLE} Index.md"orFILENAME="${TITLE}.md". - The resulting path
OUT="$TARGET_DIR/$FILENAME"can be manipulated to point outside the intended vault directory if the--titlecontains traversal sequences like../../. - [DATA_EXFILTRATION]: The skill hardcodes a default local path (
/Users/ethanphan/Documents/my-obsidian-v1) inSKILL.mdandscripts/new_note.sh. This exposes the author's local username and file structure preferences, though it does not constitute a direct credential leak.
Audit Metadata