obsidian-vault

Warn

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/new_note.sh is vulnerable to path traversal through the --title argument.
  • For note types source, wiki, and index, the script constructs the output filename directly from the $TITLE variable without sanitization or slugification.
  • Evidence in scripts/new_note.sh (lines 92-108): For source or wiki types, FILENAME="${PREFIX} -- ${TITLE}.md". For index types, FILENAME="${TITLE} Index.md" or FILENAME="${TITLE}.md".
  • The resulting path OUT="$TARGET_DIR/$FILENAME" can be manipulated to point outside the intended vault directory if the --title contains traversal sequences like ../../.
  • [DATA_EXFILTRATION]: The skill hardcodes a default local path (/Users/ethanphan/Documents/my-obsidian-v1) in SKILL.md and scripts/new_note.sh. This exposes the author's local username and file structure preferences, though it does not constitute a direct credential leak.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 01:51 PM
Security Audit — agent-trust-hub — obsidian-vault