update-index
Warn
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The Bash script in
SKILL.mdis vulnerable to path traversal. It uses the$ARGUMENTSvariable directly to construct theWIKI_PATHwithout sanitizing for directory traversal sequences like../. This allows an attacker to force the script to read files outside the intended Obsidian vault. - [DATA_EXFILTRATION]: The script reads the contents of files specified via
$ARGUMENTS. If a user is tricked into providing a path to a sensitive file (e.g.,../../.ssh/config), the script will attempt to parse it for tags, potentially exposing the existence or structure of sensitive local data in the error logs or resulting index updates. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It parses the
tagsfield from a note's frontmatter to determine which index files to modify. If a note contains a maliciously crafted tag such as../../etc/cron.d/malicious, the script may attempt to write content to that path during the index update process. - [CREDENTIALS_UNSAFE]: The script contains a hardcoded local filesystem path:
/Users/ethanphan/Documents/my-obsidian-v1. While not a credential, this exposes the user's local username and internal directory structure, which can be used to facilitate more targeted attacks.
Audit Metadata