obsidian-bases

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-controlled metadata and frontmatter from Obsidian notes, establishing an ingestion surface for untrusted data. * Ingestion points: SKILL.md documents functions to query note properties (file.properties) and metadata (file.path, file.tags). * Capability inventory: references/FUNCTIONS_REFERENCE.md lists powerful functions for logic, list processing (map, reduce), and UI rendering (html, image). * Boundary markers: No specific delimiters are provided to separate schema instructions from the ingested note data. * Sanitization: The presence of the html() function allows for rendering strings as HTML without mandatory sanitization, although escapeHTML() is available as a utility.
  • [DYNAMIC_EXECUTION]: The skill defines a domain-specific language for formulas that are evaluated at runtime to process note data and configure views. * The html(string) function provides a mechanism to render arbitrary strings as HTML content, which can be exploited if the input strings include note properties containing malicious scripts. * The formula engine supports complex transformations and functional programming patterns like map and reduce, expanding the potential impact of processed untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — obsidian-bases