obsidian-bases
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-controlled metadata and frontmatter from Obsidian notes, establishing an ingestion surface for untrusted data. * Ingestion points:
SKILL.mddocuments functions to query note properties (file.properties) and metadata (file.path,file.tags). * Capability inventory:references/FUNCTIONS_REFERENCE.mdlists powerful functions for logic, list processing (map,reduce), and UI rendering (html,image). * Boundary markers: No specific delimiters are provided to separate schema instructions from the ingested note data. * Sanitization: The presence of thehtml()function allows for rendering strings as HTML without mandatory sanitization, althoughescapeHTML()is available as a utility. - [DYNAMIC_EXECUTION]: The skill defines a domain-specific language for formulas that are evaluated at runtime to process note data and configure views. * The
html(string)function provides a mechanism to render arbitrary strings as HTML content, which can be exploited if the input strings include note properties containing malicious scripts. * The formula engine supports complex transformations and functional programming patterns likemapandreduce, expanding the potential impact of processed untrusted data.
Audit Metadata