obsidian-cli

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill exposes an eval command (obsidian eval code="...") that allows the execution of arbitrary JavaScript within the context of the running Obsidian application. This provides a direct path for running unsanitized code snippets.
  • [DATA_EXFILTRATION]: The dev:screenshot command facilitates capturing the visual state of the user's workspace. If an agent is compromised, this could be used to exfiltrate sensitive information visible in the UI.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides the ability to read and search vault content, which constitutes an ingestion surface for untrusted data. Malicious instructions stored within vault notes could potentially influence the agent to misuse its capabilities.
  • Ingestion points: Vault file content retrieved via obsidian read and obsidian search commands.
  • Boundary markers: The skill instructions do not specify the use of delimiters or instructions to ignore embedded prompts when reading vault data.
  • Capability inventory: The skill possesses powerful capabilities including file modification (create, append, property:set), screenshot capture (dev:screenshot), and arbitrary code execution (eval).
  • Sanitization: There is no mention of sanitizing or escaping the content read from the vault before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill relies on executing the obsidian CLI tool via shell commands, which is the primary mechanism for vault interaction.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — obsidian-cli