obsidian-cli
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill exposes an
evalcommand (obsidian eval code="...") that allows the execution of arbitrary JavaScript within the context of the running Obsidian application. This provides a direct path for running unsanitized code snippets. - [DATA_EXFILTRATION]: The
dev:screenshotcommand facilitates capturing the visual state of the user's workspace. If an agent is compromised, this could be used to exfiltrate sensitive information visible in the UI. - [INDIRECT_PROMPT_INJECTION]: The skill provides the ability to read and search vault content, which constitutes an ingestion surface for untrusted data. Malicious instructions stored within vault notes could potentially influence the agent to misuse its capabilities.
- Ingestion points: Vault file content retrieved via
obsidian readandobsidian searchcommands. - Boundary markers: The skill instructions do not specify the use of delimiters or instructions to ignore embedded prompts when reading vault data.
- Capability inventory: The skill possesses powerful capabilities including file modification (
create,append,property:set), screenshot capture (dev:screenshot), and arbitrary code execution (eval). - Sanitization: There is no mention of sanitizing or escaping the content read from the vault before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill relies on executing the
obsidianCLI tool via shell commands, which is the primary mechanism for vault interaction.
Audit Metadata