obsidian-markdown
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of reference materials and formatting rules for Obsidian notes. It does not include any scripts, tools, or automated command execution patterns.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation and editing of markdown files, which involves ingesting user-provided text and referencing other notes via wikilinks and embeds. This creates an inherent surface for indirect prompt injection where instructions could be embedded in note content.
- Ingestion points: User input and note files within an Obsidian vault referenced via wikilinks and embeds (SKILL.md, references/EMBEDS.md).
- Boundary markers: Absent; the skill defines how to structure content but not how to isolate untrusted data.
- Capability inventory: File system read and write operations required to manage notes.
- Sanitization: Absent; the skill focus is on formatting syntax rather than input validation.
Audit Metadata