obsidian-markdown

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of reference materials and formatting rules for Obsidian notes. It does not include any scripts, tools, or automated command execution patterns.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation and editing of markdown files, which involves ingesting user-provided text and referencing other notes via wikilinks and embeds. This creates an inherent surface for indirect prompt injection where instructions could be embedded in note content.
  • Ingestion points: User input and note files within an Obsidian vault referenced via wikilinks and embeds (SKILL.md, references/EMBEDS.md).
  • Boundary markers: Absent; the skill defines how to structure content but not how to isolate untrusted data.
  • Capability inventory: File system read and write operations required to manage notes.
  • Sanitization: Absent; the skill focus is on formatting syntax rather than input validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — obsidian-markdown