obsidian-bases
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest note metadata and frontmatter from an Obsidian vault to generate database views, filters, and formulas. This creates a surface where malicious instructions embedded in note properties could influence the agent's logic during the creation or modification of these files.
- Ingestion points: The agent reads
file.tags,file.properties, and specific frontmatter fields (e.g.,author) from notes in the vault (SKILL.md). - Boundary markers: The instructions lack explicit boundary markers or warnings directing the agent to ignore instructions found within the vault data.
- Capability inventory: The agent generates functional YAML configuration files that contain logical filters and arithmetic formulas.
- Sanitization: No sanitization or validation process is defined for the agent to follow when interpolating vault data into the generated configuration files.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill facilitates the agent's access to local filesystem metadata within the Obsidian vault. It provides functions to retrieve full file paths (
file.path), creation times (file.ctime), and all frontmatter properties (file.properties). This allows the agent to process and potentially expose the structure and metadata of the user's private notes. - [DYNAMIC_EXECUTION]: The skill's formula reference (FUNCTIONS_REFERENCE.md) documents an
html()function that renders strings directly as HTML within the Obsidian user interface. This introduces a risk of Cross-Site Scripting (XSS) if the agent is directed to use this function to render unsanitized data retrieved from note properties.
Audit Metadata