obsidian-bases

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest note metadata and frontmatter from an Obsidian vault to generate database views, filters, and formulas. This creates a surface where malicious instructions embedded in note properties could influence the agent's logic during the creation or modification of these files.
  • Ingestion points: The agent reads file.tags, file.properties, and specific frontmatter fields (e.g., author) from notes in the vault (SKILL.md).
  • Boundary markers: The instructions lack explicit boundary markers or warnings directing the agent to ignore instructions found within the vault data.
  • Capability inventory: The agent generates functional YAML configuration files that contain logical filters and arithmetic formulas.
  • Sanitization: No sanitization or validation process is defined for the agent to follow when interpolating vault data into the generated configuration files.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill facilitates the agent's access to local filesystem metadata within the Obsidian vault. It provides functions to retrieve full file paths (file.path), creation times (file.ctime), and all frontmatter properties (file.properties). This allows the agent to process and potentially expose the structure and metadata of the user's private notes.
  • [DYNAMIC_EXECUTION]: The skill's formula reference (FUNCTIONS_REFERENCE.md) documents an html() function that renders strings directly as HTML within the Obsidian user interface. This introduces a risk of Cross-Site Scripting (XSS) if the agent is directed to use this function to render unsanitized data retrieved from note properties.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — obsidian-bases