obsidian-cli
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes an
obsidianCLI tool to perform vault operations, including creating files, searching content, and managing plugin states. - [DYNAMIC_EXECUTION]: The
obsidian evalcommand allows for the execution of arbitrary JavaScript code (code="...") within the running Obsidian application context. While intended for development, this allows for runtime code execution controlled by the agent's prompts. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from the user's vault, creating a surface for indirect prompt injection if notes contain malicious instructions.
- Ingestion points:
obsidian read,obsidian search,obsidian dev:errors, andobsidian dev:console(SKILL.md). - Boundary markers: Absent. The instructions do not specify delimiters to separate vault content from agent instructions.
- Capability inventory: The skill can write files (
create,append), modify metadata (property:set), and execute JavaScript (eval) (SKILL.md). - Sanitization: Absent. There is no mention of filtering or sanitizing vault content before it is read by the agent.
Audit Metadata