obsidian-cli

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes an obsidian CLI tool to perform vault operations, including creating files, searching content, and managing plugin states.
  • [DYNAMIC_EXECUTION]: The obsidian eval command allows for the execution of arbitrary JavaScript code (code="...") within the running Obsidian application context. While intended for development, this allows for runtime code execution controlled by the agent's prompts.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the user's vault, creating a surface for indirect prompt injection if notes contain malicious instructions.
  • Ingestion points: obsidian read, obsidian search, obsidian dev:errors, and obsidian dev:console (SKILL.md).
  • Boundary markers: Absent. The instructions do not specify delimiters to separate vault content from agent instructions.
  • Capability inventory: The skill can write files (create, append), modify metadata (property:set), and execute JavaScript (eval) (SKILL.md).
  • Sanitization: Absent. There is no mention of filtering or sanitizing vault content before it is read by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — obsidian-cli