obsidian-cli

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates extensive interaction with the local file system and Obsidian application environment via the obsidian CLI tool. It provides capabilities to create, read, modify, and delete notes and properties.
  • [DYNAMIC_EXECUTION]: The skill exposes the obsidian eval code="..." command, which allows for the execution of arbitrary JavaScript code directly within the Obsidian application context. This is a significant security risk as it provides a direct bridge for the agent to execute unvalidated code provided in its instructions or inferred from processed data.
  • [INDIRECT_PROMPT_INJECTION]: The skill features multiple ingestion points for untrusted data through commands like obsidian read, obsidian search, and obsidian backlinks.
  • Ingestion points: Vault files accessed via read, search, tasks, and backlinks commands.
  • Boundary markers: None identified in the provided instructions; external content is likely processed directly into the agent's context.
  • Capability inventory: Includes file writing (create, append), file reading (read), and arbitrary code execution (eval).
  • Sanitization: There are no explicit instructions for the agent to sanitize or ignore malicious instructions embedded within the vault files it reads.
  • [EXTERNAL_DOWNLOADS]: The skill references official Obsidian documentation (https://help.obsidian.md/cli). This is a reference to a well-known service for documentation purposes.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — obsidian-cli