obsidian-cli
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates extensive interaction with the local file system and Obsidian application environment via the
obsidianCLI tool. It provides capabilities to create, read, modify, and delete notes and properties. - [DYNAMIC_EXECUTION]: The skill exposes the
obsidian eval code="..."command, which allows for the execution of arbitrary JavaScript code directly within the Obsidian application context. This is a significant security risk as it provides a direct bridge for the agent to execute unvalidated code provided in its instructions or inferred from processed data. - [INDIRECT_PROMPT_INJECTION]: The skill features multiple ingestion points for untrusted data through commands like
obsidian read,obsidian search, andobsidian backlinks. - Ingestion points: Vault files accessed via
read,search,tasks, andbacklinkscommands. - Boundary markers: None identified in the provided instructions; external content is likely processed directly into the agent's context.
- Capability inventory: Includes file writing (
create,append), file reading (read), and arbitrary code execution (eval). - Sanitization: There are no explicit instructions for the agent to sanitize or ignore malicious instructions embedded within the vault files it reads.
- [EXTERNAL_DOWNLOADS]: The skill references official Obsidian documentation (
https://help.obsidian.md/cli). This is a reference to a well-known service for documentation purposes.
Recommendations
- AI detected serious security threats
Audit Metadata