obsidian-markdown

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official Obsidian documentation from help.obsidian.md to provide the agent with additional context on Markdown syntax.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions involve processing and generating Obsidian Markdown files, which creates a potential surface for indirect prompt injection if external note content contains malicious instructions.
  • Ingestion points: Obsidian Markdown files (.md) and their YAML frontmatter properties.
  • Boundary markers: Absent; there are no specific instructions for the agent to use delimiters or ignore instructions found within processed notes.
  • Capability inventory: None; the skill contains no executable scripts, shell commands, or network operations.
  • Sanitization: Absent; no sanitization or validation logic is provided for the content of processed notes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — obsidian-markdown