using-obsidian

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes command-line interfaces such as obsidian-cli for vault interaction and defuddle for markdown extraction from the web.
  • [EXTERNAL_DOWNLOADS]: Capabilities like wiki-auto-research and defuddle involve fetching data from external web sources to populate the Obsidian vault.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection. It ingests data from untrusted sources (web pages and external files) and has the capability to write this data into the local filesystem.
  • Ingestion points: Web content via defuddle and wiki-auto-research; external files via obsidian-file-intel and wiki-ingest.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the provided documentation.
  • Capability inventory: File system read/write, metadata manipulation, web search, and CLI execution.
  • Sanitization: No documented sanitization, escaping, or validation logic for external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:05 PM
Security Audit — agent-trust-hub — using-obsidian