obsidian-add-knowledge

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external URLs and user-provided text, creating a potential surface for indirect prompt injection where malicious instructions embedded in the source material could attempt to influence the agent's behavior during the distillation and reconciliation process.
  • Ingestion points: The skill ingests data from external URLs, user-provided text, and topics as described in the 'Distill the payload' step of SKILL.md.
  • Boundary markers: No specific delimiters or boundary markers are instructed for use when interpolating external content into the distillation process.
  • Capability inventory: The agent has the capability to read from the network (URLs) and perform read/write operations on the local file system (Obsidian vault).
  • Sanitization: The instructions do not specify any sanitization or escaping protocols for the external content.
  • Mitigation: The skill implements a 'Hard Gate' at step 4, requiring the user to approve the exact target path and substance of a change before any writing occurs. This manual verification step is a strong defense against automated exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 08:22 AM
Security Audit — agent-trust-hub — obsidian-add-knowledge