obsidian-mcp

Warn

Audited by Snyk on Aug 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). In server.tool(...) the required workflow registers MCP tools that directly consume outsider-supplied params (including free-text content) and pass it into CDP cdpService.evaluate(...)/REST file operations without needing to first select a specific preexisting item.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 02:21 PM
Issues
1
Security Audit — snyk — obsidian-mcp