obsidian-tax-vault-manager
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill defines a standardized YAML schema for storing sensitive Personally Identifiable Information (PII), including NPWP (Indonesian Taxpayer ID), NIK (National ID), and Nitku. While the skill body emphasizes a 'Local-First' policy, the agent's instructions to manage these files mean it will have access to high-value financial and personal data within the local vault environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes and aggregates data from markdown files within the Obsidian vault (e.g., using Dataview queries). This creates an ingestion surface where malicious instructions embedded in documents (such as tax regulations or client notes) could potentially influence the agent's behavior. \n
- Ingestion points: All markdown files within the
Tax-Vault/subfolders (01-Klien,02-Peraturan, etc.).\n - Boundary markers: Absent; the skill does not define specific delimiters to separate data from instructions.\n
- Capability inventory: File reading, YAML parsing, and Dataview template generation.\n
- Sanitization: Not specified; the skill relies on standard Obsidian/Dataview processing.\n- [CREDENTIALS_UNSAFE]: The skill demonstrates positive security awareness by explicitly instructing the agent and user not to store sensitive credentials like CoreTax passwords or API tokens in plain text, recommending local environment references instead.
Audit Metadata