obsidian
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
obsidian-clicommand-line tool to perform vault management tasks, including searching content, creating new notes, and moving or deleting existing Markdown files. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and process content from user notes in Obsidian vaults. This creates a standard surface for indirect prompt injection where the agent might ingest instructions embedded within a note's text.
- Ingestion points: Markdown notes (
*.md) within the user's local Obsidian vaults. - Capability inventory: The skill can create, move, and delete files using
obsidian-cliand perform direct edits to Markdown files. - Boundary markers: No explicit boundary markers or instructions to ignore embedded content are provided.
- Sanitization: No sanitization or validation of note content is performed before processing.
Audit Metadata