obsidian-web-clipper
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill acts as a documentation aid for the Obsidian Web Clipper browser extension. Its primary function is to help an agent generate valid JSON configurations for capturing web content.
- [SAFE]: Instructions to read local vault files such as
CLAUDE.md,AGENTS.md, orREADME.mdare intended solely to ensure generated templates match the user's existing organizational style and formatting conventions. - [SAFE]: The AI Interpreter feature described is an official capability of the documented tool used for summarizing web content. While this creates a standard surface for indirect prompt injection common to all web-scraping AI tools, no malicious exploitation patterns were found.
- [SAFE]: Analysis of Indirect Prompt Injection surface (Category 8):
- Ingestion points: Templates extract data from external URLs via variables like
{{content}}and{{selectorHtml}}inSKILL.md. - Boundary markers: The skill encourages matching existing note shapes but does not define explicit boundary markers for untrusted content.
- Capability inventory: The skill enables the creation of Markdown files within an Obsidian vault and the use of an AI interpreter for content processing.
- Sanitization: No automated sanitization of web content is specified, which is consistent with the tool's purpose as a content capture utility.
- [SAFE]: All referenced external documentation sources (e.g.,
/obsidianmd/obsidian-clipper) belong to the official repository of the well-known Obsidian service and are treated as trusted sources.
Audit Metadata