obsidian-bases

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted note data such as properties, tags, and file content to generate database views and filters.
  • Ingestion points: Data is pulled from note frontmatter like 'note.author', file metadata like 'file.tags', and file system paths via 'file(path)' functions as described in SKILL.md.
  • Capability inventory: The agent can create, edit, and configure '.base' files which dictate how data is displayed and processed within the Obsidian environment.
  • Sanitization: While the 'escapeHTML()' function is documented, the skill does not explicitly require the agent to sanitize note data before it is rendered via the 'html()' function, creating a potential XSS surface.
  • Boundary markers: There are no specific instructions to use delimiters or sanitization routines when note metadata is interpolated into YAML filter logic.
  • [DYNAMIC_EXECUTION]: The skill utilizes a formula engine to compute values at runtime within the Obsidian Bases plugin.
  • The agent generates expressions for the 'formulas' section of '.base' files, including conditional logic and HTML rendering paths.
  • The 'html()' function documented in the reference allows strings to be rendered as HTML in the UI, which could be exploited to execute malicious scripts if the agent incorporates unsanitized note content into these rendering paths.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation from Obsidian's help resources.
  • References include links to 'help.obsidian.md' for syntax, functions, and views guidance, which are legitimate service domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:43 PM
Security Audit — agent-trust-hub — obsidian-bases