obsidian-cli
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The required runtime workflow reads outsider-authored free text when the agent receives user-supplied query/contents as arguments to the Obsidian CLI wrapper (e.g.,
obsidian-exec.sh context --query,capture --text,daily --text,task --add), and then passes that text to the CLI which searches the vault or writes it into notes.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata