obsidian-bases

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a system for processing and rendering vault content (notes, tags, and metadata), which creates a potential surface for indirect prompt injection.\n
  • Ingestion points: Note content, tags, and properties accessed via filters as shown in the Task Tracker and Reading List examples in SKILL.md and references/detailed-guide.md.\n
  • Boundary markers: The workflow lacks instructions for implementing clear delimiters or boundary markers between the processed note data and the agent's instructions.\n
  • Capability inventory: The documented DSL in references/FUNCTIONS_REFERENCE.md includes functions such as html() for rendering content and file() for accessing note metadata and vault objects.\n
  • Sanitization: The reference documentation includes escapeHTML(), but its use is not strictly mandated or consistently applied in the provided formula examples to sanitize interpolated data.\n- [NO_CODE]: The skill package consists solely of Markdown reference files and YAML configuration examples for the Obsidian application. It does not contain any Python code, Node.js modules, or shell scripts for execution by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 01:36 AM
Security Audit — agent-trust-hub — obsidian-bases