obsidian

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes Homebrew to install the obsidian-cli tool from the third-party tap yakitrak/yakitrak/obsidian-cli during initialization.
  • [COMMAND_EXECUTION]: The skill relies on shell commands via obsidian-cli to perform operations on the local file system, such as searching note contents, moving markdown files with link refactoring, and deleting notes.
  • [DATA_EXFILTRATION]: The skill accesses the local Obsidian application configuration file at ~/Library/Application Support/obsidian/obsidian.json to identify active vault locations and their paths on the disk. This exposure is limited to local read access necessary for the skill's primary functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 10:45 PM
Security Audit — agent-trust-hub — obsidian