skills/steipete/openclaw/obsidian/Gen Agent Trust Hub

obsidian

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and installs the obsidian-cli utility from the yakitrak/yakitrak/obsidian-cli Homebrew repository to enable vault management.
  • [COMMAND_EXECUTION]: The instructions utilize obsidian-cli to perform file management tasks like searching, creating, renaming, and deleting markdown notes within the user's vaults.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by reading user-controlled data from local markdown files.
  • Ingestion points: Note content read from vaults via the search-content command described in SKILL.md.
  • Boundary markers: Absent; no explicit delimiters separate user content from instructions.
  • Capability inventory: The agent can create, move, and delete files using obsidian-cli across the vault.
  • Sanitization: Absent; the content of notes is retrieved and processed without specific validation or filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 02:11 PM
Security Audit — agent-trust-hub — obsidian