obsidian-vault
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides organizational guidelines and search workflows for a specific local directory path. It does not initiate network connections or include external code.
- [COMMAND_EXECUTION]: The skill suggests the use of standard shell utilities like
findandgrepto manage files within the vault. These operations are restricted to the local environment and the specified vault path. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and search through external markdown files within the Obsidian vault. This constitutes a data ingestion surface where the agent could potentially encounter embedded instructions in note content. However, the skill acts as a standard file management utility and lacks complex automated triggers or exfiltration paths, resulting in a low risk profile.
Audit Metadata