obsidian-notes

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified during the analysis of this skill.
  • [DATA_EXPOSURE]: The skill is designed to manage files within a local Obsidian vault (specifically in base/notes/ and base/categories/). These operations are restricted to the specified workspace directories and do not access sensitive system files or credentials.
  • [PROMPT_INJECTION]: While the instructions use authoritative language (e.g., "CRITICAL: Follow all naming conventions strictly"), this is used for formatting compliance and does not attempt to override the AI agent's core safety protocols or system instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided content to generate Markdown files. While it lacks explicit sanitization for the note content, the scope of the skill is limited to file creation within a controlled directory, posing no significant risk of execution or exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 10:44 PM