obsidian-bases
Pass
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a domain-specific configuration format for the Obsidian Bases plugin. Its primary purpose is to instruct the agent on generating valid YAML structures for data visualization within the user's vault.
- [PROMPT_INJECTION]: The skill defines a surface for processing external data (note metadata and content). While this creates an entry point for indirect prompt injection, the risk is mitigated by the restricted nature of the formula language, which lacks capabilities for network access or system command execution.
- [SAFE]: No hardcoded credentials, external network requests, or remote code execution patterns were found in the provided files. All operations are confined to local file formatting and metadata computation.
Audit Metadata