obsidian-init — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited obsidian-init (Agent Skill) and scored it 87/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 3 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill requires Python 3.8+ and standard library only. No external packages needed.
To install this skill's dependencies:
pip-compile ./requirements.in
pip install -r ./requirements.txtSee ./requirements.txt for the dependency lockfile (currently empty — standard library only).
Status: Active Author: Richard Fremmerlid Domain: Obsidian Integration
This skill is the entry point for any project adopting Obsidian. It handles:
The Obsidian desktop app must be installed on the host machine. It is the visual interface for browsing, editing, and viewing the Graph and Canvas.
macOS (Homebrew):
brew install --cask obsidianManual Download:
Verify:
ls /Applications/Obsidian.appThe official CLI communicates with a running Obsidian instance via IPC singleton lock. It enables programmatic vault operations (read, search, backlinks, properties).
npm (global install):
npm install -g obsidian-cliVerify:
obsidian --versionNote: The CLI requires an active Obsidian Desktop instance to communicate with. It operates in "silent" mode by default. For headless/CI environments where Obsidian is not running, ourvault_ops.py(fromobsidian-vault-crud) handles direct filesystem operations without requiring the CLI.
Lossless YAML frontmatter handling requires ruamel.yaml:
pip install ruamel.yamlFor advanced vault features, install these from within the Obsidian app:
| Plugin | Purpose | Required For |
|---|---|---|
| Dataview | Database-style queries over frontmatter | Structured metadata queries |
| Canvas (built-in) | Visual boards with JSON Canvas spec | obsidian-canvas-architect skill |
| Bases | Table/grid/card views from YAML | obsidian-bases-manager skill |
python ./init_vault.py --vault-root <path>python ./init_vault.py \
--vault-root <path> \
--exclude "custom_dir/" "*.tmp"python ./init_vault.py --vault-root <path> --validate-only.md files.obsidian/ configuration directory (if not present)app.json with sensible exclusion filters for developer repos.gitignore to exclude .obsidian/ (user-specific config)| Pattern | Reason |
|---|---|
node_modules/ | NPM dependencies |
.worktrees/ | Git worktree isolation |
.vector_data/ | ChromaDB binary data |
.git/ | Git internals |
venv/ | Python virtual environments |
__pycache__/ | Python bytecode cache |
*.json | Data/config files (not knowledge) |
*.jsonl | Export payloads |
learning_package_snapshot.md | Machine-generated bundle |
bootstrap_packet.md | Machine-generated bundle |
learning_debrief.md | Machine-generated bundle |
*_packet.md | Audit/review bundles |
*_digest.md | Context digests |
dataset_package/ | Export artifacts |
These are giant concatenated snapshots produced by bundler/distiller scripts. Indexing them in Obsidian would pollute the graph with thousands of false backlinks pointing into machine-generated text, not human-authored knowledge.
01_PROTOCOLS/, ADRs/, etc. appear in sidebar[[link]] to confirm navigation worksexport VAULT_PATH=/path/to/vaultAfter the vault is initialized, you can optionally initialize the LLM Wiki Engine layer. This creates a wiki_sources.json manifest — the multi-source registry that tells the wiki engine which raw content folders to index.
This is the wiki equivalent ofrlm_profiles.jsonin the RLM system. Each named entry inwiki_sources.jsonis a raw content directory that will be parsed into Karpathy-style wiki nodes. No files are moved.
The sub-agent interviews you interactively to register your raw content directories:
/wiki-initOr directly:
python ./scripts/raw_manifest.py --init --wiki-root /path/to/wiki-rootFor each source folder you want to index, it asks:
| Question | Example Answer |
|---|---|
| Wiki root path? | /path/to/vault/wiki-root |
| Source folder path? | /path/to/vault/notes |
| Label for this source? | daily-notes |
| File extensions? | .md (default) |
| Subdirectories to exclude? | _archive, *.tmp |
| Add another source? | yes/no |
rlm_wiki_raw_sources_manifest.jsonUses the same flat schema as rlm-factory and vector-db for consistency:
{
"description": "Source raw content for Obsidian Wiki",
"include": [
"plugins/",
"plugin-research/"
],
"exclude": [
".git/",
"node_modules/",
".venv/",
"__pycache__/"
],
"recursive": true
}Saved to: .agent/learning/rlm_wiki_raw_sources_manifest.json
/wiki-ingest <- parse all registered sources, build wiki nodes
/wiki-distill <- generate RLM summaries (cheapest available LLM CLI)
/wiki-query <- start querying the wikiThis skill is project-agnostic. It works on any Git repository with markdown files. The exclusion filters are sensible defaults for developer projects. When reusing this plugin in other projects, simply run the init script with the new project's root path.
# 1. Install prerequisites
brew install --cask obsidian # Desktop app
npm install -g obsidian-cli # CLI tools
pip install ruamel.yaml # Lossless YAML
# 2. Initialize vault
python ./init_vault.py \
--vault-root /path/to/your/project
# 3. Set environment variable
export VAULT_PATH=/path/to/your/project
# 4. Open in Obsidian app
open /Applications/Obsidian.app~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.