obsidian-vault-crud — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited obsidian-vault-crud (Agent Skill) and scored it 87/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 3 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill requires Python 3.8+ and standard library only. No external packages needed.
To install this skill's dependencies:
pip-compile ./requirements.in
pip install -r ./requirements.txtSee ./requirements.txt for the dependency lockfile (currently empty — standard library only).
Status: Active Author: Richard Fremmerlid Domain: Obsidian Integration Depends On: obsidian-markdown-mastery (WP05)
This skill provides the disk I/O layer for all agent interactions with the Obsidian Vault. It does NOT handle syntax parsing (that belongs to obsidian-markdown-mastery). Instead, it ensures that every file write is:
os.rename() from a .tmp staging file.agent-lock file at the vault rootmtime comparison before/after readruamel.yaml for frontmatter (never PyYAML)python ./vault_ops.py read --file <path>python ./vault_ops.py create --file <path> --content <text> [--frontmatter key=value ...]python ./vault_ops.py update --file <path> --content <text>python ./vault_ops.py append --file <path> --content <text><target>.agent-tmp.agent-tmp file was written completelyos.rename('<target>.agent-tmp', '<target>') — atomic on POSIX.agent-tmp is cleaned up<vault_root>/.agent-lock.agent-lock.agent-lock before writingos.stat(file).st_mtime before readingst_mtime againruamel.yaml (NOT PyYAML) to preserve comments, indentation, and array styles~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.