Atlas / MCP servers / aaronsb / Obsidian Semantic

Obsidian SemanticCAUTION

mcp/aaronsb/obsidian-semantic

A semantic MCP server for Obsidian that simplifies 20+ tools into 5 AI-optimized operations with intelligent workflow hints and state-aware suggestions.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
5 2r · 3w · 0d
Transport
stdio
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🎉 Exciting News! We've taken everything we learned from this project and created something even better! Check out the new **Obsidian MCP Plugin** - a native Obsidian plugin that runs directly inside your vault with improved performance, simplified setup, and enhanced features. We encourage you to try it out!

[](https://www.npmjs.com/package/obsidian-semantic-mcp)

A semantic, AI-optimized MCP server for Obsidian that consolidates 20 tools into 5 intelligent operations with contextual workflow hints.

🚀 Try Our New Native Plugin!

This MCP server taught us valuable lessons about AI integration with Obsidian. We've applied these insights to create the [Obsidian MCP Plugin](https://github.com/aaronsb/obsidian-mcp-plugin), which offers:

  • Native Integration: Runs directly inside Obsidian (no external dependencies!)
  • Better Performance: Direct vault access without REST API overhead
  • Easier Setup: Install like any Obsidian plugin - no API keys or external servers
  • Enhanced Features: Full access to Obsidian's internal APIs and search capabilities
  • Improved Reliability: No more connection issues or timeouts

👉 [Get the Obsidian MCP Plugin](https://github.com/aaronsb/obsidian-mcp-plugin)

Prerequisites

Installation

npm install -g obsidian-semantic-mcp

Or use directly with npx (recommended):

npx obsid
Read from source at commit c7eac46409d5OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add obsidian-semantic-mcp --env OBSIDIAN_API_KEY=${OBSIDIAN_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "obsidian-semantic-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OBSIDIAN_API_KEY": "${OBSIDIAN_API_KEY}"
      }
    }
  }
}
03

Exposed tools (5)

2 read · 3 write · 0 destructive.

ToolRiskDescription
edit_vault_from_bufferwriteRetry an edit using previously buffered content
edit_vault_windowwriteEdit a portion of a file using fuzzy string matching with automatic fallback strategies
fetchreadFetch and convert web content to markdown
insert_vault_at_linewriteInsert content at a specific line number
view_vault_windowreadView a portion of a file with optional search highlighting
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/utils/obsidian-api.ts:25
rejectUnauthorized: false
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:68
"OBSIDIAN_API_URL": "https://127.0.0.1:27124",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:343
OBSIDIAN_API_URL=http://127.0.0.1:27123
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/node, @types/sharp, @types/turndown, axios, dotenv, sharp, turndown
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:18
- **Enhanced Features**: Full access to Obsidian's internal APIs and search capabilities

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c7eac46409d5full audit observations/trust-audit/mcp-server/aaronsb__obsidian-semantic.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c7eac46409d5CAUTIONB89first audit
06

Questions

What is the Obsidian Semantic MCP server?

A semantic MCP server for Obsidian that simplifies 20+ tools into 5 AI-optimized operations with intelligent workflow hints and state-aware suggestions.

What tools does Obsidian Semantic expose?

5 in total: 2 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Obsidian Semantic safe to connect to an agent?

With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Obsidian Semantic need?

It reads OBSIDIAN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Obsidian Semantic run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as obsidian-semantic-mcp at 1.7.2.

How current is this page?

The grade is for one exact copy of the source (c7eac46409d5), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement