Atlas / MCP servers / boweylou / Obsidian Enhanced

Obsidian EnhancedCAUTION

mcp/boweylou/obsidian-enhanced

This is an enhanced version of the excellent cyanheads/obsidian-mcp-server with additional features specifically tailored for remote Claude.ai integration, advanced task querying, and security via Tailscale.

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
10 4r · 4w · 2d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.typescriptlang.org/) [](https://modelcontextprotocol.io/) [](./CHANGELOG.md) [](https://opensource.org/licenses/Apache-2.0) [](https://github.com/BoweyLou/obsidian-mcp-server-enhanced/issues) [](https://github.com/cyanheads/obsidian-mcp-server)

Enhanced Obsidian MCP Server with Claude.ai Remote Integration, Tailscale Support, and Advanced Query Capabilities!

🔥 Enhanced Fork Notice: This is an enhanced version of the excellent cyanheads/obsidian-mcp-server with additional features specifically tailored for remote Claude.ai integration, advanced task querying, and security via Tailscale.

An MCP (Model Context Protocol) server providing comprehensive access to your Obsidian vault. Enables LLMs and AI agents to read, write, search, and manage your notes and files through the Obsidian Local REST API plugin.

Built on the `cyanheads/mcp-ts-template`, this server follows a modular architecture with robust error handling, logging, and security features.

🚀 Enhanced Features (This Fork)

🏛️ Multi-Vault Support

Simultaneous access to multiple Obsidian vaults through a single MCP server:

  • Multiple Vault Management: Connect to multiple Obsidian instances on different ports simultaneously
  • Vault-Specific Routing: Tools automatically route to the correct vault based on vault parameter
  • **Individua
Read from source at commit 63a6867431f9OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add obsidian-mcp-server --env MCP_AUTH_KEY=${MCP_AUTH_KEY} --env OBSIDIAN_API_KEY=${OBSIDIAN_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "obsidian-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MCP_AUTH_KEY": "${MCP_AUTH_KEY}",
        "OBSIDIAN_API_KEY": "${OBSIDIAN_API_KEY}"
      }
    }
  }
}
03

Exposed tools (10)

4 read · 4 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
append_notedestructiveAppend or prepend note content. Whole-note overwrite is not available here.
create_daily_notewriteCreate today
create_notewriteCreate a new note by vault-relative path. Existing notes are not overwritten.
create_taskwriteCreate a Tasks-plugin compatible task.
fetchreadFetch bounded Obsidian note content by vault-relative path.
latest_notereadReturn the markdown note with the latest filesystem modification time.
overwrite_notedestructiveOverwrite a note. Enable only for explicitly trusted connector clients.
searchreadBounded Obsidian vault search with snippets.
task_queryreadQuery Obsidian Tasks-plugin compatible tasks.
update_taskwriteUpdate an existing task by path and line or text match.
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (11 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (20)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.clinerules:30
- **`OBSIDIAN_BASE_URL`**: **Required.** Base URL for the Obsidian Local REST API (e.g., `http://127.0.0.1:27123`).
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.clinerules:238
- Provide the corresponding `OBSIDIAN_BASE_URL` (e.g., `http://127.0.0.1:27123`).
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.clinerules:240
- If the user prefers to use the default encrypted HTTPS URL (e.g., `https://127.0.0.1:27124`), explain that it uses a self-signed certificate.
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.clinerules:1161
- **Example (for Obsidian API)**: `npm run fetch:spec http://127.0.0.1:27123/ docs/obsidian-api/obsidian_rest_api_spec` (Replace URL if your Obsidian API runs elsewhere)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Makefile:11
CHATGPT_FACADE_TARGET ?= http://127.0.0.1:3020
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
append_note, overwrite_note
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.ncurc.json
.ncurc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
scripts/autostart/macos/.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/fetch-openapi-spec.ts:113
return yaml.load(data) as object;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/fetch-openapi-spec.ts:122
const parsedYaml = yaml.load(data) as object;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/autostart/macos/install-autostart-macos.sh:17
PROJECT_DIR="$(cd "$SCRIPT_DIR/../../.." && pwd)"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/obsidianBlockReferenceTool/index.ts:7
import { RequestContext, requestContextService } from "../../../utils/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/obsidianBlockReferenceTool/index.ts:8
import { BaseErrorCode, McpError } from "../../../types-global/errors.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/obsidianBlockReferenceTool/index.ts:9
import { ObsidianRestApiService } from "../../../services/obsidianRestAPI/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/obsidianBlockReferenceTool/logic.ts:5
import { RequestContext } from "../../../utils/index.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/jsonwebtoken, @types/sanitize-html, axios, date-fns, dotenv, express, ignore
Why it matters. 27 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/NATIVE_HTTP_TRANSPORT.md:227
res.setHeader("Access-Control-Allow-Credentials", "true");
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/TAILSCALE_SECURITY.md:178
- **Unauthorized Access**: Verify API key setup
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
scripts/autostart/README.md:216
# Add to crontab for weekly log rotation
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 63a6867431f9full audit observations/trust-audit/mcp-server/boweylou__obsidian-enhanced.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0863a6867431f9CAUTIONB83first audit
06

Questions

What is the Obsidian Enhanced MCP server?

This is an enhanced version of the excellent cyanheads/obsidian-mcp-server with additional features specifically tailored for remote Claude.ai integration, advanced task querying, and security via Tailscale.

What tools does Obsidian Enhanced expose?

10 in total: 4 read-only, 4 that write, and 2 that can delete or overwrite (append_note, overwrite_note). Every one is listed on this page with its risk.

Is Obsidian Enhanced safe to connect to an agent?

With care. The audit graded it B (83/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Obsidian Enhanced need?

It reads MCP_AUTH_KEY and OBSIDIAN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Obsidian Enhanced run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as obsidian-mcp-server at 2.1.0.

How current is this page?

The grade is for one exact copy of the source (63a6867431f9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement