ObsidianBLOCK
Read, write, search, and surgically edit Obsidian vault notes, tags, and frontmatter via MCP. STDIO or Streamable HTTP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
obsidian-mcp-server Read, write, search, and surgically edit Obsidian vault notes, tags, and frontmatter via MCP. STDIO or Streamable HTTP. 14 Tools • 3 Resources
[](./CHANGELOG.md) [](./LICENSE) [](https://github.com/users/cyanheads/packages/container/package/obsidian-mcp-server) [](https://modelcontextprotocol.io/) [](https://www.npmjs.com/package/obsidian-mcp-server) [](https://www.typescriptlang.org/) [](https://bun.sh/)
[](https://github.com/cyanheads/obsidian-mcp-server/releases/latest/download/obsidian-mcp-server.mcpb) [](https://cursor.com/en/install-mcp?name=obsidian-mcp-server&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIm9ic2lkaWFuLW1jcC1zZXJ2ZXIiXSwiZW52Ijp7Ik9CU0lESUFOX0FQSV9LRVkiOiJ5b3VyLWFwaS1rZXkifX0=) [](https://vscode.dev/redirect?url=vscode:mcp/install?%7B%22name%22%3A%22obsidian-mcp-server%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22ob
0fe96b6c339eOBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add obsidian-mcp-server -- npx -y [email protected] run start:stdio
claude mcp add obsidian-mcp-server -- npx -y [email protected] run start:http
Exposed tools (3)
2 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
obsidian-status | read | Server reachability, plugin version, auth status, and registered API extensions of the Obsidian Local REST API. Still reports reachability when the API key is misconfigured; |
obsidian-tags | write | All tags found in the Obsidian vault, with usage counts, in upstream order and uncapped — a full snapshot. Includes hierarchical parents (e.g. |
obsidian-vault-note | read | A note in the Obsidian vault. Returns the parsed note — content, frontmatter, tags, and stat — so clients can attach a specific note to a conversation. |
Trust audit
BLOCKgrade F · trust 37/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (9 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
**Seed orientation context when the next moves are predictable.** Piggybacking a compact snapshot alongside the primary result — recent activity, tracked state, a few reference items — does two things
- **Mirror a bulk upstream instead of paginating it live.** When the server wraps a large or slow API whose corpus is queried far more than it changes, sync it once into a persistent local index and q
Exercise tools, resources, and prompts against a live HTTP server via MCP JSON-RPC over curl. Starts the server, surfaces the catalog, runs real and adversarial inputs, measures every call (bytes, tok
Kills the background server and its port-holding child, removes the server log, then removes the helper script itself. Do this *before* writing the report so nothing leaks into the next session. Pass
const tsc = await exec([join(ROOT_DIR, 'node_modules', '.bin', 'tsc'), '-p', project], 'tsc');
const alias = await exec(
exec(cmd: string[], options: { cwd: string }): Promise<ShellResult> {return exec();
'**/.netrc',
return { tls: { rejectUnauthorized: false } };Prereq: a GitHub PAT with `read:org` + `read:user` scopes stored in Keychain under the service name `mcp-publisher-github-pat`:
2. **No `git stash`, no `git reset --hard`, no `git restore .`, no `git clean -f`, no `git checkout -- .`.** These bypass safety and risk silent data loss. Read-only git (`status`, `diff`, `log`, `sho
# Base URL of the Local REST API plugin. Default: http://127.0.0.1:27123.
# Use https://127.0.0.1:27124 for the always-on HTTPS port (self-signed cert; pair with OBSIDIAN_VERIFY_SSL=false).
# OBSIDIAN_BASE_URL=http://127.0.0.1:27123
# OBSIDIAN_OMNISEARCH_URL=http://127.0.0.1:51361
.mcpbignore
['multiple ..', '../../etc/passwd'],
target: { type: 'path', path: 'Projects/../../etc/passwd' },baseUrl: z.string().url().default('http://127.0.0.1:27123'),const relaxed = { tls: { rejectUnauthorized: false } };'#a¡b #c¿d #e─f #g©h #i«j #k§l #m¶n #o°p #q·r #sΩt #u€v #wTMx #y→z #aa♥bb #cc×dd',
'sΩt',
@cyanheads/mcp-ts-core, js-yaml, pino-pretty, undici, yaml, zod, @biomejs/biome, @socketsecurity/bun-security-scanner
- **A cancelled single-request HTTP POST's SSE stream now closes immediately**, instead of waiting for keep-alive or session expiry ([cyanheads/mcp-ts-core#401](https://github.com/cyanheads/mcp-ts-cor
Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.
0fe96b6c339efull audit observations/trust-audit/mcp-server/cyanheads__obsidian-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 0fe96b6c339e | BLOCK | F | 37 | first audit |
Questions
What is the Obsidian MCP server?
Read, write, search, and surgically edit Obsidian vault notes, tags, and frontmatter via MCP. STDIO or Streamable HTTP.
What tools does Obsidian expose?
3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Obsidian safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (37/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Obsidian need?
It reads NODE_TLS_REJECT_UNAUTHORIZED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Obsidian run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as obsidian-mcp-server at 3.6.0.
How current is this page?
The grade is for one exact copy of the source (0fe96b6c339e), read on 2026-09-28. The repository is watched and re-audited when it changes.