Atlas / MCP servers / cyanheads / Obsidian

ObsidianBLOCK

mcp/cyanheads/obsidian-1

Read, write, search, and surgically edit Obsidian vault notes, tags, and frontmatter via MCP. STDIO or Streamable HTTP.

Verdict
BLOCK
Grade
F
Trust score
37 /100
Exposed tools
3 2r · 1w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
687
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

obsidian-mcp-server Read, write, search, and surgically edit Obsidian vault notes, tags, and frontmatter via MCP. STDIO or Streamable HTTP. 14 Tools • 3 Resources

[](./CHANGELOG.md) [](./LICENSE) [](https://github.com/users/cyanheads/packages/container/package/obsidian-mcp-server) [](https://modelcontextprotocol.io/) [](https://www.npmjs.com/package/obsidian-mcp-server) [](https://www.typescriptlang.org/) [](https://bun.sh/)

[](https://github.com/cyanheads/obsidian-mcp-server/releases/latest/download/obsidian-mcp-server.mcpb) [](https://cursor.com/en/install-mcp?name=obsidian-mcp-server&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIm9ic2lkaWFuLW1jcC1zZXJ2ZXIiXSwiZW52Ijp7Ik9CU0lESUFOX0FQSV9LRVkiOiJ5b3VyLWFwaS1rZXkifX0=) [](https://vscode.dev/redirect?url=vscode:mcp/install?%7B%22name%22%3A%22obsidian-mcp-server%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22ob

Read from source at commit 0fe96b6c339eOBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add obsidian-mcp-server -- npx -y [email protected] run start:stdio
claude-code (npm)
claude mcp add obsidian-mcp-server -- npx -y [email protected] run start:http
03

Exposed tools (3)

2 read · 1 write · 0 destructive.

ToolRiskDescription
obsidian-statusreadServer reachability, plugin version, auth status, and registered API extensions of the Obsidian Local REST API. Still reports reachability when the API key is misconfigured;
obsidian-tagswriteAll tags found in the Obsidian vault, with usage counts, in upstream order and uncapped — a full snapshot. Includes hierarchical parents (e.g.
obsidian-vault-notereadA note in the Obsidian vault. Returns the parsed note — content, frontmatter, tags, and stat — so clients can attach a specific note to a conversation.
04

Trust audit

BLOCKgrade F · trust 37/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (10 observation(s))
Shell
declared (9 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
framework-skills/add-tool/SKILL.md:783
**Seed orientation context when the next moves are predictable.** Piggybacking a compact snapshot alongside the primary result — recent activity, tracked state, a few reference items — does two things
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
framework-skills/design-mcp-server/SKILL.md:344
- **Mirror a bulk upstream instead of paginating it live.** When the server wraps a large or slow API whose corpus is queried far more than it changes, sync it once into a persistent local index and q
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
framework-skills/field-test/SKILL.md:4
Exercise tools, resources, and prompts against a live HTTP server via MCP JSON-RPC over curl. Starts the server, surfaces the catalog, runs real and adversarial inputs, measures every call (bytes, tok
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
framework-skills/field-test/SKILL.md:452
Kills the background server and its port-holding child, removes the server log, then removes the helper script itself. Do this *before* writing the report so nothing leaks into the next session. Pass 
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build.ts:129
const tsc = await exec([join(ROOT_DIR, 'node_modules', '.bin', 'tsc'), '-p', project], 'tsc');
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/build.ts:133
const alias = await exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/devcheck.ts:158
exec(cmd: string[], options: { cwd: string }): Promise<ShellResult> {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/services/obsidian/obsidian-service.ts:1208
return exec();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
scripts/devcheck.ts:681
'**/.netrc',
Why it matters. touches a credential store
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/services/obsidian/obsidian-service.ts:1127
return { tls: { rejectUnauthorized: false } };
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
framework-skills/release-and-publish/SKILL.md:215
Prereq: a GitHub PAT with `read:org` + `read:user` scopes stored in Keychain under the service name `mcp-publisher-github-pat`:
Why it matters. asks the agent to read credentials
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
framework-skills/orchestrations/SKILL.md:55
2. **No `git stash`, no `git reset --hard`, no `git restore .`, no `git clean -f`, no `git checkout -- .`.** These bypass safety and risk silent data loss. Read-only git (`status`, `diff`, `log`, `sho
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:56
# Base URL of the Local REST API plugin. Default: http://127.0.0.1:27123.
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:58
# Use https://127.0.0.1:27124 for the always-on HTTPS port (self-signed cert; pair with OBSIDIAN_VERIFY_SSL=false).
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:59
# OBSIDIAN_BASE_URL=http://127.0.0.1:27123
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.example:77
# OBSIDIAN_OMNISEARCH_URL=http://127.0.0.1:51361
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/services/obsidian-service.test.ts:1707
['multiple ..', '../../etc/passwd'],
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/tools/obsidian-get-note.test.ts:115
target: { type: 'path', path: 'Projects/../../etc/passwd' },
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
AGENTS.md:142
baseUrl: z.string().url().default('http://127.0.0.1:27123'),
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/services/obsidian-service-tls.test.ts:85
const relaxed = { tls: { rejectUnauthorized: false } };
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/services/frontmatter-ops.test.ts:801
'#a¡b #c¿d #e─f #g©h #i«j #k§l #m¶n #o°p #q·r #sΩt #u€v #wTMx #y→z #aa♥bb #cc×dd',
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/services/frontmatter-ops.test.ts:812
'sΩt',
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@cyanheads/mcp-ts-core, js-yaml, pino-pretty, undici, yaml, zod, @biomejs/biome, @socketsecurity/bun-security-scanner
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
changelog/3.5.x/3.5.3.md:17
- **A cancelled single-request HTTP POST's SSE stream now closes immediately**, instead of waiting for keep-alive or session expiry ([cyanheads/mcp-ts-core#401](https://github.com/cyanheads/mcp-ts-cor
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, instruction_override, no_behavioural_pass, undeclared_transfer.

Audited 2026-09-28 · audit v0.4.1 · source sha 0fe96b6c339efull audit observations/trust-audit/mcp-server/cyanheads__obsidian-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-280fe96b6c339eBLOCKF37first audit
06

Questions

What is the Obsidian MCP server?

Read, write, search, and surgically edit Obsidian vault notes, tags, and frontmatter via MCP. STDIO or Streamable HTTP.

What tools does Obsidian expose?

3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Obsidian safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (37/100) and found 12 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Obsidian need?

It reads NODE_TLS_REJECT_UNAUTHORIZED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Obsidian run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as obsidian-mcp-server at 3.6.0.

How current is this page?

The grade is for one exact copy of the source (0fe96b6c339e), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement