Atlas / MCP servers / es617 / Obsidian Sync

Obsidian SyncCAUTION

mcp/es617/obsidian-sync

MCP server for Obsidian — access your vault from any AI agent, even when your machine is off. Powered by Self-hosted LiveSync.

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
10 6r · 3w · 1d
Transport
streamable-http
License
MIT
Stars
59
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Give any AI agent access to your Obsidian vault over MCP. Run it locally against your vault files, or pair it with Self-hosted LiveSync and deploy to the cloud so it works even when your machine is off.

Example: From your phone, ask your AI: "What's in my daily note for today?" — and get the full content back, with a link to open it in Obsidian.

How it works

The server connects to your vault in two ways:

  • Filesystem mode — reads .md files directly from your vault folder. No database needed.
  • CouchDB mode — reads from a CouchDB database, locally or in the cloud. Your vault syncs to CouchDB via Self-hosted LiveSync, the community Obsidian plugin (600k+ downloads). The MCP server reads from CouchDB directly using livesync-commonlib — the same library that powers the plugin — for proper chunk handling and E2E encryption support.

Both modes expose the same MCP tools over HTTP, so any MCP-compatible agent can connect: Claude, Copilot, custom agents, anything that speaks the Model Context Protocol.

Choose your setup

A. Deploy MCP to the cloud

You already have LiveSync and CouchDB on a

Read from source at commit dc2f6c9675f0OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add obsidian-sync-mcp --env COUCHDB_PASSWORD=${COUCHDB_PASSWORD} --env COUCHDB_PASSPHRASE=${COUCHDB_PASSPHRASE} --env MCP_AUTH_TOKEN=${MCP_AUTH_TOKEN} -- npx -y [email protected]
03

Exposed tools (10)

6 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
delete_notedestructiveDelete a note from the Obsidian vault.
edit_notewriteEdit a note without rewriting it. Use
get_note_metadatareadGet metadata about a note without reading its full content. Returns frontmatter, tags, outgoing links, backlinks (notes that link to this one), size, and timestamps. Use this to navigate the knowledge graph.
list_foldersreadList all folders in the vault. Use this to discover folder names before writing or listing notes. Returns the folder tree with note counts.
list_notesreadList markdown notes in the vault with modification timestamps. Examples: list_notes(sort_by=
list_tagsreadList all tags used in the vault, sorted by frequency. Use this to discover tags before filtering with list_notes.
move_notewriteMove or rename a note. Use this to rename a note within the same folder, move it to a different folder, or both at once. Creates destination folders automatically.
read_notereadRead the content of a note from the Obsidian vault. Returns the markdown content and a deep link to open it in Obsidian.
search_notesreadSearch note contents for terms, case-insensitive.\n
write_notewriteWrite or update a note in the Obsidian vault. Creates the note if it doesn
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (20)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth.ts:344
console.log(`Auth: /oauth/token request grant_type=${JSON.stringify(grantType)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth.ts:399
console.log(`Auth: /oauth/token issuing access token client_id=${pending.clientId}`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_note
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/note-path.test.ts:38
for (const p of ["../escape.md", "a/../../etc/passwd.md", "/abs/note.md", "a\0b.md", "a//b.md", "folder/.md"]) {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/vault-local.test.ts:27
it("blocks ../../ traversal", async () => {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/vault-local.test.ts:28
await assert.rejects(() => vault.readNote("../../etc/shadow"), /Invalid note path/);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/vault-local.test.ts:36
await assert.rejects(() => vault.deleteNote("../../important.md"), /Invalid note path/);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/vault-local.test.ts:40
await assert.rejects(() => vault.listNotes("../../etc"), /Path traversal blocked/);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
SECURITY.md:19
- **Browser-attack protection (no auth mode)** — with no token, the server validates both the HTTP `Host` and `Origin` headers and rejects any request whose host/origin is not `localhost`/`127.0.0.1`/
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/host-guard.test.ts:71
assert.ok(isOriginAllowed("http://127.0.0.1:8787", allowed));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
diff-match-patch, fastmcp, fflate, minimatch, octagonal-wheels, pouchdb-adapter-http, pouchdb-core, pouchdb-errors
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:50
- **Fixed a critical authentication bypass in password-gated OAuth (GHSA-cc9w-6w4g-hqv7).** `/oauth/token` issued an access token for any authorization code that was in flight, without checking that t
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:102
cat > .env <<EOF
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
README.md:76
export PATH="$HOME/.fly/bin:$PATH"  # add to ~/.zshrc or ~/.bashrc
Why it matters. instructs the agent to persist itself in the user's environment
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
README.md:128
export PATH="$HOME/.fly/bin:$PATH"  # add to ~/.zshrc or ~/.bashrc
Why it matters. instructs the agent to persist itself in the user's environment
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:75
curl -L https://fly.io/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:127
curl -L https://fly.io/install.sh | sh
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:13
- Bump `@modelcontextprotocol/sdk` to 1.32.1, clearing a high-severity advisory (GHSA-6qxp-vccf-f47h: an OAuth client could send credentials to an authorization server chosen by the MCP server).
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SECURITY.md:19
- **Browser-attack protection (no auth mode)** — with no token, the server validates both the HTTP `Host` and `Origin` headers and rejects any request whose host/origin is not `localhost`/`127.0.0.1`/
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha dc2f6c9675f0full audit observations/trust-audit/mcp-server/es617__obsidian-sync.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08dc2f6c9675f0CAUTIONB84first audit
06

Questions

What is the Obsidian Sync MCP server?

MCP server for Obsidian — access your vault from any AI agent, even when your machine is off. Powered by Self-hosted LiveSync.

What tools does Obsidian Sync expose?

10 in total: 6 read-only, 3 that write, and 1 that can delete or overwrite (delete_note). Every one is listed on this page with its risk.

Is Obsidian Sync safe to connect to an agent?

With care. The audit graded it B (84/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Obsidian Sync need?

It reads COUCHDB_PASSPHRASE, COUCHDB_PASSWORD, MCP_AUTH_TOKEN and TEST_COUCHDB_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Obsidian Sync run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as obsidian-sync-mcp at 0.8.0.

How current is this page?

The grade is for one exact copy of the source (dc2f6c9675f0), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement