Atlas / MCP servers / jacksteamdev / Obsidian Tools

Obsidian ToolsBLOCK

mcp/jacksteamdev/obsidian-tools

Add Obsidian integrations like semantic search and custom Templater prompts to Claude or any MCP client.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MIT
Stars
832
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/jacksteamdev/obsidian-mcp-tools/releases/latest) [](https://github.com/jacksteamdev/obsidian-mcp-tools/actions) [](LICENSE)

Features | Installation | Configuration | Troubleshooting | Security | Development | Support

⚠️ Project Archived I'm grateful to all the users who have downloaded this plugin over the past year. Watching the Obsidian store install count climb to 87k has been fun! I never expected it to become the #1 MCP-related Obsidian plugin. This project was originally a labor of love for my partner, who was using Obsidian and wanted to chat with her notes. We're not using Obsidian currently, so I have decided to step aside to allow plugin developers who have a vested interest in the Obsidian ecosystem to gain users. There are at least five alternatives published to the Obsidian Community Plugins store, with many more MCP-related beta plugins available through BRAT. I'm not going to make recommendations for a specific plugin; I'll leave that to the user's discretion.

MCP Tools for Obsidian enables AI applications like Claude Desktop to securely access and work with your Obsidian vault through the Model Context Protocol (MCP). MCP is an open protocol that standardizes how AI applications can interact with external data sources and tools while maintaining security and user control. [^2]

This plugin consists of two parts:

  1. An Obsidian plugin that adds MCP capabilities to your vault
  2. A local MCP server that handles communication with AI applications

When you install this plugin, it

Read from source at commit ad252723cfc0OBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add test-server --env NODE_TLS_REJECT_UNAUTHORIZED=${NODE_TLS_REJECT_UNAUTHORIZED} --env OBSIDIAN_API_KEY=${OBSIDIAN_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "test-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "NODE_TLS_REJECT_UNAUTHORIZED": "${NODE_TLS_REJECT_UNAUTHORIZED}",
        "OBSIDIAN_API_KEY": "${OBSIDIAN_API_KEY}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
agereadEnter your age
namereadEnter your name
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (3 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (17)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/obsidian-plugin/src/features/mcp-server-install/utils/openFolder.ts:15
exec(command, (error: Error | null) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
packages/mcp-server/src/shared/makeRequest.ts:13
process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0";
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMSupply chain · supply.git_dep · CWE-829, CWE-1357
bun.lock:867
"obsidian-dataview": ["[email protected]", "", { "dependencies": { "@codemirror/language": "git+https://github.com/lishid/cm-language.git", "@codemirror/state": "^6.0.1", "@codemirror/view": "^
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.yaml
.prettierrc.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/obsidian-plugin/.eslintignore
.eslintignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/test-site/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/mcp-server/src/features/version/index.ts:1
import { version } from "../../../../../package.json" with { type: "json" };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/obsidian-plugin/bun.config.ts:8
import { version } from "../../package.json" assert { type: "json" };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/obsidian-plugin/scripts/link.ts:23
const projectRootDirectory = resolve(__dirname, "../../..");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/obsidian-plugin/scripts/zip.ts:5
import { version } from "../../../package.json" with { type: "json" };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/obsidian-plugin/src/features/core/index.ts:6
import type McpToolsPlugin from "../../main";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
caniuse-lite, npm-run-all
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp-server/package.json
acorn, acorn-walk, radash, turndown, zod, @types/bun, @types/turndown, prettier
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/obsidian-plugin/package.json
@types/fs-extra, arktype, express, fs-extra, obsidian-local-rest-api, radash, rxjs, semver
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/shared/package.json
arktype, @types/bun
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/test-site/package.json
@eslint/compat, @eslint/js, @sveltejs/adapter-static, @sveltejs/kit, @sveltejs/vite-plugin-svelte, autoprefixer, eslint, eslint-config-prettier
Why it matters. 19 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha ad252723cfc0full audit observations/trust-audit/mcp-server/jacksteamdev__obsidian-tools.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-27ad252723cfc0BLOCKD69first audit
06

Questions

What is the Obsidian Tools MCP server?

Add Obsidian integrations like semantic search and custom Templater prompts to Claude or any MCP client.

What tools does Obsidian Tools expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Obsidian Tools safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Obsidian Tools need?

It reads NODE_TLS_REJECT_UNAUTHORIZED and OBSIDIAN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Obsidian Tools run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as test-server at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (ad252723cfc0), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement