Obsidian ToolsBLOCK
Add Obsidian integrations like semantic search and custom Templater prompts to Claude or any MCP client.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/jacksteamdev/obsidian-mcp-tools/releases/latest) [](https://github.com/jacksteamdev/obsidian-mcp-tools/actions) [](LICENSE)
Features | Installation | Configuration | Troubleshooting | Security | Development | Support
⚠️ Project Archived I'm grateful to all the users who have downloaded this plugin over the past year. Watching the Obsidian store install count climb to 87k has been fun! I never expected it to become the #1 MCP-related Obsidian plugin. This project was originally a labor of love for my partner, who was using Obsidian and wanted to chat with her notes. We're not using Obsidian currently, so I have decided to step aside to allow plugin developers who have a vested interest in the Obsidian ecosystem to gain users. There are at least five alternatives published to the Obsidian Community Plugins store, with many more MCP-related beta plugins available through BRAT. I'm not going to make recommendations for a specific plugin; I'll leave that to the user's discretion.
MCP Tools for Obsidian enables AI applications like Claude Desktop to securely access and work with your Obsidian vault through the Model Context Protocol (MCP). MCP is an open protocol that standardizes how AI applications can interact with external data sources and tools while maintaining security and user control. [^2]
This plugin consists of two parts:
- An Obsidian plugin that adds MCP capabilities to your vault
- A local MCP server that handles communication with AI applications
When you install this plugin, it
ad252723cfc0OBSERVED · 2026-09-27Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add test-server --env NODE_TLS_REJECT_UNAUTHORIZED=${NODE_TLS_REJECT_UNAUTHORIZED} --env OBSIDIAN_API_KEY=${OBSIDIAN_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"test-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"NODE_TLS_REJECT_UNAUTHORIZED": "${NODE_TLS_REJECT_UNAUTHORIZED}",
"OBSIDIAN_API_KEY": "${OBSIDIAN_API_KEY}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
age | read | Enter your age |
name | read | Enter your name |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
exec(command, (error: Error | null) => {process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0";
"obsidian-dataview": ["[email protected]", "", { "dependencies": { "@codemirror/language": "git+https://github.com/lishid/cm-language.git", "@codemirror/state": "^6.0.1", "@codemirror/view": "^
.clinerules
.prettierrc.yaml
.eslintignore
.prettierignore
import { version } from "../../../../../package.json" with { type: "json" };import { version } from "../../package.json" assert { type: "json" };const projectRootDirectory = resolve(__dirname, "../../..");
import { version } from "../../../package.json" with { type: "json" };import type McpToolsPlugin from "../../main";
caniuse-lite, npm-run-all
acorn, acorn-walk, radash, turndown, zod, @types/bun, @types/turndown, prettier
@types/fs-extra, arktype, express, fs-extra, obsidian-local-rest-api, radash, rxjs, semver
arktype, @types/bun
@eslint/compat, @eslint/js, @sveltejs/adapter-static, @sveltejs/kit, @sveltejs/vite-plugin-svelte, autoprefixer, eslint, eslint-config-prettier
Gates applied: no_behavioural_pass.
ad252723cfc0full audit observations/trust-audit/mcp-server/jacksteamdev__obsidian-tools.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-27 | ad252723cfc0 | BLOCK | D | 69 | first audit |
Questions
What is the Obsidian Tools MCP server?
Add Obsidian integrations like semantic search and custom Templater prompts to Claude or any MCP client.
What tools does Obsidian Tools expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Obsidian Tools safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Obsidian Tools need?
It reads NODE_TLS_REJECT_UNAUTHORIZED and OBSIDIAN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Obsidian Tools run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as test-server at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (ad252723cfc0), read on 2026-09-27. The repository is watched and re-audited when it changes.