ObsidianCAUTION
Obsidian MCP (Model Context Protocol) Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
This project implements a Model Context Protocol (MCP) server for connecting AI models with Obsidian knowledge bases. Through this server, AI models can directly access and manipulate Obsidian notes, including reading, creating, updating, and deleting notes, as well as managing folder structures.
Created by huangyihe
- Prompt House: https://prompthouse.app/
- YouTube: https://www.youtube.com/@huanyihe777
- Twitter: https://x.com/huangyihe
- Community: https://t.zsxq.com/19IaNz5wK
Features
- 🔗 Seamless Obsidian Integration: Direct access to Obsidian knowledge bases through MCP protocol
- 📝 Complete Note Management: Read, create, update, and delete notes with advanced text replacement
- 📁 Folder Operations: Create, rename, move, and delete folders with full hierarchy support
- 🔍 Intelligent Search: Full-text search across all file types with smart scoring
- 🤖 AI-Powered Analysis: NEW Strategic insights using TRILEMMA-PRINCIPLES framework
- 🔗 Auto Backlink Generation: NEW Intelligent detection and conversion of note names to wikilinks
- ⚡ Precision Editing: Advanced PATCH operations with heading and block-level targeting
- 🚀 Dual API Strategy: Obsidian REST API with filesystem fallback for maximum reliability
- 🎯 Context Optimization: Smart content summarization for LLM context length management
- 📊 Batch Processing: Efficient bulk operations with progress tracking
Supported Tools
The MCP server provides the following comprehensive tools:
📋 Core Operations
list_notes: List notes in the Obsidian vault with optional folder filtering- NEW
recursiveparameter: Control whether to list files recursively in subdirectories (default: true) - Use
recursive: falseto list only files in the specified folder without subdirectories read_note: Read the content of a specific note in the Obsidian vault- `readmultiplenote
1e95b7a8ac46OBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add obsidian-mcp --env OBSIDIAN_API_TOKEN=${OBSIDIAN_API_TOKEN} -- npx -y @huangyihe/[email protected]{
"mcpServers": {
"obsidian-mcp": {
"command": "npx",
"args": [
"-y",
"@huangyihe/[email protected]"
],
"env": {
"OBSIDIAN_API_TOKEN": "${OBSIDIAN_API_TOKEN}"
}
}
}
}Exposed tools (11)
5 read · 4 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
auto_backlink_vault | write | Automatically add backlinks throughout the entire vault by detecting note names in content and converting them to wikilinks |
create_note | write | Create a new note in the Obsidian vault |
delete_note | destructive | Delete a note from the Obsidian vault |
list_notes | read | List notes in the Obsidian vault. By default lists all notes recursively. |
manage_folder | destructive | Create, rename, move, or delete a folder in the Obsidian vault |
move_note | write | Move or rename a note to a new location in the Obsidian vault |
notes_insight | read | Generate insights about a topic using TRILEMMA-PRINCIPLES framework with AI-powered summarization |
read_multiple_notes | read | Read content from multiple notes simultaneously |
read_note | read | Read the content of a note in the Obsidian vault |
search_vault | read | Search for content in the Obsidian vault |
update_note | write | Update content in an existing note using text replacements or precise insertions |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
console.log(` API Token: ${testConfig.apiToken.substring(0, 8)}...`);delete_note, manage_folder
--network host \
--network host \
@modelcontextprotocol/sdk, @types/diff, archiver, axios, diff, dotenv, eventsource, express
obsidian-mcp.dxt
Gates applied: no_behavioural_pass.
1e95b7a8ac46full audit observations/trust-audit/mcp-server/newtype-01__obsidian-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 1e95b7a8ac46 | CAUTION | B | 89 | first audit |
Questions
What is the Obsidian MCP server?
Obsidian MCP (Model Context Protocol) Server
What tools does Obsidian expose?
11 in total: 5 read-only, 4 that write, and 2 that can delete or overwrite (delete_note, manage_folder). Every one is listed on this page with its risk.
Is Obsidian safe to connect to an agent?
With care. The audit graded it B (89/100) and found 6 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Obsidian need?
It reads OBSIDIAN_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Obsidian run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @huangyihe/obsidian-mcp at 1.7.1-beta.
How current is this page?
The grade is for one exact copy of the source (1e95b7a8ac46), read on 2026-10-03. The repository is watched and re-audited when it changes.