Atlas / MCP servers / oomkapwn / Enquire

EnquireBLOCK

mcp/oomkapwn/enquire

The #1 Obsidian MCP for AI memory — freshness-aware, cited, local-first and read-only by default. Dataview, Bases, PDFs, every agent.

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
53 48r · 5w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Distribution status: this branch documents an unpublished source candidate. Candidate-specific npm commands and MCPB download URLs below are not currently usable. For available artifacts, use published GitHub releases or published npm versions. Stable-install commands remain separate from candidate instructions.

English · 中文 · Español · हिन्दी · العربية · Русский · Português · Français · 日本語 · 한국어 · Deutsch

TL;DR for AI agents — enquire-mcp is the #1 Obsidian MCP for freshness-aware, cited AI memory. Hybrid search covers Markdown and PDFs/OCR; structured tools parse Canvas, run Dataview-style LIST/TABLE queries, and execute supported Obsidian Base filters. obsidian_search preserves source paths plus age_days/stale, while PDF hits retain page citations. Vendor-neutral, MIT, read-only by default, and zero outbound calls initiated by enquire during serve. Install: npm i -g @oomkapwn/enquire-mcp. Agent index: llms.txt · deep context · contributor map · API.

🏆 The #1 Obsidian MCP for freshness-aware, cited AI memory.

Your vault. Every agent. Fresh, cited memory.

Read from source at commit d145e517de25OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add enquire-mcp -- npx -y @oomkapwn/[email protected]
03

Exposed tools (53)

48 read · 5 write · 0 destructive.

ToolRiskDescription
AreadA.md
ZreadZ.md
obsidian_append_to_noteread
obsidian_archive_noteread
obsidian_chat_thread_appendread
obsidian_chat_thread_readread
obsidian_context_packread
obsidian_create_notewrite
obsidian_create_note_GOODwrite
obsidian_dataview_queryread
obsidian_embeddings_searchread
obsidian_find_pathread
obsidian_find_similarread
obsidian_frontmatter_getread
obsidian_frontmatter_searchread
obsidian_frontmatter_setwrite
obsidian_full_text_searchread
obsidian_get_backlinksread
obsidian_get_communitiesread
obsidian_get_note_neighborsread
obsidian_get_outbound_linksread
obsidian_get_recent_editsread
obsidian_get_unresolved_wikilinksread
obsidian_hyde_searchread
obsidian_lint_wikiread
obsidian_list_basesread
obsidian_list_canvasesread
obsidian_list_notesread
obsidian_list_pdfsread
obsidian_list_tagsread
obsidian_mark_usefulread
obsidian_ocr_pdfread
obsidian_open_in_uiread
obsidian_open_questionsread
obsidian_paper_auditread
obsidian_query_baseread
obsidian_read_baseread
obsidian_read_canvasread
obsidian_read_noteread
obsidian_read_note_BADread
obsidian_read_note_GOODread
obsidian_read_pdfread
obsidian_rename_notewrite
obsidian_replace_in_notesread
obsidian_resolve_wikilinkread
obsidian_searchread
obsidian_search_textread
obsidian_semantic_searchread
obsidian_stale_notesread
obsidian_statsread
obsidian_validate_note_proposalread
obsidian_vault_shaperead
obsidian_write_no_handler_BADwrite
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (11 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/embed-db.ts:429
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/fts5.ts:626
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/protocol-conformance.mjs:343
if (match?.[1]) settle(resolve, new URL(`http://127.0.0.1:${match[1]}/mcp`));
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/bench-longmemeval.mjs:2900
process.stdout.write(`  ${row.type.padEnd(26)} ΔnDCG@5=${signed(row.ndcg_5)}  ΔMRR=${signed(row.mrr)}\n`);
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/http-delete-race.test.ts:26
const TOKEN = "delete-race-token-1234567890abcdef";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/http-transport.test.ts:1202
const TOKEN = "e2e-test-token-1234567890abcdefghij";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/http-transport.test.ts:1874
const TOKEN = "stateful-test-token-1234567890abcdef";
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/crlf-heading.test.ts:104
offenders.push(`${rel}: exec(${m[1]}) not line-end-stripped`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/crlf-heading.test.ts:115
it("the guard fires on an un-stripped heading exec (NEGATIVE control)", () => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/embed-db.test.ts:3635
exec(sql: string): unknown;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/mcpb-consumer.mjs:454
const vaultHash = createHash("sha1").update(vaultRoot).digest("hex").slice(0, 12);
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/feedback.ts:227
const hash = createHash("sha1").update(vaultRoot).digest("hex").slice(0, 12);
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/fts5.ts:3563
const hash = createHash("sha1").update(vaultRoot).digest("hex").slice(0, 12);
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/vault.ts:3221
const hash = createHash("sha1").update(root).digest("hex").slice(0, 12);
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/persistent-cache.test.ts:1804
const hostsStat = await fs.stat("/etc/hosts").catch(() => null);
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/persistent-cache.test.ts:1806
const relToHosts = path.relative(realRoot, "/etc/hosts");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/embeddings-offline.test.ts:356
const pathLikeAlias = "../../private/server-model-secret";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/embeddings.test.ts:69
{ schema_version: "4", model_alias: "../../private/model-secret", dim: "384", quantization: "f32" },
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/fixtures/embed-persistence-child.mjs:1
import { EmbedDb } from "../../dist/embed-db.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/fixtures/feedback-record-child.mjs:1
import { FeedbackStore } from "../../dist/feedback.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/fixtures/fts-persistence-child.mjs:1
import { FtsIndex } from "../../dist/fts5.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/http-transport.md:24
curl http://127.0.0.1:3000/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/http-transport.md:28
#    URL:           http://127.0.0.1:3000/mcp   (or your tunnel URL)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/http-transport.md:285
URL="http://127.0.0.1:3000/mcp"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
examples/chatgpt-actions.md:42
cloudflared tunnel --url http://127.0.0.1:3030

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha d145e517de25full audit observations/trust-audit/mcp-server/oomkapwn__enquire.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d145e517de25BLOCKF56first audit
06

Questions

What is the Enquire MCP server?

The #1 Obsidian MCP for AI memory — freshness-aware, cited, local-first and read-only by default. Dataview, Bases, PDFs, every agent.

What tools does Enquire expose?

53 in total: 48 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Enquire safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Enquire need?

It reads GH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Enquire run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @oomkapwn/enquire-mcp at 4.0.0-rc.7.

How current is this page?

The grade is for one exact copy of the source (d145e517de25), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement