EnquireBLOCK
The #1 Obsidian MCP for AI memory — freshness-aware, cited, local-first and read-only by default. Dataview, Bases, PDFs, every agent.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Distribution status: this branch documents an unpublished source candidate. Candidate-specific npm commands and MCPB download URLs below are not currently usable. For available artifacts, use published GitHub releases or published npm versions. Stable-install commands remain separate from candidate instructions.
English · 中文 · Español · हिन्दी · العربية · Русский · Português · Français · 日本語 · 한국어 · Deutsch
TL;DR for AI agents — enquire-mcp is the #1 Obsidian MCP for freshness-aware, cited AI memory. Hybrid search covers Markdown and PDFs/OCR; structured tools parse Canvas, run Dataview-style LIST/TABLE queries, and execute supported Obsidian Base filters. obsidian_search preserves source paths plus age_days/stale, while PDF hits retain page citations. Vendor-neutral, MIT, read-only by default, and zero outbound calls initiated by enquire during serve. Install: npm i -g @oomkapwn/enquire-mcp. Agent index: llms.txt · deep context · contributor map · API.
🏆 The #1 Obsidian MCP for freshness-aware, cited AI memory.
Your vault. Every agent. Fresh, cited memory.
d145e517de25OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add enquire-mcp -- npx -y @oomkapwn/[email protected]
Exposed tools (53)
48 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
A | read | A.md |
Z | read | Z.md |
obsidian_append_to_note | read | |
obsidian_archive_note | read | |
obsidian_chat_thread_append | read | |
obsidian_chat_thread_read | read | |
obsidian_context_pack | read | |
obsidian_create_note | write | |
obsidian_create_note_GOOD | write | |
obsidian_dataview_query | read | |
obsidian_embeddings_search | read | |
obsidian_find_path | read | |
obsidian_find_similar | read | |
obsidian_frontmatter_get | read | |
obsidian_frontmatter_search | read | |
obsidian_frontmatter_set | write | |
obsidian_full_text_search | read | |
obsidian_get_backlinks | read | |
obsidian_get_communities | read | |
obsidian_get_note_neighbors | read | |
obsidian_get_outbound_links | read | |
obsidian_get_recent_edits | read | |
obsidian_get_unresolved_wikilinks | read | |
obsidian_hyde_search | read | |
obsidian_lint_wiki | read | |
obsidian_list_bases | read | |
obsidian_list_canvases | read | |
obsidian_list_notes | read | |
obsidian_list_pdfs | read | |
obsidian_list_tags | read | |
obsidian_mark_useful | read | |
obsidian_ocr_pdf | read | |
obsidian_open_in_ui | read | |
obsidian_open_questions | read | |
obsidian_paper_audit | read | |
obsidian_query_base | read | |
obsidian_read_base | read | |
obsidian_read_canvas | read | |
obsidian_read_note | read | |
obsidian_read_note_BAD | read | |
obsidian_read_note_GOOD | read | |
obsidian_read_pdf | read | |
obsidian_rename_note | write | |
obsidian_replace_in_notes | read | |
obsidian_resolve_wikilink | read | |
obsidian_search | read | |
obsidian_search_text | read | |
obsidian_semantic_search | read | |
obsidian_stale_notes | read | |
obsidian_stats | read | |
obsidian_validate_note_proposal | read | |
obsidian_vault_shape | read | |
obsidian_write_no_handler_BAD | write |
Trust audit
BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(sql: string): void;
exec(sql: string): void;
if (match?.[1]) settle(resolve, new URL(`http://127.0.0.1:${match[1]}/mcp`));process.stdout.write(` ${row.type.padEnd(26)} ΔnDCG@5=${signed(row.ndcg_5)} ΔMRR=${signed(row.mrr)}\n`);const TOKEN = "delete-race-token-1234567890abcdef";
const TOKEN = "e2e-test-token-1234567890abcdefghij";
const TOKEN = "stateful-test-token-1234567890abcdef";
offenders.push(`${rel}: exec(${m[1]}) not line-end-stripped`);it("the guard fires on an un-stripped heading exec (NEGATIVE control)", () => {exec(sql: string): unknown;
const vaultHash = createHash("sha1").update(vaultRoot).digest("hex").slice(0, 12);const hash = createHash("sha1").update(vaultRoot).digest("hex").slice(0, 12);const hash = createHash("sha1").update(vaultRoot).digest("hex").slice(0, 12);const hash = createHash("sha1").update(root).digest("hex").slice(0, 12);const hostsStat = await fs.stat("/etc/hosts").catch(() => null);const relToHosts = path.relative(realRoot, "/etc/hosts");
const pathLikeAlias = "../../private/server-model-secret";
{ schema_version: "4", model_alias: "../../private/model-secret", dim: "384", quantization: "f32" },import { EmbedDb } from "../../dist/embed-db.js";import { FeedbackStore } from "../../dist/feedback.js";import { FtsIndex } from "../../dist/fts5.js";curl http://127.0.0.1:3000/health
# URL: http://127.0.0.1:3000/mcp (or your tunnel URL)
URL="http://127.0.0.1:3000/mcp"
cloudflared tunnel --url http://127.0.0.1:3030
Gates applied: no_behavioural_pass.
d145e517de25full audit observations/trust-audit/mcp-server/oomkapwn__enquire.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | d145e517de25 | BLOCK | F | 56 | first audit |
Questions
What is the Enquire MCP server?
The #1 Obsidian MCP for AI memory — freshness-aware, cited, local-first and read-only by default. Dataview, Bases, PDFs, every agent.
What tools does Enquire expose?
53 in total: 48 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Enquire safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (56/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Enquire need?
It reads GH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Enquire run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @oomkapwn/enquire-mcp at 4.0.0-rc.7.
How current is this page?
The grade is for one exact copy of the source (d145e517de25), read on 2026-10-08. The repository is watched and re-audited when it changes.