obsidian — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited obsidian (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use the backend that best matches user intent:
When a request is ambiguous, pick MCP first unless the user explicitly asks for sync/backup/git/app behavior.
replaceAll: false, if oldString appears more than once the call fails and returns matchCount. Set replaceAll: true only when you mean it, or add surrounding context to make the match unique.title: will match frontmatter fields. Include enough context to target the right occurrence.oldString and newString must be non-empty and non-whitespace. To delete text, use newString with a single space or restructure the note with write_note.p (path), t (title), ex (excerpt), mc (matchCount), ln (lineNumber), uri (obsidianUri). Hard cap of 20 results regardless of limit.append/prepend mode, if the note doesn't exist it's created. Frontmatter is merged (new keys override) in append/prepend; replaced entirely in overwrite.confirmPath must be character-identical to path. No normalization, no trailing-slash tolerance. Mismatch silently fails with success: false.confirmOldPath and confirmNewPath must exactly match their counterparts. Use move_note for markdown renames (text-aware, no confirmation needed); use move_file only for binary files or when you need binary-safe moves.list merges frontmatter tags + inline #hashtags. add/remove only modify the frontmatter tags array. Inline tags are never touched.allSettled internally. Failed files appear in the err array; successful ones in ok. Always check both. Hard limit of 10 paths per call.| Error | Next step |
|---|---|
| patch_note "Found N occurrences" | Add surrounding lines to oldString to make it unique, or set replaceAll: true |
| delete_note / move_file confirmation mismatch | Re-read the note path with read_note or list_directory, then retry with the exact string |
| search_notes returns 0 results | Try single keywords instead of phrases, toggle searchFrontmatter, or broaden with partial terms |
read_multiple_notes partial err | Verify failed paths with list_directory, fix typos or missing extensions, retry only failed ones |
When the user asks to "sync", "backup", or "store my vault with git", use CLI git with this behavior:
git availablegit config user.name and git config user.email are setgit pull --rebase now? (Recommended: Yes)"git add -Agit commit -m "vault sync: YYYY-MM-DD HH:mm" (skip commit if no changes)git pull --rebasegit pushgh is optional:gh only for remote bootstrapping (create repo / set origin) when requested.gh for normal sync once remote is configured.When the user asks for app-context operations (active file, open in editor, daily notes with templates, backlinks), use the Obsidian CLI directly via shell commands.
| Priority | macOS | Linux | Windows |
|---|---|---|---|
| 1 | obsidian (PATH) | obsidian (PATH) | obsidian.exe or Obsidian.com (PATH) |
| 2 | /Applications/Obsidian.app/Contents/MacOS/obsidian-cli | — | — |
| 3 | /Applications/Obsidian.app/Contents/MacOS/Obsidian | — | — |
Obsidian 1.12.7+ installer bundles a dedicatedobsidian-clibinary (~10x faster than the legacy Electron-based CLI: ~25ms vs ~250ms per call). On macOS, after installing the 1.12.7+ installer, disable then re-enable the CLI in Settings > General > Advanced to update PATH registration. This replaces the old~/.zprofilePATH entry with a/usr/local/bin/obsidiansymlink pointing toobsidian-cli.
>
On Linux, PATH registration creates a symlink at/usr/local/bin/obsidian(or~/.local/bin/obsidianas fallback). On Windows, the installer places anObsidian.comterminal redirector alongsideObsidian.exe.
>
Note: The priority table and stale PATH check are verified on macOS only. Linux and Windows may also bundle obsidian-cli with the 1.12.7+ installer, but this has not been confirmed. Contributions welcome via issue or PR.obsidian on PATH, checkwhether it points to the fast binary or the slow Electron launcher:
| Resolved path | Meaning | Action |
|---|---|---|
/usr/local/bin/obsidian → obsidian-cli | 1.12.7 symlink registration | None — fast binary |
/Applications/.../MacOS/obsidian | Old ~/.zprofile entry (pre-1.12.7 registration or 1.12.7 installer without re-registering) | Check if obsidian-cli exists in the bundle |
If obsidian resolves to the MacOS directory (not /usr/local/bin) AND /Applications/Obsidian.app/Contents/MacOS/obsidian-cli exists, tell the user: _"Obsidian 1.12.7+ is installed but PATH still points to the slower Electron binary. In Obsidian, go to Settings > General > Advanced and disable then re-enable the CLI to update PATH registration."_ Continue with whichever priority matched — this is advisory, not blocking.
pgrep -xiq obsidian (macOS/Linux) or tasklist /FI "IMAGENAME eq Obsidian.exe" /NH (Windows)obsidian:// URIsobsidian vault="VaultName" <command>. The vault name is the folder basename unless OBSIDIAN_VAULT_NAME is set. # Read the currently active file
obsidian read
# Read a specific file
obsidian read file="My Note"
# Open a file in Obsidian
obsidian open path="Notes/example.md"
# Open today's daily note
obsidian daily
# Append to daily note
obsidian daily:append content="- [ ] New task"
# Search (Obsidian's own search, different from MCP's BM25)
obsidian search query="meeting notes" limit=10
# List all tags with frequency
obsidian tags sort=count counts
# Get backlinks for a note
obsidian backlinks file="My Note"
# Find unresolved links
obsidian unresolvedobsidian help for the full command reference. The CLI evolves with Obsidian releases.Load these only when needed, not on every invocation.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.