Obsidian Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Obsidian Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol server that lets any MCP-compatible AI host (Cursor, Claude Desktop, Zed, etc.) read, search, link, and write notes inside a local Markdown / Obsidian vault.
obsidian-mcp is an MCP server. MCP is an open standard from Anthropic for connecting AI assistants to external tools and data sources — think "USB-C for AI applications". Once this server is registered with an MCP host you can ask the model questions like:
"What did I learn about MCP this week, and which of my notes link to it?"
…and the model will call this server's tools (search_notes, find_backlinks, get_recent_notes, …) to answer using your actual notes.
| Phase | Scope | State |
|---|---|---|
| 0 | Repo skeleton, CI, sample vault, server stub with get_note | shipped |
| 1 | Sandboxed pathing, parser, reader, tests | shipped |
| 2 | Search, listings, backlinks, tag index | planned |
| 3 | Resources (notes as obsidian:// URIs) | planned |
| 4 | Write tools (create_note, append_to_note) + atomic writes | planned |
| 5 | Prompts (/weekly-review, /daily-note-template) | planned |
┌────────────────┐ stdio JSON-RPC ┌────────────────────────┐
│ MCP host │ ───────────────────► │ obsidian-mcp server │
│ (Cursor / │ │ (this repo) │
│ Claude / │ │ │
│ Zed) │ │ tools / resources / │
└────────────────┘ │ prompts │
└───────────┬────────────┘
│
sandboxed ▼
┌────────────────────────┐
│ Local Markdown vault │
└────────────────────────┘Every caller-supplied path is funnelled through a single sandboxing function (utils/pathing.py::safe_resolve) before any filesystem access, so the server cannot be coerced into reading files outside the configured vault root.
git clone https://github.com/darrenlopez/obsidian-mcp.git
cd obsidian-mcp
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"OBSIDIAN_MCP_VAULT_PATH="$(pwd)/sample-vault" \
npx @modelcontextprotocol/inspector \
python -m obsidian_mcpThis launches Anthropic's official MCP Inspector pointed at this server, so you can interactively call get_note and inspect schemas without leaving your browser.
Add the following to your Cursor MCP config (~/.cursor/mcp.json or the Cursor settings UI):
{
"mcpServers": {
"obsidian": {
"command": "python",
"args": ["-m", "obsidian_mcp"],
"env": {
"OBSIDIAN_MCP_VAULT_PATH": "/absolute/path/to/your/vault",
"OBSIDIAN_MCP_READ_ONLY": "false"
}
}
}
}Add the same block to ~/Library/Application Support/Claude/claude_desktop_config.json on macOS (or the platform equivalent).
All configuration is via environment variables (prefix OBSIDIAN_MCP_).
| Variable | Default | Purpose |
|---|---|---|
OBSIDIAN_MCP_VAULT_PATH | (required) | Absolute path to the vault root. |
OBSIDIAN_MCP_READ_ONLY | false | When true, write tools are not registered. |
OBSIDIAN_MCP_MAX_FILE_KB | 1024 | Max note size (KiB) returned by read operations. |
OBSIDIAN_MCP_INCLUDE_HIDDEN | false | Include dotfiles and .obsidian/ in listings/search. |
| Tool | Description |
|---|---|
get_note(path) | Read a single note, returning parsed frontmatter, tags, and outgoing wikilinks. |
The Phase 2+ tool surface (search_notes, list_notes, find_backlinks, list_tags, get_recent_notes, …) is documented in the architecture plan and tracked in STATUS.
This server reads (and, in non-read-only mode, writes) files on your machine. Some choices that limit blast radius:
safe_resolve(vault_root, user_input),which rejects absolute paths, .. segments, and symlink escapes before any filesystem touch.
OBSIDIAN_MCP_READ_ONLY=true and write tools arenot registered at all.
OBSIDIAN_MCP_MAX_FILE_KB caps the bytes returned by readoperations to prevent DoS via huge files.
.obsidian/ and dotfiles are skipped by default,so plugin secrets do not leak into model context.
pip install -e ".[dev]"
ruff check .
ruff format --check .
mypy
pytestThe test suite includes adversarial path-traversal tests (tests/test_pathing.py) — keep them green.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.