Smart Connections Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Smart Connections Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A security-first MCP server for Smart Connections. Read-only. Path-validated. Auditable.
Exposes Smart Connections embeddings to Claude Code and other MCP clients for semantic search of your Obsidian vault.
We needed semantic search of our Obsidian vault from Claude Code. Existing options have problems:
This implementation:
| Property | Guarantee |
|---|---|
| Path confinement | All file access validated against vault root |
| No traversal | ../ and symlink attacks blocked |
| Read-only | No write operations exposed |
| Bounded responses | Capped results (50), content length (10KB) |
| Fail closed | Errors deny access, never bypass |
| Audit logging | Security events logged with context |
git clone https://github.com/gogogadgetbytes/smart-connections-mcp
cd smart-connections-mcp
npm install
npm run buildAdd to your Claude Code config:
claude mcp add smart-connections \
-e VAULT_PATH="/path/to/your/obsidian/vault" \
-- node /path/to/smart-connections-mcp/dist/index.jsOr manually add to ~/.claude.json:
{
"mcpServers": {
"smart-connections": {
"command": "node",
"args": ["/path/to/smart-connections-mcp/dist/index.js"],
"env": {
"VAULT_PATH": "/path/to/your/obsidian/vault"
}
}
}
}Restart Claude Code to load the server.
Once configured, Claude Code can use these tools:
"Search my vault for notes about backup strategies"
→ Uses search_by_text tool"Find notes similar to Topics/Claude_Code.md"
→ Uses search_similar tool"Show me the content of Topics/Obsidian.md"
→ Uses get_note tool"What notes are indexed in my vault?"
→ Uses list_indexed tool| Tool | Description |
|---|---|
search_by_text | Search using freeform text (computes embedding locally) |
search_similar | Find notes semantically similar to a given note |
search_by_embedding | Search using a raw embedding vector |
get_note | Get content of a specific note (path validated) |
get_model_info | Get embedding model configuration |
list_indexed | List all indexed notes |
| Variable | Required | Description |
|---|---|---|
VAULT_PATH | Yes | Absolute path to Obsidian vault |
~/.cache/huggingface/# Build
npm run build
# Test with MCP Inspector
npx @modelcontextprotocol/inspector node dist/index.jsSee CONTRIBUTING.md. Security-focused PRs welcome.
To report security vulnerabilities, please email [email protected]. Do not open public issues for security concerns.
MIT - see LICENSE
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.