Obsidian Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Obsidian Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The most reliable way to connect Claude Desktop to your Obsidian Vault.
Unlike other MCP servers that require the "Local REST API" or "Obsidian MCP" plugins (which frequently break or require Obsidian to be open), this server uses Direct File Access. It talks straight to your filesystem, making it faster, more stable, and functional even when Obsidian is closed.
Most Obsidian MCPs only allow you to read or overwrite entire files. This "Ultimate" edition adds power-user features:
patch_note to find-and-replace text without rewriting the whole file.[[Links]] to find the actual file path.Clone this repo to a permanent folder on your computer:
git clone https://github.com/YOUR_USERNAME/obsidian-mcp-ultimate.git
cd obsidian-mcp-ultimate
npm installAdd the server to your Claude Desktop config file:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json{
"mcpServers": {
"obsidian": {
"command": "node",
"args": ["/ABSOLUTE/PATH/TO/index.js"],
"env": {
"OBSIDIAN_VAULT_PATH": "/ABSOLUTE/PATH/TO/YOUR/VAULT"
}
}
}
}(Note: Use forward slashes `/` even on Windows, or double backslashes `\\`.)
| Tool | Description |
|---|---|
list_notes | Recursively lists all .md files in your vault. |
read_note | Reads the full content of a note. |
patch_note | (New) Find-and-replace specific text within a note. |
search_notes | Full-text search across the entire vault. |
resolve_link | (New) Converts a [[Wikilink]] into a usable file path. |
Youtube | (New) Extracts YAML frontmatter/properties. |
Notes | Creates or overwrites a note. |
append_note | Quickly adds text to the bottom of a note. |
move_note | (New) Rename or move files and folders. |
delete_note | (New) Permanently deletes a note. |
create_directory | (New) Creates new folders in your vault. |
If Claude sees a link like [[Meeting Notes 2024]], it might not know where that file is. It should first call resolve_link(link_text: "Meeting Notes 2024") to get the path, then read_note.
Instead of asking Claude to "Update my note," ask it to:
"Find the line starting with 'Status:' and replace it with 'Status: Completed' in my project note."
This triggers patch_note, which is much safer for large files than overwriting the entire thing.
This server has delete and overwrite capabilities. While it only acts on your command, it is highly recommended to have Obsidian Sync, Git, or a system backup (Time Machine/File History) enabled for your vault.
Found a bug or want to add a ripgrep integration for massive vaults? PRs are welcome!
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.