← Index

io.github.es617/obsidian-sync-mcp

io.github.es617/obsidian-sync-mcp·v0.5.2·Security

Give AI agents access to your Obsidian vault via local files or Self-hosted LiveSync.

Trust verdict · v1 advisory · method
REVIEWstatus: PARTIALfresh until 2026-05-31 01:58 UTC
screened 2026-05-31tier: scannedgranularity: description-level

Semantic screen found no manipulation pattern in the description. Conformance probe not yet run.

mcpindex.integrity.descriptionpassINFO

evidenceAccess granted by uservia static_description

Limits of this verdict
  • - Semantic screen only - the deterministic conformance probe has not run on this server
  • - Confidence is reported but not yet calibrated (v1)
  • - Screen reads the tool description, not the live behavior
  • - advisory

Semantic screen: an LLM judge reads the tool description for hidden instructions (status PARTIAL). A pass means the description is not lying, not that the tool is safe: a high-capability tool with an honest description still warrants caution. The deterministic conformance probe has not been run on this server yet, so the screen here is semantic-only. Posture: advisory. Confidences are reported but not yet calibrated (calibrated=false at v1). History is paid-tier and not shown here.

Own this server? Screen its description →

Embed this badge

A live verdict badge for your README or listing. It reflects the current screen, links back here, and updates when the verdict does.

Markdown
[![mcpindex](https://mcpindex.ai/api/v1/badge/io-github-es617-obsidian-sync-mcp)](https://mcpindex.ai/server/io-github-es617-obsidian-sync-mcp)
HTML
<a href="https://mcpindex.ai/server/io-github-es617-obsidian-sync-mcp"><img src="https://mcpindex.ai/api/v1/badge/io-github-es617-obsidian-sync-mcp" alt="mcpindex verdict" height="20" /></a>
Environment variables
VAULT_PATH

Path to your Obsidian vault directory (filesystem mode)

COUCHDB_URL

CouchDB server URL (CouchDB mode)

COUCHDB_USER

CouchDB username

COUCHDB_PASSWORD
secret

CouchDB password (required in CouchDB mode)

COUCHDB_DATABASE

CouchDB database name

COUCHDB_PASSPHRASE
secret

LiveSync E2E encryption passphrase (must match plugin setting)

COUCHDB_OBFUSCATE_PROPERTIES

Set to 'true' if 'Obfuscate Properties' is enabled in LiveSync (obfuscates file paths, sizes, dates)

VAULT_NAME

Vault name for deep links and index storage

MCP_AUTH_TOKEN
secret

Password for OAuth authentication

BASE_URL

Public URL for OAuth callbacks (required when using a tunnel)

PORT

HTTP port

MCP quality score · maturity, not trust · methodology
freshness
21
completeness
10
installability
25
documentation
15
stability
5
Alternatives in Security