0
/ 100
1 month ago
glama

obsidian-mcp

A self-hosted MCP server with a management UI for reading, searching, editing, and organizing notes in an Obsidian vault, with OAuth and token authentication, git snapshots, and optional Obsidian Sync.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Code appears obfuscated
1 file are unreadable to a human reviewer. Cannot audit what they do.
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 3 credentials: CLOUDFLARED_TUNNEL_TOKEN, GATECRASH_HOST_KEY, GATECRASH_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 high1 medium18 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highhono@4.12.0GHSA-q5qw-h33p-qvwr

Hono vulnerable to arbitrary file access via serveStatic vulnerability

highhono@4.12.0GHSA-xh87-mx6m-69f3

Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo

mediumhono@4.12.0GHSA-xf4j-xp2r-rqqx

Hono: Path traversal in toSSG() allows writing files outside the output directory

lowhono@4.12.0GHSA-26pp-8wgv-hjvm

Hono missing validation of cookie name on write path in setCookie()

lowhono@4.12.0GHSA-2gcr-mfcq-wcc3

Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCLOUDFLARED_BIN
🔐 secretCLOUDFLARED_TUNNEL_TOKEN
configDATA_DIR/data Root for all persistent state
configGATECRASH_BIN
🔐 secretGATECRASH_HOST_KEY
configGATECRASH_SERVER
configGATECRASH_TARGET
🔐 secretGATECRASH_TOKEN
configLOG_LEVELinfo debug / info / warn / error
configOB_BIN
configPORT3000 Listen port
configPUBLIC_URL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/jclement-obsidian-mcp-26bj31)](https://m8ven.ai/mcp/jclement-obsidian-mcp-26bj31)
commit: d14dbcda23dab44de6e8f5f7aafb539fc9a63daf
code hash: f71bc30b1a99d9339538e7db6185a18e042712292cb147a800e09943ad910802
verified: 6/13/2026, 9:37:23 AM
view raw JSON →