obsidian-remote-mcp (nweii/obsidian-remote-mcp) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it yet. No publisher has claimed this listing.
Self-hosted MCP server that provides remote AI clients with read and write access to Obsidian vaults over HTTPS without needing the Obsidian desktop app running.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
nweii
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
Hono: Algorithmic Complexity DoS in Language Middleware
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
APPROVAL_OPENIf a reverse proxy or zero-trust gateway already guards /authorize (the stronger control), set =true for the click-to-approve page instead.APPROVAL_PASSWORDCORS_ALLOWED_ORIGINSScope — .mcpignore blocks paths from access, VAULT_READ_ONLY disables writes, and limits browser origins. Paths are always confined to the vault root.HEALTH_TOKENLOG_DIRLOG_ENABLEDMCP_BASE_URLmust match the public site origin (no /mcp).MCP_CLIENT_ALLOWED_REDIRECT_URISMCP_CLIENT_ID[OAuth 2.1 + PKCE](#oauth-browser-sign-in) — browser sign-in, presenting your .MCP_CLIENT_SECRETMCP_CLIENT_ID, optionally MCP_CLIENT_SECRETMCP_DCR_ALLOWED_REDIRECT_URISMCP_DCR_ENABLEDMCP_STATIC_BEARER_TOKEN[API key](#api-key-static-bearer-token) () — a fixed bearer token, for clients that can't open a browser.OBSIDIAN_VAULT_IDIf obsidian.json contains multiple vaults, set to the vault entry you want to use.RESOLVE_INDEX_TTL_MSTOKEN_STORE_PATH(default ./tokens.json) — stores OAuth-issued tokens after login so clients survive server restarts.VAULT_ATTACHMENT_MAX_BYTESVAULT_CONTEXT_PATHRead the vault guidance note configured by VAULT_CONTEXT_PATH, or fall back to AGENTS.md / CLAUDE.mdVAULT_DISPLAY_NAMEThe display name used in the OAuth approval page defaults to the resolved vault directory name. You can override that with .VAULT_MCP_TESTVAULT_PATH1. , if setWEB_CLIPPER_SETTINGS_PATHPORTLicense file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Production dependencies are patched
0 critical, 1 high severity in production deps — js-yaml@4.3.0 (high), hono@4.12.32 (low)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/nweii/obsidian-remote-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check