Obsidian community plugin that exposes the vault as a local MCP server, allowing Claude to read, search, and manage notes.
Obsidian MCP demonstrates solid fundamentals: all 19 tools have clear verb-noun naming (get_, list_, create_, update_, delete_, search_, apply_), descriptions range 50 - 200 chars (well within 10 - 1024 baseline), and input schemas are consistently present with typed parameters. Tool composition is clean, each tool has one responsibility. However, output schemas are not documented in the source code, parameter descriptions lack constraint details (ranges, formats, enums), and error handling guidance is absent. Risk annotations (READ_ONLY, WRITE, DESTRUCTIVE) are present but not formalized as toolAnnotations in the MCP protocol. Descriptions are functional but could be more LLM-optimized with dependency hints and recovery guidance.
Apply a template to a note, inserting the template content at the cursor position or appending to the note.
Create a new note at the given path with the provided content. Returns success status and the created file path.
Delete a note. Moves it to .trash/ if trashOnWrite is enabled, otherwise permanently deletes.
Find notes that share tags or frontmatter keys with the given note. Cheap heuristic, not embedding-based.
Get the daily note for a given date. Accepts ISO (YYYY-MM-DD), 'today', 'yesterday', 'tomorrow', or relative offsets like '+1d', '-7d', '+2w'.
List frontmatter keys used across the vault with usage counts. Optionally restrict to a folder.
Output schemas not documented. Tools return results but LLMs cannot infer field names, types, or structure. Downstream tool chaining is guesswork.
Parameter descriptions lack constraint details. 'limit' params have no min/max bounds stated in descriptions; 'date' format in get_daily_note is documented but others are vague.
No error handling guidance. Destructive tools (delete_note, update_note) lack recovery hints. No dry-run or confirmation pattern for irreversible operations.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 69 | <=2025-11-25 | v2 |
Returns the heading hierarchy of a note (level, text, line offset). Pulled from Obsidian's metadata cache — cheap, no body parse.
Returns plugin version, vault name, read-only state, and the registered tool count. Use this to probe capabilities before invoking other tools.
List wikilinks across the vault that do not yet resolve to a file. Useful for finding link targets to create.
List notes that link to the given note (resolved links only).
List folders in the vault. Use `folder` to scope to a subtree and `recursive` to control depth.
List notes with optional folder filter, recursive flag, sort, and pagination.
List all tags used across the vault with usage counts. Combines inline #tags and frontmatter tags. Sorted by count descending.
List available templates in the vault's templates folder (configured in Obsidian settings).
Open a note in the active Obsidian window. Does not return content — use read_note for that. Useful as a final step after find/search to focus the user's attention.
Read a note's markdown content. Returns parsed frontmatter and the body with the frontmatter block stripped.
Restore a note from .trash/ back to its original location (inferred from the timestamped backup filename).
Search the vault. Filters compose: query (body substring), filename (path/basename substring), tag (e.g. #project), frontmatterKey+frontmatterValue. Use offset+limit to page.
Overwrite a note's content. Optionally backs up the prior content to .trash/ before overwriting.
Risk annotations (READ_ONLY, WRITE, DESTRUCTIVE) are metadata but not formalized as MCP toolAnnotations (readOnlyHint, destructiveHint, idempotentHint). LLMs cannot parse risk from tool definitions.
Pagination parameters (limit, offset) present but no total count or next_cursor returned. Large result sets risk context window exhaustion.