obsidian-local-rest-api — security grade SAFE, quality 70/100

Security audit verdict: SAFE · quality 70/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by coddingtonbear · MCP Server · ★ 2.9k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is obsidian-local-rest-api safe to install? View the security audit →

Featured in: Obsidian, Second Brain & LLM Wiki

About obsidian-local-rest-api

Local REST API & MCP Server Give your scripts, browser extensions, and AI agents a direct line into your Obsidian vault via a secure, authenticated REST API. Interactive API docs: https://coddingtonbear.github.io/obsidian-local-rest-api/ What you can do Access your vault through the REST API or the built-in MCP server — both interfaces expose the same core capabilities, so scripts, browser extensions, and AI agents all speak the same language. Read, create, update, or delete notes — full CRUD on any file in your vault, including binary files Surgically patch specific sections — target a heading, block reference, or frontmatter key and append, prepend, or replace just that section without touching the rest of the file Search your vault — simple full-text search or structured JsonLogic queries against note metadata (frontmatter, tags, path, content) Access the active file — read or write whatever note is currently open in Obsidian Work with periodic notes — get or create daily, weekly, monthly, quarterly, and yearly notes List and execute commands — trigger any Obsidian command as if you'd used the command palette Query tags — list all tags across your vault with usage counts Open...

Quick Facts

Stars2,868
Forks336
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score69.9241600396734/100
Open Issues2
Last Updated2026-08-31
Created2022-01-25
Platformsmcp, node
Est. Tokens~17k

Compatible Skills

These tools work well together with obsidian-local-rest-api for enhanced workflows:

  • freee-mcp — semantic(0.47)+same_lang+similar_pop+shared_platform (51%)
  • mcp-server — semantic(0.58)+same_lang+similar_pop+shared_platform (50%)
  • drawio-mcp-server — semantic(0.42)+same_lang+similar_pop+shared_platform (50%)
  • brave-search-mcp-server — semantic(0.40)+same_lang+similar_pop+shared_platform (49%)
  • airtable-mcp-server — semantic(0.40)+same_lang+similar_pop+shared_platform (49%)

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is obsidian-local-rest-api?

obsidian-local-rest-api is A secure REST API and Model Context Protocol (MCP) server for your vault.. It is categorized as a MCP Server with 2.9k GitHub stars.

What programming language is obsidian-local-rest-api written in?

obsidian-local-rest-api is primarily written in TypeScript.

How do I install or use obsidian-local-rest-api?

You can find installation instructions and usage details in the obsidian-local-rest-api GitHub repository at github.com/coddingtonbear/obsidian-local-rest-api. The project has 2.9k stars and 336 forks, indicating an active community.

What license does obsidian-local-rest-api use?

obsidian-local-rest-api is released under the MIT license, making it free to use and modify according to the license terms.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools