io.obsideo/mcp
NPM · OBSIDEO-MCP · SCANNED SEP 20
Encrypted S3-compatible storage with possession proofs you can verify yourself. 12 GB free.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security99
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 122 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency32
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: the license (PolyForm-Shield-1.0.0) isn't a recognized OSI-approved license. See how to fix → Fail
- Actively maintained (last published 3 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability78
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1490 tokens (~114/item across 13 items; 13 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management93
- Stability observed for 28 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage93
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 79% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.obsideo/mcp server?
io.obsideo/mcp runs locally as an npm package, launched with npx -y obsideo-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · obsideo-mcp
claude mcp add io-obsideo-mcp -- npx -y obsideo-mcp
{
"mcpServers": {
"io-obsideo-mcp": {
"command": "npx",
"args": [
"-y",
"obsideo-mcp"
]
}
}
} {
"servers": {
"io-obsideo-mcp": {
"command": "npx",
"args": [
"-y",
"obsideo-mcp"
]
}
}
} codex mcp add io-obsideo-mcp -- npx -y obsideo-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-obsideo-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"obsideo-mcp"
],
"enabled": true
}
}
} openclaw mcp add io-obsideo-mcp --command npx --arg -y --arg obsideo-mcp
mcp_servers:
io-obsideo-mcp:
command: "npx"
args: ["-y", "obsideo-mcp"] {
"McpServers": {
"io-obsideo-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"obsideo-mcp"
]
}
}
} assistant mcp add io-obsideo-mcp -t stdio -c npx -a -y obsideo-mcp
{
"mcpServers": {
"io-obsideo-mcp": {
"command": "npx",
"args": [
"-y",
"obsideo-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +12
- Stability: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Malware scan: unverified → pass ▲ security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Stability: pass → 0.80 functional
- Package version: 0.7.1 → 0.7.2 functional
- 15 Sept 26 −15
- Malware scan: pass → unverified ▼ security
- Stability: 0.97 → pass security
- License: pass → fail ▼ functional
- Schema quality: pass → fail ▼ functional
- Tool coverage: 67% → 79% ▲ functional
- Schema quality: good → excellent functional
- Destructive annotations: All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation. functional
- Licence: MIT → PolyForm-Shield-1.0.0 functional
- Package version: 0.1.0 → 0.7.1 functional
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 −3
- Stability: pass → 0.80 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/obsideo-mcp@0.7.2
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 122 packages
| Packages resolved | 122 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
backup_keys Back up the credentials and encryption key ~147
Copy everything needed to recover this account's data (credentials, account signing key, encryption key, upload commitments) to a path the human names. Obsideo holds no copy of the encryption key: if the local file is lost, encrypted objects are unrecoverable no matter how many providers hold them. Call this once right after the account is created and again after any signup that rotates keys. A .tar.gz path produces one archive; a directory path produces plain copies; no path produces an archive in the home directory.
| Name | Type | Req | Description |
|---|---|---|---|
| destination | string | – | Archive path ending in .tar.gz, or a directory; defaults to ~/obsideo-keys-<account>-<date>.tar.gz |
No output schema declared.
No examples provided.
get Retrieve an object ~84
Retrieve an object. Encrypted objects (the default for anything stored through this server) are decrypted automatically with the local key; retrieval from a machine without that key will fail, which is the intended property. Small text objects return inline; pass local_path for anything else.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | – |
| local_path | string | – | Save to this path instead of returning inline |
No output schema declared.
No examples provided.
ls List stored objects ~27
List stored objects (size TAB key), optionally under a prefix.
| Name | Type | Req | Description |
|---|---|---|---|
| prefix | string | – | – |
No output schema declared.
No examples provided.
plan Show the paid plan ~53
Show the account's plan: free tier or paid blocks (200 GB per block, $5/month each), status, period end, and any upgrade offer waiting for the human's agreement. Never changes anything and never contacts Stripe.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
portal Get the billing portal link ~55
Get the Stripe Customer Portal link for a paid plan: cancel, change card, download invoices. For the human to open. Cancelling keeps everything stored and readable; the account returns to its free quota at the end of the paid period.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
put Store an object ~269
Store a local file or inline content as an object. ENCRYPTED BY DEFAULT: the bytes are encrypted client-side with AES-256-GCM using a locally generated, user-held key before they leave the machine, so the platform stores ciphertext it cannot read. The key lives only in the local config file and Obsideo has no copy: if the user loses it the data is unrecoverable, so tell them to back it up. Pass encrypt=false only when another tool must read the stored bytes directly (S3 interop); that stores plaintext. Zero-byte objects are rejected. Objects are replicated to 3 providers and verified on a continuous cryptographic challenge cycle. The first call on a fresh machine also creates the account and can take 20 to 50 seconds; progress is reported while it runs. Encrypted objects are readable only with this machine's key: there is no cross-user sharing of encrypted objects.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | Inline UTF-8 content (alternative to local_path) |
| encrypt | boolean | – | Defaults to true. Set false to store plaintext for S3 interop. |
| key | string | yes | Object key, e.g. backups/db-2026-07-19.sql.zst |
| local_path | string | – | Path of a local file to upload |
No output schema declared.
No examples provided.
rm Delete an object ~20
Delete an object by key.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | – |
No output schema declared.
No examples provided.
signup_start Start Obsideo signup (or claim the trial) ~174
Start Obsideo signup: emails a 6-digit verification code (12 GB free tier, no card, no expiry). If a no-email trial is configured on this machine, this CLAIMS it in place: same account, bucket, keys and data, only the quota rises. Otherwise it creates a new account for the email. Use a real inbox you or your human can read; documentation placeholders and disposable domains are refused with labeled errors. Then call signup_verify.
| Name | Type | Req | Description |
|---|---|---|---|
| abandon_trial | boolean | – | Only when the email already has its own account (email_in_use): sign in to that account instead of claiming; the trial and its data are left behind. |
| string | yes | Real email address; it is the account identity | |
| source | string | – | Where you found Obsideo (defaults to 'mcp') |
No output schema declared.
No examples provided.
signup_verify Complete Obsideo signup ~116
Complete signup with the emailed code. When claiming a trial, nothing but the quota and the identity changes (credentials stay valid, no propagation wait). For a new account, generates the Ed25519 account signing keypair locally (only the public half is sent) and stores S3 credentials in ~/.obsideo/mcp.json; re-running that path rotates credentials and keypair with no overlap, so do not re-run to retry.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | The 6-digit code from the email |
| string | yes | – |
No output schema declared.
No examples provided.
trial Create an instant trial account (no email) ~215
Create a free Obsideo account with no email and no human in the loop: a small proof-of-work and a ~10 second wait in place of identity. Returns a real account on the production network (100 MB, about 7 days, RF=3 replication, continuous possession proofs) and saves credentials locally. You usually do NOT need to call this: the first put/get/ls/usage auto-creates a trial if no account is configured. Call it to provision explicitly. To keep data beyond the trial, claim it with an email via signup_start (same account and data, quota rises to 12 GB). Takes about 15 to 30 seconds (proof of work plus a 10 second issuance window); progress is reported while it runs.
| Name | Type | Req | Description |
|---|---|---|---|
| replace | boolean | – | Only if the human explicitly wants a fresh, separate account: replace the account already configured on this machine. Without it, this tool refuses when an account exists. |
| source | string | – | Where you found Obsideo (defaults to 'mcp') |
No output schema declared.
No examples provided.
upgrade Get a checkout link for a paid plan ~141
Get a Stripe-hosted checkout link for a paid plan of N x 200 GB blocks at $5/month per block. This tool charges NOTHING and changes nothing: the human opens the link and pays on Stripe's page, and the quota rises after payment. Call it only when the human has asked for more space, and hand the link back to them; do not open or submit it yourself. If the account already has a paid plan this returns the plan instead (plan size is never changed from here; only the human's click on Obsideo's emailed agree link does that).
| Name | Type | Req | Description |
|---|---|---|---|
| blocks | integer | – | Number of 200 GB blocks (default 1) |
No output schema declared.
No examples provided.
usage Show storage usage ~14
Show account storage usage versus quota.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
verify Prove an object is really stored (client-side) ~175
Independently verify that the network still holds an object, without downloading it. Challenges each provider directly, recomputes the merkle root from your own copy of the bytes, and checks each provider's cryptographic signature. Trusts nothing the coordinator says for the verdict. Objects stored through this server verify at full strength with no extra arguments, because their commitment was recorded locally at upload time. Pass local_path (your copy of the stored file) to prove possession against a file on disk instead. Returns how many providers proved possession right now and whether any returned bad data.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | Object key to verify, e.g. backups/db-2026-08-13.sql.zst |
| local_path | string | – | Your local copy of the stored bytes (optional; only needed for objects this server did not upload) |
No output schema declared.
No examples provided.
What is the io.obsideo/mcp server?
io.obsideo/mcp is listed in the public MCP registry as io.obsideo/mcp. Encrypted S3-compatible storage with possession proofs you can verify yourself. 12 GB free. This page covers its npm package (obsideo-mcp).
Is the io.obsideo/mcp server safe to use?
io.obsideo/mcp scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.obsideo/mcp server expose?
io.obsideo/mcp exposes 13 tools: trial, signup_start, signup_verify, put, get, and 8 more. Their descriptions and schemas cost roughly 1,490 tokens of context every time the server is loaded.
Is the io.obsideo/mcp server still maintained?
io.obsideo/mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.obsideo/mcp server under?
io.obsideo/mcp declares the PolyForm-Shield-1.0.0 licence, which is not on the OSI-approved list. Read the terms before using it at work, and note this covers the source only, not the cost of any service it calls.