io.github.zachhannum/obelisk
NPM · OBELISK-MCP · SCANNED SEP 21
Comment on a passage of an Obsidian note, and propose suggested edits.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- No production dependencies, so there is no dependency health to assess. View diagnostics → Pass
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to zachhannum/obelisk). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 16 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 886 tokens (~221/item across 4 items; 4 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management60
- Stability observed for 18 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 4 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 4 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.zachhannum/obelisk MCP server?
io.github.zachhannum/obelisk runs locally as an npm package, launched with npx -y obelisk-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · obelisk-mcp
claude mcp add zachhannum-obelisk -- npx -y obelisk-mcp
{
"mcpServers": {
"zachhannum-obelisk": {
"command": "npx",
"args": [
"-y",
"obelisk-mcp"
]
}
}
} {
"servers": {
"zachhannum-obelisk": {
"command": "npx",
"args": [
"-y",
"obelisk-mcp"
]
}
}
} codex mcp add zachhannum-obelisk -- npx -y obelisk-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"zachhannum-obelisk": {
"type": "local",
"command": [
"npx",
"-y",
"obelisk-mcp"
],
"enabled": true
}
}
} openclaw mcp add zachhannum-obelisk --command npx --arg -y --arg obelisk-mcp
mcp_servers:
zachhannum-obelisk:
command: "npx"
args: ["-y", "obelisk-mcp"] {
"McpServers": {
"zachhannum-obelisk": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"obelisk-mcp"
]
}
}
} assistant mcp add zachhannum-obelisk -t stdio -c npx -a -y obelisk-mcp
{
"mcpServers": {
"zachhannum-obelisk": {
"command": "npx",
"args": [
"-y",
"obelisk-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 8 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 6 Sept 26 +16
- Malware scan: unverified → pass ▲ security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Analysed npm/obelisk-mcp@0.2.0
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | zachhannum/obelisk |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/zachhannum/obelisk/.github/workflows/release.yml@refs/heads/main |
| Rekor log index | 2720929617 |
| Predicate type | https://slsa.dev/provenance/v1 |
| Subject digest | sha512:eb995778f156823b9bcb63b15ce13236a009ba827b81182d8068a026cc66415c36a274b06579a52d5aad4b4af64a06b1b630f0dd17ddfcaa78c75d276 |
Background: How many MCP packages publish verified provenance →
Dependencies 0 packages
| Packages resolved | 0 |
|---|---|
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
obelisk_comment Comment on a passage ~362
Leave a comment on one passage of a note. It appears in the reader's Obsidian sidebar, badged as coming from an agent. `quote` is the anchor and must appear in the note verbatim — the same characters, punctuation, capitalization and spacing. Copy it from obelisk_list; do not retype it or tidy it up. There is no way to pass a line or column, and you should not try to count them: the quote is the anchor and the tool does the arithmetic. If the quote is not found, or is found more than once, nothing is written and you are told which. `body` is markdown. To propose a specific rewrite, put it in a ```suggestion fenced block inside the body — its contents replace exactly the quoted passage when the reader clicks Apply, so a comment can explain itself and propose the change at once.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | The comment, as markdown. A ```suggestion block inside it proposes a replacement for the quoted passage. |
| model | string | – | Recorded on the comment as the model that wrote it. |
| nearLine | integer | – | Only when the quote appears more than once: the body line number, as printed by obelisk_list, of the occurrence you mean. |
| note | string | yes | Path to the note, relative to the vault root or to the working directory. Absolute paths reach a note in another vault. `.md` optional. |
| quote | string | yes | The passage to anchor to, copied verbatim out of the note. |
| run | string | – | Groups the comments from one review pass so the reader can dismiss them together. Defaults to this session's id; pass the same value for every comment in a pass. |
No output schema declared.
No examples provided.
obelisk_list List a note's comments ~197
Every Obelisk comment on a note, with the passage each one is anchored to, plus the note body with line numbers. Read this before commenting: the `quote` you pass to obelisk_comment has to be copied out of this body character for character, and the line numbers here are what `nearLine` refers to. It is also the first half of the other flow — a person leaves a comment asking for something, you read it here, make the edit yourself, and call obelisk_resolve.
| Name | Type | Req | Description |
|---|---|---|---|
| includeBody | boolean | – | Include the line-numbered note body. Defaults to true; turn it off only if you already have the text. |
| note | string | yes | Path to the note, relative to the vault root or to the working directory. Absolute paths reach a note in another vault. `.md` optional. |
| openOnly | boolean | – | Only unresolved comments. Defaults to false. |
No output schema declared.
No examples provided.
obelisk_reply Reply to a comment ~165
Add a reply to an existing comment thread. A reply is markdown too, so a counter-proposal is a ```suggestion block in one. Use this to answer a question a person asked in a comment. To say that you have done what a comment asked, edit the note and call obelisk_resolve instead — a reply saying "done" leaves the thread open.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | The reply, as markdown. |
| id | string | yes | The comment's id, from obelisk_list. |
| model | string | – | Written into the reply's author field. |
| note | string | yes | Path to the note, relative to the vault root or to the working directory. Absolute paths reach a note in another vault. `.md` optional. |
No output schema declared.
No examples provided.
obelisk_resolve Resolve or reopen a comment ~162
Mark a comment settled — the reader's sidebar grays it out and drops it from the open count. This is what closes the loop on a comment a person left for you: read it, make the edit in the note yourself, then resolve it. Resolving a comment you did not write is allowed, but it records that what the comment asked for has been done, so resolve only once it has.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The comment's id, from obelisk_list. |
| note | string | yes | Path to the note, relative to the vault root or to the working directory. Absolute paths reach a note in another vault. `.md` optional. |
| reopen | boolean | – | Mark it open again instead. Defaults to false. |
No output schema declared.
No examples provided.
What is the io.github.zachhannum/obelisk MCP server?
io.github.zachhannum/obelisk is an MCP server listed in the public MCP registry as io.github.zachhannum/obelisk. Comment on a passage of an Obsidian note, and propose suggested edits. This page covers its npm package (obelisk-mcp).
Is the io.github.zachhannum/obelisk MCP server safe to use?
io.github.zachhannum/obelisk scores 89 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 21 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.zachhannum/obelisk MCP server expose?
io.github.zachhannum/obelisk exposes 4 tools: obelisk_list, obelisk_comment, obelisk_reply, obelisk_resolve. Their descriptions and schemas cost roughly 886 tokens of context every time the server is loaded.
Is the io.github.zachhannum/obelisk MCP server still maintained?
io.github.zachhannum/obelisk is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.zachhannum/obelisk MCP server under?
io.github.zachhannum/obelisk declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.