Borrowing it
Nothing to install: this file belongs to bepitulaz/obsidian-multivault-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/bepitulaz/obsidian-multivault-mcp/main/AGENTS.mdgit clone --depth 1 https://github.com/bepitulaz/obsidian-multivault-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/instructions/bepitulaz/obsidian-multivault-mcp/agents-md)<a href="https://agentmods.dev/instructions/bepitulaz/obsidian-multivault-mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/bepitulaz/obsidian-multivault-mcp/agents-md.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.01376 | $0.01376 |
| Opus 5 | $0.00688 | $0.00688 |
| Sonnet 5 | $0.00275 | $0.00275 |
| Haiku 4.5 | $0.00138 | $0.00138 |
Grade B, and why
obsidian-multivault-mcp AGENTS.md scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks for rootmediumPrivilege escalation
A mod that escalates privileges can change anything on the machine, not only the project.
cd ~/obsidian-multivault-mcp && git pull && npm ci && npm run build && sudo systemctl restart obsidian-multivault-mcp Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
`curl -s -o /dev/null -w '%{http_code}\n' localhost:8787/healthz` → `200`. How it starts
The opening of the file, as written. The whole thing — 86 lines — stays where its author put it; the contents beside it link to each section on GitHub.
AGENTS.md — deploying this MCP server on the VPS
Mission: deploy this repository as the public, OAuth-protected HTTPS MCP server so Claude's remote connectors (mobile + desktop + web) can reach the Obsidian vaults on this VPS.
The authoritative, copy-pasteable, step-by-step runbook is DEPLOY.md — follow it exactly. This file is the brief around it: the goal, the inputs to gather first, the guardrails, and how to know you're done. When the two disagree, DEPLOY.md's commands win.
Do not touch the existing stdio-over-SSH path (used by Claude Desktop today). The HTTP service is additive and runs independently as its own systemd unit.
VPS facts (example — change to match yours)
| Run user | youruser |
| App / repo dir | /home/youruser/obsidian-multivault-mcp |
| Public hostname | 203-0-113-10.sslip.io → 203.0.113.10 (sslip.io — no domain needed) |
| Local port | 8787 (Node binds 127.0.0.1 only; Caddy fronts :443) |
| Node | via asdf — resolve the concrete path with asdf which node |
Two people, each with their own login passphrase mapped to their own vault (this is what fixes both landing on the same vault). Passphrases must be distinct:
| id | vault |
|---|---|
alice |
/home/youruser/alice-vault |
bob |
/home/youruser/bob-vault |
Gather BEFORE you start
- Two strong, DISTINCT passphrases — one for
alice, one forbob(e.g.openssl rand -base64 24each). Record which is whose to report back to the human. They go only in/etc/obsidian-multivault-mcp-users.json(mode 600) — never in the repo. - Confirm both vault paths exist:
ls -d /home/youruser/alice-vault /home/youruser/bob-vault. If either differs, stop and ask the human; adjust the users file to the real paths. - Repo clone auth: if this GitHub repo is private, set up a deploy key or token before cloning.
- Inbound ports 80 and 443 open (host
ufwand any cloud-provider firewall) — Let's Encrypt needs both.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 86 lines · 1,376 tokens per session scan B b21ee99d92aa
obsidian-multivault-mcp AGENTS.md is an instructions file published in the GitHub repository bepitulaz/obsidian-multivault-mcp (61 stars, last pushed 2mo ago), licensed MIT. It adds 1,376 tokens to every session, about $0.0069 per session on Opus 5. A static security scan graded it B with 2 findings (asks for root, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other instructions, from other repositories
next.js AGENTS.md
AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.
codex AGENTS.md
AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.
vscode buildNext.instructions.md
Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).
vscode oss-third-party-notices.instructions.md
Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).
langchain AGENTS.md
AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.
spec-kit AGENTS.md
AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.