obsidian-multivault-mcp: Instructions file for Codex

AGENTS.md

obsidian-multivault-mcp AGENTS.md is an instructions file for Codex, OpenCode from bepitulaz/obsidian-multivault-mcp. It costs 1,376 tokens per session, scanned B, original, MIT.

Deployment instructions for Obsidian Multivault MCP, a service that lets remote AI assistants access separate Obsidian note vaults through a protected web connection. They point to the detailed deployment runbook and list the required server setup.

In plain words
What is it for?
Use them to deploy the service on a VPS, configure its hostname and local port, keep each person's vault separate, and verify the finished setup.
Why use it?
They reduce deployment mistakes and ensure the new web service does not disrupt the existing SSH connection method.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md. Also seen: mentions AGENTS.md.

This is bepitulaz/obsidian-multivault-mcp's own configuration. It tells Codex and OpenCode how to work on obsidian-multivault-mcp itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything obsidian-multivault-mcp configures →

Not installable: its command points at a path on the author’s own machine, so it runs nowhere else. The line is /home/youruser/obsidian-multivault-mcp.

Reuse

Borrowing it

Nothing to install: this file belongs to bepitulaz/obsidian-multivault-mcp. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/bepitulaz/obsidian-multivault-mcp/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/bepitulaz/obsidian-multivault-mcp

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for obsidian-multivault-mcp AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/bepitulaz/obsidian-multivault-mcp/agents-md.svg)](https://agentmods.dev/instructions/bepitulaz/obsidian-multivault-mcp/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/bepitulaz/obsidian-multivault-mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/bepitulaz/obsidian-multivault-mcp/agents-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,376 This file is loaded in full into every session.
When invoked 1,376 The same file — it is already loaded in full.
Security scan B 2 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.01376 $0.01376
Opus 5 $0.00688 $0.00688
Sonnet 5 $0.00275 $0.00275
Haiku 4.5 $0.00138 $0.00138

Measured 8d ago against content hash b21ee99d92aa, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade B, and why

obsidian-multivault-mcp AGENTS.md scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Asks for rootmediumPrivilege escalation

A mod that escalates privileges can change anything on the machine, not only the project.

cd ~/obsidian-multivault-mcp && git pull && npm ci && npm run build && sudo systemctl restart obsidian-multivault-mcp

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

`curl -s -o /dev/null -w '%{http_code}\n' localhost:8787/healthz` → `200`.
AGENTS.md · 86 lines

How it starts

The opening of the file, as written. The whole thing — 86 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AGENTS.md — deploying this MCP server on the VPS

Mission: deploy this repository as the public, OAuth-protected HTTPS MCP server so Claude's remote connectors (mobile + desktop + web) can reach the Obsidian vaults on this VPS.

The authoritative, copy-pasteable, step-by-step runbook is DEPLOY.md — follow it exactly. This file is the brief around it: the goal, the inputs to gather first, the guardrails, and how to know you're done. When the two disagree, DEPLOY.md's commands win.

Do not touch the existing stdio-over-SSH path (used by Claude Desktop today). The HTTP service is additive and runs independently as its own systemd unit.

VPS facts (example — change to match yours)

Run user youruser
App / repo dir /home/youruser/obsidian-multivault-mcp
Public hostname 203-0-113-10.sslip.io203.0.113.10 (sslip.io — no domain needed)
Local port 8787 (Node binds 127.0.0.1 only; Caddy fronts :443)
Node via asdf — resolve the concrete path with asdf which node

Two people, each with their own login passphrase mapped to their own vault (this is what fixes both landing on the same vault). Passphrases must be distinct:

id vault
alice /home/youruser/alice-vault
bob /home/youruser/bob-vault

Gather BEFORE you start

  1. Two strong, DISTINCT passphrases — one for alice, one for bob (e.g. openssl rand -base64 24 each). Record which is whose to report back to the human. They go only in /etc/obsidian-multivault-mcp-users.json (mode 600) — never in the repo.
  2. Confirm both vault paths exist: ls -d /home/youruser/alice-vault /home/youruser/bob-vault. If either differs, stop and ask the human; adjust the users file to the real paths.
  3. Repo clone auth: if this GitHub repo is private, set up a deploy key or token before cloning.
  4. Inbound ports 80 and 443 open (host ufw and any cloud-provider firewall) — Let's Encrypt needs both.

Read the full file on GitHub · 86 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 86 lines · 1,376 tokens per session scan B b21ee99d92aa

Subscribe to this mod's changes

obsidian-multivault-mcp AGENTS.md is an instructions file published in the GitHub repository bepitulaz/obsidian-multivault-mcp (61 stars, last pushed 2mo ago), licensed MIT. It adds 1,376 tokens to every session, about $0.0069 per session on Opus 5. A static security scan graded it B with 2 findings (asks for root, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens