Cursidian

Cursidian

Enables Cursor agents to read, write, search, and manage local Obsidian vaults via 13 tools with safe writes and direct filesystem access.

Category
访问服务器

README

Cursidian

Implementation of the Obsidian llm-wiki concept for Cursor, using an MCP designed to minimise token consumption and maximise relevant results. Includes slop removal tools.

Getting Started:

  • Download Obsidian, create an empty vault, make a note of its location.
  • Install the "LLM Slop Detector" plugin in your Cursor (thias-se.llm-slop-detector)
  • Install this MCP and the skills into your Cursor.
  • Restart / Reload Cursor.
  • Enter this prompt: "I have just created an empty obsidian vault at vault location, please set up my wiki there"

Let it do its thing, it will take about 5 minutes and burn like 30k tokens. Auto is fine, you don't need Claude for this! At this point you don't even need to be running Obsidian any more, the point of it was just to create the vault structure.

Once it is set up you can just ask Cursor agents for stuff like "create pages in my wiki about my project, as many as you need to capture everything." Or "refactor my ui to be more colourful, using the design notes in my wiki" etc. The sky is the limit. The more effort you ask agents to put into your wiki, the more you get out of it.

And notice the distinction there. the more effort you ask your agents to put in, you don't write this thing yourself. Have the Cursor agents do everything, they write the wiki, they read it, they lint it, check it and maintain it. You can dump entire ebooks into it, or have it review your most recent 100 cursor chat transcripts and save any relevant information it finds to your wiki. Optionally, ask it to "remove all slop from my wiki" once in a while.

You can dip in to read it using Obsidian whenever you like, but really its a resource for Cursor agents to store information about your projects, your goals, your design desisions and rules and so on.

Credits

I took the "Obsidian Wiki" concept from Andrej Karpathy, and I drew inspiration from this existing Obsidian MCP: @istrejo/obsidian-mcp. But really the credit goes to Fable, Grok and Composer 2.5, I am just their conductor, and I used Cursor to create this.

Anyway that's the end of the human-written portion of the readme, the rest is by Agents and for Agents really, but feel free to keep reading if you want.

Emjoy! John.

Features

  • 4 MCP tools - note, search, graph, vault (action-dispatch surface)
  • Safe writes - patch inferred when old_string/new_string are set; replace_section for heading edits
  • Agent-friendly search - default limit 10, compact format, stopwords stripped, token-AND with OR/typo fallback; hits include title/summary/tags
  • Auto timestamps - note create/update/frontmatter set created/updated automatically
  • Optimistic concurrency - revisionHash on read (full note), expectedRevision on write; contentHash / expectedHash remain as body-only / deprecated alias
  • Operation journals + undo - mutating calls return operationId; vault history / undo reverse journaled work
  • Typed manifest - vault manifest for _meta/manifest.md (no hand-edited ledger lines)
  • Signature-based caches - index and search snapshots invalidate when files change on disk (including Obsidian edits)
  • Deslop gate - npm run build runs slop:check first; strips AI typography and decorative emoji from the repo (and optionally the wiki vault)
  • Wiki skills - nine Cursor skills that drive the MCP tools for ingest, query, lint, capture, update, status, and deslop
  • Skill contract gate - npm run skills:check rejects retired tool names, phantom health fields, and read-only write leaks

Tools

Tool Actions Purpose
note read, create, update, delete, rename, frontmatter Note CRUD, safe edits, metadata; returns revisionHash / operationId
search content (default), by_tags, list, recent, tags Find and enumerate notes (paginated; may report incomplete)
graph - One-hop neighborhood (resolved + unresolved outgoing, paginated backlinks)
vault health, sync_index, create_folder, list_folders, delete_folder, log, history, undo, manifest Health, catalog, folders, bookkeeping, undo, ingest ledger

Requirements

  • Node.js >= 20
  • An absolute Obsidian vault path via OBSIDIAN_VAULT_PATH

Quick start (published package)

Add to ~/.cursor/mcp.json (Windows: %USERPROFILE%\.cursor\mcp.json):

{
  "mcpServers": {
    "cursidian": {
      "command": "npx",
      "args": ["-y", "cursidian"],
      "env": {
        "OBSIDIAN_VAULT_PATH": "C:\\Users\\you\\Documents\\MyVault"
      }
    }
  }
}

Unix:

"OBSIDIAN_VAULT_PATH": "/Users/you/Documents/MyVault"

Reload Cursor. The config key "cursidian" appears as MCP server user-cursidian.

See also examples/cursor-mcp.json.

Local development setup

git clone https://github.com/CoolJohn-lab/Cursidian.git
cd Cursidian
npm install
npm run build
npm test

Point Cursor at the built entrypoint:

{
  "mcpServers": {
    "cursidian": {
      "command": "node",
      "args": ["/absolute/path/to/Cursidian/dist/index.js"],
      "env": {
        "OBSIDIAN_VAULT_PATH": "/absolute/path/to/your/vault"
      }
    }
  }
}

Wiki skills + MCP

Cursidian is a two-layer product:

Layer Role Where
MCP server Runtime vault I/O for agents Published cursidian package / local dist/
Wiki skills Workflow instructions (ingest, query, lint, ...) skills/wiki/ copied into ~/.cursor/skills/

The MCP server is the only way agents read or write vault markdown. Skills do not open vault files with the IDE filesystem tools or shell - they call user-cursidian (note, search, graph, vault). If an MCP call fails, the skill reports the failure and stops (no silent filesystem fallback).

Source documents outside the vault (PDFs, repo files, URLs) may be read with normal tools for ingest; the moment content enters the vault, it is MCP-only.

How agents use both

  1. Cursor loads skills from ~/.cursor/skills/ when the user asks something matching a skill description (e.g. "add this to the wiki", "what do I know about X").
  2. The skill tells the agent which MCP actions to call, in what order (cheap search first, full note read only when needed).
  3. Writes follow the safe-write protocol: note read -> revisionHash -> narrowest note update with expectedRevision. Mutating skills keep an operation-ID stack and call vault undo in reverse on failure after writes.
  4. After multi-page edits, skills typically call vault sync_index (rebuild index.md) and vault log (append log.md / optional hot.md), then verify with sync_index dryRun: true expecting wouldWrite: false.

Shared schema and the full MCP contract live in the llm-wiki skill.

Install skills

npm run skills:install
# or from the published package:
npx cursidian-skills

That removes then copies the nine skill folders into ~/.cursor/skills/ (never symlink; copying into an existing folder nests skill/skill/SKILL.md). Full steps: skills/wiki/INSTALL.md. Re-run after skill or MCP tool-surface changes, then start a new agent chat so Cursor re-discovers them.

Exception: wiki-slop runs the npm deslop scripts against the same vault path as MCP (deterministic lint/fix on disk); it does not invent a second vault location.

Skill Purpose Typical MCP use
llm-wiki Theory, schema, MCP contract Reference for other skills
wiki-query Read-only Q&A search -> optional note read / graph (no writes)
wiki-lint Vault health / consolidate vault health, then note/vault fixes
wiki-setup Bootstrap vault structure vault folders, note create special files
wiki-ingest Distill docs/URLs into pages search + note create/update + vault manifest/log/sync
wiki-capture Save session findings note create/update (_raw/ or full pages); merge on duplicate
wiki-update Sync a project into the wiki git delta outside vault; writes via note/vault manifest
wiki-status Delta / what next / hot.md vault manifest read; _raw/ with includeOperational; hot refresh on request
wiki-slop Deslop repo or vault npm slop:* scripts (same vault path as MCP)

Deslop (LLM-slop)

Keeps AI typography (em/en dashes, curly quotes, ellipsis, arrows) and decorative emoji out of the package and, when you ask, the Obsidian vault. Uses llm-slop-detector with this repo's .llmsloprc.json.

Command Purpose
npm run slop:check Scan this repo; exit non-zero if dirty
npm run slop:fix Auto-fix chars/emoji in this repo
npm run slop:check:wiki Scan the vault (OBSIDIAN_VAULT_PATH or mcp.json)
npm run slop:fix:wiki Auto-fix chars/emoji in the vault
npm run build prebuild -> slop:check, then tsc

Wiki scans use the same rules but do not gate build (the vault lives outside the package). Phrase-pack hits need a manual rewrite; chars/emoji are auto-fixed. Prefer the wiki-slop skill over ad-hoc CLI flags.

Safe write workflow

  1. Read - note with action: "read"; note the revisionHash (full note) and legacy contentHash (body only).
  2. Edit - note with action: "update" using the safest mode (patch, replace_section, append, prepend, or replace).
  3. Pass expectedRevision from step 1 to detect concurrent edits (including frontmatter-only changes). expectedHash still works as a deprecated body-hash alias.
  4. On success, record operationId when present. To reverse: vault undo with operationId and confirm: true.

Undo example

{ "action": "history", "limit": 10 }
{ "action": "undo", "operationId": "<id-from-mutation>", "confirm": true }

Manifest example

{
  "action": "manifest",
  "manifestOperation": "upsert_source",
  "sourceKey": "C:/abs/path/paper.pdf",
  "sourceIngested": "2026-07-13T00:00:00Z",
  "sourcePages": ["concepts/foo"]
}

Security model

Cursidian is a local stdio MCP server. It trusts the Cursor process that launches it and the OS user that owns the vault directory. There is no network attack surface in normal use; hardening focuses on path containment, bounded I/O, and recoverable writes when agents or external editors touch the vault.

Layer What it guarantees
Lexical containment Resolved paths must stay under OBSIDIAN_VAULT_PATH (blocks ../ and absolute escapes).
Real-path containment Symlinks/junctions that resolve outside the vault are rejected before reads and writes.
Symlink-safe discovery Vault scans use followSymbolicLinks: false and filter results whose real path escapes the vault.
Atomic single-file writes Creates use exclusive open; updates use same-directory temp + rename under a per-path lock.
Optimistic concurrency revisionHash / expectedRevision checked under the mutation lock; frontmatter-only external edits are detected.
Multi-file rollback Rename (including source backup), backlink rewrites, and vault log (log + hot) journal together and roll back on failure; partial_update with sideEffects: "partial" only when rollback itself fails.

For untrusted agents or shared machines, run with OBSIDIAN_READ_ONLY=true and restrict vault directory ACLs to least privilege.

Backups (.cursidian-trash)

When OBSIDIAN_BACKUP_ENABLED is true (default), each mutating MCP call journals under .cursidian-trash/<operationId>/ (prior snapshots for every affected path, including creates so undo can remove them):

Operation Journaled
note update / replace / patch / section edit Yes
note frontmatter set / merge / delete Yes
note delete Yes
note rename Yes (source + each rewritten backlink/index file)
note create (incl. overwrite) Yes
vault sync_index Yes (index.md)
vault log Yes (log.md; hot.md when updated)
vault manifest Yes

Legacy .obsidian-mcp-trash entries are migrated into .cursidian-trash/_legacy-migrated/ on first backup (not deleted). Retention keeps the newest 50 operation folders by default; older folders are pruned automatically. With backups disabled, mutations still succeed but return undoAvailable: false.

Environment variables

Variable Required Description
OBSIDIAN_VAULT_PATH Yes Absolute path to your Obsidian vault (~ / %USERPROFILE% expanded)
OBSIDIAN_READ_ONLY No Set to true to disable writes
OBSIDIAN_MAX_FILE_SIZE No Max file size in bytes (default 10 MB)
OBSIDIAN_BACKUP_ENABLED No Pre-write backups to .cursidian-trash (default true; set false to disable)
OBSIDIAN_LOG_LEVEL No debug, info, warn, error (default info)

Development

npm run dev      # run server directly (stdio)
npm test         # vitest with coverage
npm run test:file -- tests/tools/read-note.test.ts  # focused test file, no coverage threshold
npm run test:clean # coverage run through npm env cleanup for Cursor sandboxes
npm run lint     # eslint
npm run typecheck
npm run build    # slop:check (prebuild), then tsc
npm run verify   # lint + typecheck + test + build + MCP integration + skills check + fixture smoke
npm run smoke    # live smoke against OBSIDIAN_VAULT_PATH (unique path, finally cleanup)
npm run skills:check
npm run mcp:test -- suite smoke

In Cursor agent sandboxes, npm may inherit a deprecated npm_config_devdir value. Use npm run verify or npm run test:clean so child processes run through the repository's npm environment cleanup. On Windows PowerShell, prefer these scripts over manual && command chains.

Isolated tool calls:

npm run mcp:test -- note --action read --path index
npm run mcp:test -- search --query "wiki index" --limit 10
npm run mcp:test -- --list

License

MIT - see LICENSE.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选