Skip to main content
Glama
aliasunder

Vault Cortex Obsidian MCP Server

CI Gitleaks Trivy GitHub Release npm OpenSSF Scorecard OpenSSF Best Practices Ask DeepWiki vault-cortex MCP server

Vault Cortex is a standalone MCP server that gives any AI agent hybrid search, task management, structured memory, and read/write access to your Obsidian vault. No plugins, no running Obsidian, no separate bridge. One Docker container, your vault folder, a full tool suite + guided prompts. Run it on a remote server with Obsidian Sync, and the same vault is accessible from your phone, claude.ai, or any remote MCP client, secured with OAuth 2.1. Deploy it with one click or self-host it; either way, the vault is always yours.

Contents — What you get · Quick Start · How It Works · Hybrid Search · Memory · Tasks · Files · Tools · Prompts · Properties · Config · Daily Notes · Data Integrity · Auth · Deployment · One-click Deploy · Community Deployments

What you get

  • Remote access — works from your phone, a remote server, or any MCP client via OAuth 2.1. One click on Render or Railway gets you there with no server to manage; a VPS works too.

  • Plugin-free — Obsidian doesn't need to be running. The server works directly with .md files on disk. Headless sync keeps the vault current.

  • Hybrid search — FTS5 keyword matching + vector semantic similarity via RRF fusion, refined by cross-encoder reranking for intent-heavy queries. Keywords stay precise on exact terms and jargon; vectors find notes even when your words differ from the vault's.

  • Structured memory — dated, append-only entries accumulate into a personal knowledge layer, auto-initialized for AI personalization. Topic recall answers "what do I think about X?" with the current take and the dated history behind it — evolution included.

  • Tasks — Kanban-aware task queries and updates: triage by status, dates, or priority, then complete, reprioritize, or move tasks between lanes in one call. Completing a recurring task spawns its next occurrence. Parses both Tasks plugin emoji and Dataview inline-field formats.

  • Link graph — backlinks, outgoing links, and orphan detection across the vault

  • Files — read the vault's non-markdown files too: images arrive as actual images (shrunk to fit when needed), PDFs as structured text or rendered pages, canvases as readable outlines, data files as text

  • Obsidian-native — understands frontmatter, wikilinks, tags, headings, and daily notes

  • Guided workflows — built-in prompts for vault health, memory review, and daily reconciliation — assembled from live vault data each time

Tested across a 15-day trip through Europe. 30+ sessions from a phone, 216 tool calls, zero laptop access needed. Writes in one session were immediately available in the next, across cities and days.


Related MCP server: Vault MCP Server (mschuchard)

Quick Start

Local (2 minutes — Docker + your vault folder)

Prerequisites: Docker (or a Docker-compatible runtime, e.g. OrbStack, Colima, Podman), Node.js >= 22.12 (only for the CLI — the server itself runs in Docker), and an Obsidian vault (or any folder of .md files).

npx vault-cortex@latest init

That's it — the CLI asks for your vault path, generates the auth token and config files, starts the server, and prints the connection details for your MCP client (CLI reference →).

Set up with the CLI? It manages the server from here on — configure, upgrade, start, restart, logs, down (CLI reference →).

Set up with Compose? Stick with Compose for updates too (docker compose pull && docker compose up -d) — the CLI and Compose manage the container independently.

# 1. Get the quickstart files
curl -O https://raw.githubusercontent.com/aliasunder/vault-cortex/main/deploy/local/docker-compose.yml
curl -O https://raw.githubusercontent.com/aliasunder/vault-cortex/main/deploy/local/.env.example

# 2. Configure
cp .env.example .env
# Edit .env — set MCP_AUTH_TOKEN (openssl rand -hex 32) and VAULT_PATH

# 3. Start
docker compose up

Full local guide → (includes Windows setup)

Remote (access from anywhere)

Your vault on a server, kept current by Obsidian Sync, reachable from your phone, claude.ai, or any MCP client. The one-click options ask for your vault name and timezone (plus the vault password if your vault is encrypted), then handle HTTPS, restarts, a generated MCP token, and persistent storage. Once deployed, a setup page walks you through signing in to Obsidian Sync in your browser. On your own server the CLI asks for the public URL and vault name, captures the Sync token for you, and generates the MCP token; HTTPS is yours to set up.

Railway

Render

Self-hosted

Deploy on Railway

Deploy to Render

CLI setup →

Account

Railway on the Hobby plan or higher — the 5 GB volume is included

Render with a card on file

A VPS with Docker

Cost

Usage-metered: typically $20–30 USD/mo for a personal vault — a little under Render for a quiet vault, a little over for a busy one

Flat: about $26 USD/mo for the Standard instance (2 GB) and 5 GB disk, billed by the second

Whatever your VPS costs

Pick it if

You want the easier start — the template lands you in a configured project

A predictable bill matters more than setup polish

You already run a server or want full control

Guide

Railway guide →

Render guide →

Remote guide →

All three need an Obsidian Sync subscription. Whichever you pick, the server is replaceable and your vault isn't — it stays in plain Markdown in Obsidian Sync and on your devices; the container only holds a copy.

The setup page. Deploy without an Obsidian Sync token and the server starts in setup mode: opening its URL in a browser lands on a sign-in page at /setup. Enter your Obsidian account credentials once (two-factor supported) — you sign in with Obsidian directly; the server keeps only the Sync token from that sign-in, restarts, and downloads your vault.

Self-hosted: your own VPS

The Vault Cortex CLI sets up the same container on any Linux box you run — you manage the server, the image, and updates. You need Node.js >= 22.12 for the CLI itself; the server runs in Docker.

# On your VPS:
npx vault-cortex@latest init --mode remote

That's it — the CLI walks through the public URL, Obsidian Sync token (it can run get-sync-token for you), vault name, the vault password for an encrypted vault, and auth config, then starts the server (CLI reference →).

Set up with the CLI? It manages the server from here on — configure, upgrade, start, restart, logs, down (CLI reference →).

Set up with Compose? Stick with Compose for updates too (docker compose pull && docker compose up -d) — the CLI and Compose manage the container independently.

# On your VPS:
mkdir -p /opt/vault-cortex && cd /opt/vault-cortex
curl -O https://raw.githubusercontent.com/aliasunder/vault-cortex/main/deploy/remote/docker-compose.yml
curl -O https://raw.githubusercontent.com/aliasunder/vault-cortex/main/deploy/remote/.env.example
cp .env.example .env
# Edit .env — set MCP_AUTH_TOKEN, PUBLIC_URL, VAULT_NAME (OBSIDIAN_AUTH_TOKEN optional — /setup handles it)
docker compose up -d

Left OBSIDIAN_AUTH_TOKEN empty? Once the container is up, open <PUBLIC_URL>/setup in your browser and sign in — set up HTTPS first, since the page sends your Obsidian password to the server (full walkthrough →).

Connect your MCP client

Setup

Server URL

Local

http://localhost:8000/mcp

Remote (one-click)

https://<host>/mcp — <host> is the domain Render or Railway shows on the service page

Remote (self-hosted)

<PUBLIC_URL>/mcp

Add the server URL in any MCP client — Claude Code, Claude Desktop, Cursor, OpenCode, or any other. OAuth clients open a consent page in your browser — approve with your token, and the client handles token renewal from then on. Clients without OAuth (MCP Inspector, scripts) send the token directly as an Authorization: Bearer header.

Claude Code:

claude mcp add --scope user --transport http vault-cortex http://localhost:8000/mcp   # local (or <PUBLIC_URL>/mcp)

--scope user registers the server for every project; omit it to scope it to the current directory only.

A remote server with a publicly reachable https URL adds directly in Claude Desktop's "Add custom connector" dialog — no file editing. Any http URL — localhost included — is rejected by that dialog, so register it in claude_desktop_config.json instead (Claude Desktop → Settings → Developer → Edit Config opens the file) through the mcp-remote stdio bridge:

{
  "mcpServers": {
    "vault-cortex": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "http://localhost:8000/mcp",
        "--header",
        "Authorization: Bearer <your MCP_AUTH_TOKEN>"
      ]
    }
  }
}

claude.ai (web and mobile) connects to the remote setup only — its connectors are fetched server-side and can never reach localhost.

"Remote MCP server" refers to the connection type (HTTP) — in the local setup the server still runs entirely on your machine.

See Authentication for both methods and token lifetimes.


How It Works

Everything runs in one Docker container, working directly with the .md files on disk:

  • Your vault stays the source of truth — the server reads and writes the same plain Markdown files your Obsidian apps do.

  • Search is derived data — a file watcher keeps the index (keywords + vectors) current as notes change, and it can be rebuilt from your notes at any time.

  • The remote image adds a sync loop — a bundled Obsidian Sync service keeps the container's vault current with every device: edit a note on your phone and it's searchable moments later; an agent writes a note and it shows up in Obsidian.

graph LR
    subgraph container ["One Docker container"]
        Sync["sync service<br/>(remote image)"]
        Vault[("/vault<br/>.md files — source of truth")]
        Index[("search index<br/>keywords + vectors")]
        Server["MCP server"]
        Sync <-->|read/write| Vault
        Vault -->|file watcher| Index
        Server <-->|read/write| Vault
        Server -->|query| Index
    end
    Obsidian["Your Obsidian apps<br/>(phone, laptop)"] <-->|Obsidian Sync| Sync
    Client["Any MCP client<br/>(Claude, Cursor, claude.ai)"] -->|OAuth 2.1 / Bearer| Server

See ARCHITECTURE.md for the full design, auth flow diagrams, and component breakdown.


Keyword search alone fails when your vocabulary doesn't match the vault's — "aspirations" won't find a note about "targets", "coworkers" won't surface your "references" file. In testing against a real vault, 30% of natural-language queries returned zero or tangential results with keywords alone. Hybrid search eliminated those misses in the same test.

Hybrid search fuses the keyword and vector rankings via Reciprocal Rank Fusion, then the reranker refines the fused result:

  • Keywords (FTS5) stay precise on exact terms, jargon, and property values

  • Vectors (sqlite-vec) bridge the vocabulary gap by matching on meaning

  • Reranker (cross-encoder) refines ordering by scoring each query-document pair jointly — rescues intent-heavy queries where keywords and vectors both miss

All models run locally (~45MB total, no external API). Set EMBEDDING_ENABLED=false for keyword-only search, or RERANK_MODE=none to skip reranking for lower latency.

See ARCHITECTURE.md → Hybrid Search for model details, blend weights, and the full pipeline breakdown.


Memory

A memory layer that only grows is only useful if agents can retrieve the right entries without reading everything back every time. Once you have hundreds of dated entries across multiple files — preferences, principles, communication style, ongoing commitments — whole-file reads bury the signal in irrelevant material. The memory system is designed for targeted retrieval.

The layer is a folder of plain Markdown files (default: About Me/) holding dated entries under topic headings — auto-created with starter templates on first run, grown by agents through vault_update_memory. Three properties make it work:

  • Append-only — entries are never overwritten; corrections arrive as new dated entries. The layer becomes a personal knowledge base that captures your current state and the evolution behind it

  • Topic recall — vault_memory_recall retrieves every relevant entry across all memory files at once, matched by keyword and by meaning, oldest first. Ask "what do I think about X?" and get the current take plus the dated history of how it developed — no need to read entire files or guess which file holds what

  • Grows without degrading — capping results (limit) drops the least-relevant entries, never a slice of the timeline. A memory layer with 500 entries serves a targeted query as well as one with 50

Files that describe what's current rather than what has been true (routines, active commitments) can declare entry-policy: living in frontmatter — their expired entries are prunable rather than preserved, keeping the current-state picture accurate.

The whole layer is optional — set MEMORY_ENABLED=false to hide the memory tools and skip the folder auto-creation entirely.

See ARCHITECTURE.md → Memory for the recall pipeline, indexing model, auto-initialization, and opt-out behavior, and templates/memory for the file format, entry-policy convention, and starter templates.


Tasks

Task metadata lives in plain markdown — scattered across files, encoded in emoji signifiers or inline fields, organized under Kanban headings. An agent answering "what's overdue?" would need to parse every file and understand your chosen format; completing a task on a Kanban board means knowing the board's lane structure, the date syntax, and which heading is the done lane.

The task layer handles this so agents don't have to:

  • Find — filter by status, six date fields (due, scheduled, start, created, done, cancelled), priority, folder, or Kanban lane. Each result carries its note path, line number, and nearest heading when the task sits under one (the lane on a Kanban board) — no follow-up reads needed to locate a task

  • Create — add a correctly-formatted task in one call: description, priority, dates, recurrence, "On completion" action, block_id, and checklist sub-items, placed under a heading at its top, bottom, or an exact card slot, or nested under a parent task

  • Update — complete, reprioritize, edit the text, set or clear dates, recurrence, and the "On completion" action, add checklist items, move tasks between headings, and reorder within a lane in a single call

  • Complete — marking a task done auto-detects the done lane and stamps the completion date, honoring the plugin's "Set done date" setting; reversing it removes the date. Completion also runs the Tasks plugin's own behaviors:

    • a recurring task spawns its next occurrence, dates advanced the way the plugin computes them

    • a task set to delete "On completion" disappears from the note

  • Both formats — whichever format you use, Tasks plugin emoji signifiers or Dataview inline fields, the server reads both and writes in the format your Tasks plugin is configured for — read from the plugin's settings when your vault syncs .obsidian/, with emoji signifiers as the default otherwise

See ARCHITECTURE.md → Tasks for the indexing model, date cascade sorting, and Kanban lane detection.


Files

Your notes embed screenshots, reference architecture diagrams, and link out to canvases and data files — but to an agent reading markdown, ![[diagram.png]] is just text. Vault Cortex treats files as part of the vault rather than clutter around it — linked, sized, and readable, each in the form an agent can use:

  • Images — the image itself, not the filename. Screenshots and diagrams are downscaled and recompressed server-side when they exceed what MCP clients accept, so even a phone session can look at a 5MB architecture diagram

  • Canvases — a Canvas board arrives as a readable outline: its groups, each card's content in reading order, and the connections between them. Canvas content is full-text searchable, and file references on the board appear in the link graph — backlinks and outgoing links work just like note-to-note links. The exact JSON source is one flag away when full fidelity matters

  • PDFs — text is extracted with heading hierarchy, code blocks, and hyperlinks preserved; PDF content is full-text searchable alongside your notes. Set raw: true to render pages as images instead, showing layout, diagrams, and tables that text extraction can't preserve — scanned and image-only PDFs work in this mode

  • Text and data files — TXT, SVG, JSON, XML, CSV, YAML, logs, and Bases files return exactly as written; the first 100 KB of content is full-text searchable. Big data files and logs can be read a line range at a time, with each page reporting where you are and how much file remains

  • Browse — list any visible folder's files with per-extension counts and file sizes; files a note links to report their size in the link graph too

Set FILE_TOOLS_ENABLED=false to hide the file tools — useful when your remote vault syncs without attachments.

See ARCHITECTURE.md → Files for the image pipeline and dispatch model.


Tools

Category

Tool

Description

Vault CRUD

vault_read_note

Read a note — full body, properties, outline, or a section

vault_write_note

Create a note (fails if it already exists; set overwrite to replace)

vault_patch_note

Heading-targeted edit (append, prepend, replace with include_children guard, insert)

vault_replace_in_note

Find-and-replace text in a note (first match or replace_all_occurrences)

vault_delete_span

Delete a block of lines by short anchors, no full re-quote

vault_replace_span

Replace a block of lines by short anchors with new content

vault_insert_at_anchor

Insert content before or after a line identified by a short anchor

vault_list_notes

List notes with optional glob/folder filter

vault_delete_note

Delete a note, honoring the vault's trash setting (protected paths enforced)

vault_move_note

Move or rename a note, rewriting links across the vault

Search

vault_search

Hybrid search with tag/folder/property/date filters

vault_search_by_tag

Find notes by tag (exact or prefix match)

vault_search_by_folder

Browse notes in a folder with metadata

vault_recent_notes

Recently modified or created notes

vault_list_tags

All tags with usage counts

Tasks

vault_list_tasks

Vault-wide task index with sub-task depth — Kanban-aware, date/priority/heading filters

vault_create_task

Create a correctly-formatted task — dates, priority, recurrence, on_completion, sub-tasks, block_id

vault_update_task

Edit any task field in one call — completing a recurring task creates its next occurrence

Memory

vault_get_memory

Read structured memory (file, section, or all)

vault_update_memory

Append a dated entry to a memory section

vault_delete_memory

Remove a specific memory entry by date

vault_list_memory_files

Discover memory files, their sections, and each file's entry policy

vault_memory_recall

Entry-granular hybrid recall of a topic across memory files, oldest-first

Properties

vault_list_property_keys

All property keys with sample values

vault_list_property_values

Distinct values for a property key

vault_search_by_property

Find notes by property key-value

vault_update_properties

Add or update properties without touching the body

Links

vault_get_backlinks

Notes linking to a given path

vault_get_outgoing_links

Links from a given note

vault_find_orphans

Notes with no incoming links

Files

vault_read_file

Read a non-markdown file — images delivered as images, canvases as readable outlines

vault_list_files

Browse the vault's non-markdown files with sizes and per-extension counts

Daily Notes

vault_get_daily_note

Today's (or any date's) daily note


Prompts

Tools are model-driven — the assistant calls them. Prompts are workflows you trigger. Each one queries the search index, link graph, and memory layer at invocation time, then assembles the results with guided instructions — so the session starts grounded in your vault's actual state, not assumptions.

Prompt

Arguments

What it does

vault-orientation

—

Surveys vault stats, folder distribution, property adoption rates (flags low adoption), orphans, broken link count, tags, recent notes, and the memory layer — with contextual tool suggestions

memory-review

file?, max_chars?

Structural overview (scope callouts, section entry counts) + dated content as a timeline. Guided reflection: evolution narrative, scope-fit, backfill gaps, and coverage analysis — append-only by default, pruning proposed only for entry-policy: living files. Hidden when MEMORY_ENABLED=false, READONLY_MODE=true, or DISABLED_TOOLS includes vault_update_memory.

daily-review

date?, max_chars?

Reconciles a day — daily note, vault-wide task status (due/overdue, scheduled), modified notes, outgoing links (broken-link detection), and backlinks — surfaces what happened, what's open, and what needs follow-up

Prompts adapt to your configuration (MEMORY_DIR, daily-notes settings) and work for any vault out of the box. Pass max_chars to cap embedded content if your client has payload limits.

Client support: Prompts work in Claude Desktop (Chat and Cowork — via the + menu under your connector), Claude Code (slash commands), and OpenCode. Support in other clients (Cursor, Windsurf) varies — see the MCP clients matrix for the latest.


Properties

Vault Cortex indexes every property in your notes, but five get promoted treatment — dedicated columns for fast filtering, and top-level fields in every search and discovery result:

Property

What you can do

title

Display name in search results; falls back to the filename when missing

tags

Search and filter by tag, including parent-child hierarchies (project matches project/vault-cortex)

type

Filter by note type — meeting, person, session-log, or any value your vault uses

created

Sort by creation date and see when each note was created alongside every search result

related

Filter for notes that cross-reference a specific link — surfaces connections invisible without a graph query

All other properties are still fully queryable — use vault_search with filters.properties for combined text + metadata queries, or vault_search_by_property for metadata-only lookups. vault_list_property_keys and vault_list_property_values discover what properties exist across your vault.

These are conventions, not requirements — Vault Cortex works with any property schema. Promoted properties give you richer filtering and cleaner results out of the box.

Leading callouts get the same treatment. When a note's first body content is an Obsidian callout (> [!type]) — either right after frontmatter or right after the title heading — it's indexed and surfaced alongside every discovery result (on vault_search, ask for it with include_leading_callout). This makes notes self-describing: an agent scanning results can see what each note is for before deciding which to read. The memory templates use > [!info] Scope of this file callouts for this, and any note in your vault can use the same pattern.


Configuration

All settings are environment variables with sensible defaults. Some defaults derive from other settings — the Default column shows each derivation, and a value you set replaces the whole derived default. Remote deployments also forward Obsidian Sync's own settings — DEVICE_NAME, SYNC_MODE, CONFLICT_STRATEGY, SYNC_CONFIGS, SYNC_EXCLUDED_FOLDERS, SYNC_FILE_TYPES — documented in the remote guide's configuration table.

Variable

Required?

Default

Description

MCP_AUTH_TOKEN

Yes

—

Bearer token for authentication (also the JWT signing key)

VAULT_PATH

Local only

—

Host path to your vault (bind mount source; remote uses a named volume). Must not contain *, ?, or [ — rejected at startup.

PUBLIC_URL

Remote only

—

Public URL for OAuth discovery metadata. Filled in automatically on Render and Railway (from RENDER_EXTERNAL_URL or RAILWAY_PUBLIC_DOMAIN) when left unset

OBSIDIAN_AUTH_TOKEN

—

—

Obsidian Sync auth token. Leave empty to sign in through the /setup page after deploy; or the CLI's get-sync-token captures it for you

VAULT_NAME

Remote only

—

Exact name of your Obsidian vault (case-sensitive)

VAULT_PASSWORD

Remote only

—

End-to-end encryption password, if your vault has one. Leave empty otherwise.

STORAGE_ROOT

—

—

One directory for everything that must persist — the vault, the search index, and Obsidian Sync state — for container hosting platforms that allow a single persistent volume (Railway, Render). Mount the volume there and set this to the same path. Must not contain *, ?, or [ — rejected at startup.

EMBEDDING_ENABLED

—

true

Set false to disable the embedding pipeline — skips model download, vector tables, embedding passes, and hybrid search. Search falls back to FTS5 keyword matching.

RERANK_MODE

—

blended

Cross-encoder reranking mode: blended applies position-aware score blending after RRF fusion (~200ms added latency), none skips reranking. Only takes effect when EMBEDDING_ENABLED is true.

MEMORY_ENABLED

—

true

Set false to fully disable the memory layer — hides memory tools, skips bootstrap, omits memory from server metadata. MEMORY_DIR still supplies the defaults for PROTECTED_PATHS and ORPHAN_EXCLUDE_FOLDERS when false.

FILE_TOOLS_ENABLED

—

true

Set false to hide file tools (vault_read_file, vault_list_files) — useful for remote deployments where Obsidian Sync has attachment syncing disabled.

READONLY_MODE

—

false

Set true to hide every tool that changes the vault and skip memory folder auto-creation — connected clients can read and search but never edit.

DISABLED_TOOLS

—

—

Hide individual tools by name, comma-separated (e.g. vault_delete_note,vault_move_note). Names match the Tool column in the tools table. Subtractive only — it cannot re-enable a tool another setting hides. An unknown tool name stops the server at startup, so typos surface immediately.

MEMORY_DIR

—

About Me

Vault folder for structured memory files

PROTECTED_PATHS

—

MEMORY_DIR, daily notes folder

Folders that vault_delete_note and vault_move_note refuse to touch. The default daily notes folder is read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json (default Daily Notes). Overrides the default entirely when set.

ORPHAN_EXCLUDE_FOLDERS

—

daily notes folder, Templates, MEMORY_DIR

Folders excluded from orphan detection. DAILY_NOTES_FOLDER wins; otherwise .obsidian/daily-notes.json is reread per query (fallback Daily Notes). Set a list to replace all defaults, or ORPHAN_EXCLUDE_FOLDERS=, to exclude nothing. An empty value uses the defaults. Root-level daily notes remain eligible. See Daily notes.

DAILY_NOTES_FOLDER

—

from vault config

Sets the folder your daily notes live in. When unset, read from the vault's .obsidian/daily-notes.json, falling back to Daily Notes. See Daily notes.

DAILY_NOTES_FORMAT

—

from vault config

Sets the daily note filename format — same tokens as Obsidian's daily note date format setting. When unset, read from the vault's .obsidian/daily-notes.json, falling back to YYYY-MM-DD. See Daily notes.

TZ

—

UTC

IANA timezone for timestamps and daily note resolution

SERVICE_DOCUMENTATION_URL

—

GitHub repo URL

URL returned in OAuth discovery metadata

LOG_LEVEL

—

info

Logging verbosity: debug, info, warn, error

LOG_DIR

—

/data/logs (remote), $STORAGE_ROOT/data/logs (single-volume), none (local)

Directory for log files that survive container re-creation. The container's own log (what docker logs shows) is always written, but Docker discards it whenever the container is recreated — on image updates or config changes. Date-stamped files under LOG_DIR live on the data volume and survive. none keeps only the container log.

LOG_RETENTION_DAYS

—

90

Days to keep log files before automatic cleanup on startup; only applies when LOG_DIR is a path

WINDOWS_MODE

—

false

On Windows? Set true. Switches the file watcher to polling and note moves to rename-based writes so a vault on a C: drive works through Docker Desktop. Safe to leave on for any Windows setup; unneeded on macOS/Linux/WSL2.

MAX_FILE_BYTES

—

52428800 (50 MiB)

Maximum file size vault_read_file will read (in bytes). Files exceeding this are rejected before reading. Raise for vaults with very large individual files.

MAX_IMAGE_OUTPUT_BYTES

—

49152 (48 KiB)

Byte budget for images delivered by vault_read_file, in binary bytes before base64 encoding. Images exceeding this are downscaled and recompressed to fit. Sized for the tightest mainstream MCP client cap; raise for clients that accept larger responses.

MAX_PDF_RENDER_PAGES

—

5

Maximum PDF pages to render as images when raw: true is set on vault_read_file. The per-page byte budget is MAX_IMAGE_OUTPUT_BYTES divided evenly across the rendered pages — fewer pages means higher quality each.

TRASH_RETENTION_DAYS

Local only

30

Days a note deleted under Obsidian's default "Move to system trash" setting stays in .trash/ before the server cleans it up. Set none to keep those notes forever. Only notes the server itself moved there are cleaned up. With Obsidian Sync, deletes are permanent on the server and recoverable from Sync's version history.

TRUST_PROXY_HOPS

—

0

Number of trusted reverse-proxy hops used to derive the client IP from X-Forwarded-For (OAuth rate limiting, request logs). Set 1 when exactly one proxy you control sits in front of the server (Caddy, nginx, Cloudflare Tunnel, API Gateway). With 0, injected forwarding headers are ignored.

TRUST_FORWARDED_HOPS

—

0

How many trailing for= entries in the RFC 7239 Forwarded header belong to proxies you control. 0 ignores the header; 1 when the proxy in front writes it (e.g. AWS API Gateway); 2 when a CDN fronts that proxy and is the only way to reach it.

See templates/memory/ for memory file examples and the dated-entry design philosophy.

Daily notes

vault_get_daily_note and the daily-review prompt find your daily notes using the folder and filename date format configured in Obsidian, read from your vault's .obsidian/daily-notes.json:

  • Local mode reads the file straight from your bind-mounted vault — nothing to set up.

  • Remote mode receives it through Obsidian Sync's vault configuration syncing. The server pulls it by default (the SYNC_CONFIGS setting in .env), but you'll likely need to enable the push side: Obsidian Settings → Sync → Vault configuration sync, per device. Details: the remote guide's Daily notes section.

When the file isn't available — or if you use the Periodic Notes plugin, whose settings it doesn't reflect — set the values yourself:

  • DAILY_NOTES_FOLDER — any vault-relative path: Journal, Planner/Daily

  • DAILY_NOTES_FORMAT — same tokens as Obsidian's date format setting: YYYY-MM-DD-dddd, YYYY/MM/DD, MMM D, YYYY, …

You can set one or both — a set value always wins over the config file. Without either source, the server falls back to Daily Notes and YYYY-MM-DD.

  • Changes in Obsidian apply on the next call when .obsidian/daily-notes.json is available in the server's vault. Apply environment changes with the CLI's restart command, recreate the Compose container, or redeploy on your hosting platform.

  • An empty Obsidian folder setting uses the server's Daily Notes fallback. Daily notes stored at the vault root remain eligible for orphan results; the server never excludes the whole vault automatically.

Note: A few date format tokens are unsupported — ordinals (Do, Mo, DDDo, wo), dd (2-letter weekday), d (weekday number), e, k/kk, w (week number), Q (quarter), Z/ZZ (UTC offset), and the localized formats (L–LLLL, LT, LTS). The server can't reproduce the filenames Obsidian creates with these tokens, so it could never find the notes. If your format uses any of them, vault_get_daily_note returns a clear error — change the format in Obsidian or set DAILY_NOTES_FORMAT to a supported alternative.


Data Integrity

Vault Cortex writes to personal notes — the file safety layer is built to prevent corruption, not just errors.

  • Atomic writes — every file write stages to a temp file, then renames. Readers never see a partial or 0-byte note. Exclusive creates use link() (POSIX no-clobber) to close the TOCTOU window on note moves.

  • Per-file mutex — concurrent MCP tool calls serialize or fail-fast per file. Moves lock the source, destination, and every backlink source as one unit.

  • Path traversal blocked — resolveSafePath() resolves then prefix-checks every path. Protected-path deletion is refused after normalization. Memory file names reject separators at the boundary.

  • Hidden paths are off-limits — files and folders starting with a dot (.obsidian/, .trash/) never appear in listings or search, and any tool call that targets one directly is rejected, matching Obsidian. Plugin configs and their API keys stay out of reach.

  • Deletes honor Obsidian's trash setting — with "Deleted files" at Obsidian's default "Move to system trash" or at "Move to Obsidian trash", a deleted note moves to .trash/ inside the vault instead of being removed (a container has no system trash; .trash/ is Obsidian's own fallback for that). "Permanently delete" removes the note for good.

  • Obsidian Sync deployments delete permanently — the delete syncs to every device, and recovery is Sync's version history rather than a trash folder.

  • Bounded trash with a retention sweep — notes the server moves to .trash/ under the system-default setting are cleaned up after TRASH_RETENTION_DAYS (default 30 days; none keeps them forever). The sweep removes only files it recorded — notes Obsidian itself trashed, and "Move to Obsidian trash" deletes, are never touched.

  • Injection prevention — search queries are parameterized and FTS5-sanitized; prompt content is wrapped in XML data markers with closing-tag escaping to prevent tag-breakout injection.

  • Container hardening — non-root user, PID 1 init, no package managers in the runtime image, digest-pinned base, graceful shutdown.

  • Read-only mode — READONLY_MODE=true hides every tool that edits the vault, so a connected client can read and search but never change a note.

See ARCHITECTURE.md → Data Integrity for mechanism details and SECURITY.md → Runtime Hardening for how each part of the server is hardened.


Authentication

For a server with read/write access to personal notes, authentication is not optional. Vault Cortex implements the full OAuth 2.1 specification, including PKCE and refresh-token rotation. The AWS (SST) deployment adds defense-in-depth: requests are validated at two independent layers (API Gateway Lambda authorizer + Express middleware). Per BlueRock's 2026 MCP security analysis, only 8.5% of MCP servers implement OAuth; 41% have no authentication at all.

Two methods:

Method

Used by

Token format

OAuth 2.1

Claude Desktop, Claude Code, claude.ai, any OAuth client

JWT (HS256, 6h)

Static bearer

Claude Code, MCP Inspector, curl

Raw MCP_AUTH_TOKEN

The method follows from your client — OAuth when it supports it, the raw token in a header otherwise (Connect your MCP client shows both).

OAuth uses dynamic client registration — no manual Client ID or Secret needed:

  1. Your client registers automatically and receives a client ID and secret.

  2. Enter your MCP_AUTH_TOKEN on the browser consent page to approve access.

  3. Your client includes the issued secret in subsequent token requests automatically.

Refresh tokens have a 60-day sliding expiry. Access tokens are bound to your server's URL, so a token minted for one deployment is never accepted by another. Rotating MCP_AUTH_TOKEN ends every session — each client re-authorizes through the consent page.

See ARCHITECTURE.md → Auth for the full flow diagram.


Deployment Options

Local runs on your machine. Remote deployments run on a VPS or a hosted container platform — your vault is accessible even when your laptop is closed.

Whichever path you pick, the server is replaceable and your vault isn't. Your notes are plain Markdown files, synced by Obsidian to every device you own; the container holds a copy and an index it can rebuild from scratch. Shut down the VPS, delete the Render or Railway service, switch hosts — the same files are still on your machine and in Obsidian Sync, readable by anything. That's the difference from an AI notebook whose real home is the vendor's database: here the host is a convenience, not a custodian.

Path

What

Guide

Local

Your vault on your machine — free, no cloud

deploy/local/

Remote · one-click

Render or Railway — one persistent volume, no server to manage

deploy/render/ · deploy/railway/

Remote · self-hosted

VPS + Obsidian Sync — access from any device

deploy/remote/

Remote · AWS (SST)

IaC reference deployment — automated infra, defense-in-depth auth

DEPLOY.md

The AWS path includes CI/CD workflows built for this repo — forkers need to configure their own credentials and stage before deploying.

Every path runs the same image, ghcr.io/aliasunder/vault-cortex — :latest is the MCP server alone (local), :remote bundles Obsidian Sync in the same container under s6-overlay supervision (one-click, self-hosted, and AWS). One container means any OCI runtime works: docker run, Podman, nerdctl — Docker Compose is optional.

Also on Docker Hub: the same images are mirrored to aliasunder/vault-cortex. GHCR is the primary source; Hub tags are identical.

Cost: A remote setup needs a VPS or a hosted platform plan, plus $4 USD/mo for Obsidian Sync. A 2 GiB instance handles semantic search fine for a typical vault; 4 GiB adds headroom for concurrent search and larger vaults. Skip semantic search entirely to go smaller still. Local-only is free. The reference AWS deployment runs ~$17–29 USD/mo all-in.

One-click deploy

Buttons and prerequisites are in Quick Start → Remote. Each guide walks through the deploy, where to find your URL and token, how to update, and how to delete: deploy/render/ (from the render.yaml Blueprint at the repo root) · deploy/railway/ (from a published template).

Community deployments

Deployment templates built and maintained by the community — not tested here, and they may lag behind releases.

  • vault-cortex-aca — Bicep template for Azure Container Apps by @flytzen. Runs the :remote image behind Container Apps ingress with free managed HTTPS; storage is deliberately ephemeral, with Obsidian Sync as the source of truth.

Built a deployment for another platform? Open a PR to add it here.


Development

# Run locally with hot reload
PUBLIC_URL=http://localhost:8000 MCP_AUTH_TOKEN=local-dev-token VAULT_PATH=~/Vault npm run dev:mcp

# Tests
npm test

# Full check suite
npm run prettier:check && npm run lint && npm run markdownlint && npm run knip && npm test && npm run build

npm test includes integration tests that boot a real server and call every tool and prompt over HTTP — verifying auth enforcement, config-gated tool surfaces, write mutation integrity (each write is read back), and boot rejection on misconfiguration. See SECURITY.md for the security-relevant coverage.

MCP Inspector — interactive browser UI for testing tools:

# Start server (terminal 1), then:
npx @modelcontextprotocol/inspector
# Enter http://localhost:8000/mcp as URL, local-dev-token as Bearer token

See CONTRIBUTING.md for the full development setup.


Companion: obsidian-vault skill

The MCP server works on its own with any client. For agents that support skills (Claude Code, Cursor, Windsurf, Cline, and 70+ others), the obsidian-vault skill adds deeper knowledge of Obsidian-flavored markdown — frontmatter conventions, callout syntax, and plugin-specific formats like Dataview, Tasks, and Kanban.

npx skills add aliasunder/agent-skills --skill obsidian-vault

Skill source →


Roadmap

Planned work, what's being explored, and explicit non-goals live in ROADMAP.md.


Acknowledgments

Obsidian sync is powered by obsidian-headless — containerization approach inspired by @Belphemur's obsidian-headless-sync-docker. The :remote image's s6-overlay supervision scaffolding was absorbed from that project's maintained fork and now lives in this repo.

The hybrid search pipeline draws on patterns from @tobi's qmd — RRF fusion with rank bonuses, position-aware score blending for cross-encoder reranking, content-hash gating, and heading-aware chunking.

Contributing

See CONTRIBUTING.md for development setup, code conventions, and PR guidelines.

License

MIT

The :remote image bundles obsidian-headless (the ob CLI), which is proprietary — its package.json declares "license": "UNLICENSED" (© Dynalist Inc. / Obsidian). It is installed from public npm at build time; the MIT license here does not cover it, and using it requires an active Obsidian Sync subscription. The :latest (local) image contains no proprietary components.

Security

Report vulnerabilities privately — see SECURITY.md.

Available Tools

33 tools
vault_create_taskCreate TaskA

Create a correctly-formatted task in one call — description, target heading, dates, priority, block_id, and optional checklist sub-items. The task is created as todo (using the status registry's todo symbol, [ ] by default) with ➕ today auto-stamped — starting work is vault_update_task's job. Metadata is written in the format the vault's Tasks plugin is configured for (emoji unless the plugin config says Dataview).

Example: vault_create_task({ path: "TASKS.md", description: "Fix login bug", block_id: "fix-login", heading: "Active", priority: "high", due: "2026-09-15" }) Example: vault_create_task({ path: "TASKS.md", description: "Sub-bug", block_id: "sub-bug", parent_block_id: "fix-login", due: "2026-09-01" }) — full sub-task under a parent identified by block_id Example: vault_create_task({ path: "TASKS.md", description: "Quick fix", block_id: "quick-fix", parent_line: 42 }) — sub-task under a parent identified by line number Example: vault_create_task({ path: "TASKS.md", description: "Mid-priority", block_id: "mid-priority", heading: "Active", position: 3 }) — insert as the 3rd card in the lane

When to use: Creating a new task card on a board or in a note. Guarantees correct field ordering (description → priority → 🔁 recurrence → 🏁 onCompletion → ➕ created → 🛫 start → ⏳ scheduled → 📅 due → 🆔 task_id → ⛔ depends_on → ^block_id) so the card round-trips through vault_list_tasks with all fields intact. For lightweight checklist items under an existing card (no metadata), use vault_update_task's add_subtasks param instead.

Parameters:

  • heading is required on Kanban boards (notes with kanban-plugin frontmatter).

  • parent_block_id / parent_line: the same pair vault_update_task uses (block_id / line). Pass at most one. Either is mutually exclusive with heading — a sub-task lives wherever its parent lives.

  • position: Kanban boards with new-card-insertion-method set to "prepend" default to "top" instead of "bottom". Ignored when no heading or when placing under a parent.

  • priority: the plugin ranks "no signifier" (normal priority) between medium and low.

  • recurrence: a rule ending "when done" bases the next occurrence on the completion day.

  • due / scheduled / start: omit a date rather than guessing — an absent 📅 means "no deadline".

Errors:

  • "note not found" — path does not exist

  • "path must end in …" — add the .md extension

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "heading required for Kanban boards" — kanban-plugin note without heading

  • "heading "X" not found; available: ..." — no heading matches; the error lists the note's headings

  • "cannot place at position N under "X" — the heading appears N times" — integer position on a note with duplicate heading names; rename one section to make it unique

  • "parent task not found" — parent_block_id or parent_line doesn't resolve to a task (message names the blockId or line tried), or the line is inside a fenced code block or %% %% comment

  • "checkbox "[c]" is a NON_TASK status" — the parent task's checkbox char is typed NON_TASK in the Tasks plugin's status registry, so it is not a task; to change that, retype it there and restart the server

  • "no checkbox symbol for status ..." — the status registry has no symbol for the todo status and the built-in default is retyped; update the plugin's status registry to include a todo symbol, then restart the server

  • "parentBlockId and parentLine are mutually exclusive" — both parent_block_id and parent_line were passed; drop one

  • "parent and heading are mutually exclusive" — a parent (parent_block_id or parent_line) and heading were both passed; drop one

  • "blockId ... already exists in this note" — pick a block_id not yet used in the note

  • "blockId ... contains invalid characters" — block_id must match [a-zA-Z0-9-]+

  • "description is empty" / "subtasks cannot contain an empty item" — whitespace-only description or checklist item

  • "description must be a single line" / "subtasks items must be a single line" — a task is one file line; a line break in the text would split its metadata onto a line the parser never reads

  • "taskId ... contains invalid characters" / "dependsOn entry ... contains invalid characters" — task_id and every depends_on entry must match [a-zA-Z0-9_-]+ (the Tasks plugin's id grammar)

  • "unrecognized recurrence rule ..." — the rule text is not Tasks-plugin natural language; written as-is it would silently never recur

  • "invalid date" — a date param fails calendar validation

  • "concurrent write in progress" — another write to this note is in flight; retry

Obsidian syntax: The Tasks plugin reads metadata off the END of a task line. A trailing signifier in description or subtasks text (an emoji field like "🔁 every week", or a Dataview [key:: value] field) that the plugin's parser recognizes as a field — followed only by other recognized fields — is read back as metadata, not text. Whether it is captured depends on the field's value grammar: 🔁 reads any trailing words as its recurrence rule, while 📅 followed by non-date words stays description text. The same interference can change the value an adjacent field reads back with, or make a field appear that was never set. The write still succeeds either way; when the stored line would read back differently than submitted, the result carries an advisories array naming each divergence.

Returns: JSON { path, line, description, block_id, heading, subtasks, changes, advisories } — line is the new card's 1-based position; heading is the nearest heading above the new task (omitted when the note has none); subtasks lists each checklist item written as { line, description } (omitted when none) — checklist items carry no block_id, so line is the handle for a follow-up update; changes lists every field written as "field: before → after", with "(none)" for an absent value; advisories (omitted when the line round-trips clean) lists one sentence per place the stored line parses back differently than submitted — see Obsidian syntax above.

ParametersJSON Schema
NameRequiredDescriptionDefault
dueNoDeadline (📅), YYYY-MM-DD, calendar-validated. Omit when there is no deadline.
pathYesVault-relative path to the note (must end in ".md"). The note must already exist. Use the exact letter case.
startNoEarliest day work can begin (🛫), YYYY-MM-DD, calendar-validated.
formatNoField format. Default: auto-detected from .obsidian/ config, falling back to emoji.
headingNoTarget heading. On a regular note, omit to append at end of body.
task_idNoTasks plugin 🆔 identifier other tasks can name in depends_on.
block_idYesThe ^block-id for stable identification — letters, digits, and hyphens only ([a-zA-Z0-9-]+). Must be unique within the note.
positionNoWhere within the heading section the task is placed. "top" or "bottom" for the extremes; an integer (1-based) for an exact position among the lane's top-level cards (sub-tasks move with their parent and are not counted). Position 1 is the first card. A position past the card count lands directly below the last card (unlike "bottom", which appends after any non-task text at the end of the section). Defaults to bottom.
priorityNoPriority signifier (🔺⏫🔼🔽⏬). Omit for normal priority — no signifier is written.
subtasksNoChecklist item descriptions — created as indented todo lines under the card (no metadata). For full sub-tasks with dates, priority, and block_id, make a separate call with parent_block_id.
scheduledNoDay the work is planned for (⏳), YYYY-MM-DD, calendar-validated.
depends_onNoTasks plugin ⛔ dependency IDs (🆔 values of other tasks). Non-empty; omit when there are no dependencies.
recurrenceNoTasks plugin 🔁 rule in natural language (e.g. "every week", "every month on the 15th", "every 2 weeks when done"). Completing the task spawns its next occurrence.
descriptionYesThe task text (before metadata fields).
parent_lineNo1-based line number of an existing task to nest under as a sub-task. Fragile if the file changed since the line was read.
on_completionNoTasks plugin 🏁 onCompletion action. "delete" removes the task line on completion; "keep" leaves it in place.
parent_block_idNo^block-id (without the ^) of an existing task to nest under as a sub-task.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (readOnly=false, idempotent=false, destructive=false), it discloses that the task is created in todo status with a symbol pulled from the status registry, that ➕ today is auto-stamped, that metadata is written in the plugin-configured emoji/Dataview format, and that writes can fail with 'concurrent write in progress'. It also explains the advisory mechanism when a stored line parses back differently — behavior an agent could not infer from annotations alone.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded correctly: purpose, examples, when-to-use, then parameters, errors, syntax caveats, returns. Every section is scannable, but the error catalog and the Obsidian-syntax paragraph make the text very long relative to the core instruction, and some error strings duplicate constraints already implied by the schema (block_id charset, single-line description).

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, yet the description fully documents the return object (path, line, description, block_id, heading, subtasks, changes, advisories) and explains when fields are omitted. For a 17-parameter mutation tool with no output schema, the description supplies everything needed to call it and interpret the response.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds cross-parameter and vault-specific semantics the schema lacks: heading is required on kanban-plugin notes, parent_block_id/parent_line are mutually exclusive with each other and with heading, priority's 'no signifier' ranks between medium and low, and 'when done' recurrence bases the next occurrence on the completion day. These are genuine additions, though several details (position behavior, date omission) largely restate the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with a specific verb+resource ('Create a correctly-formatted task in one call') and enumerates the fields written. It explicitly distinguishes itself from siblings: new tasks are its job, while 'starting work is vault_update_task's job' and lightweight checklist items belong to vault_update_task's add_subtasks. No schema-opening is required to route between the two tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Has a dedicated 'When to use' line plus four concrete call examples, and names the alternative use-path for lightweight checklist items. It also states preconditions and exclusions: heading required on Kanban boards, parent_block_id/parent_line mutually exclusive with heading, 'omit a date rather than guessing'. This is explicit when/when-not/alternative guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_delete_memoryDelete Memory EntryA
Destructive

Delete a single dated entry from a memory file in About Me/. Both date and entry text are required for exact matching — ensures only the intended entry is removed.

Example: vault_delete_memory({ file: "Opinions", section: "AI tooling & memory (newest first)", date: "2026-05-01", entry: "Prefer X over Y" })

When to use: Removing an entry that was wrong when it was written — a mistake, a misattribution, or something never true. Memory files are append-only by default, so do NOT delete to reflect a change: append the new state via vault_update_memory instead (newest-first naturally supersedes). The exception is a file whose frontmatter declares entry-policy: living (check via vault_list_memory_files) — a current-state file where deleting an expired entry is the intended maintenance. Call vault_get_memory(file, section) first to see exact entry text for matching. Prefer vault_delete_note for deleting entire non-protected notes.

Parameters:

  • date + entry together uniquely identify the bullet line within the given section. If multiple entries share the same date and text, deletion fails as ambiguous.

  • section scopes the match — an identical entry under a different heading is not found. Section matching is case-insensitive, with or without the "(newest first)" suffix.

Errors:

  • "memory file not found" — file does not exist in About Me/; call vault_list_memory_files to discover valid names.

  • "memory file must not start with a dot" / "memory file must be a bare name without path separators" — pass the file's bare name: no folder or slash, and no leading dot (that would target a hidden file; memory files are always visible notes).

  • "date must be a real ISO calendar date" — date only accepts an existing calendar date in bare YYYY-MM-DD form. A hand-edited bullet carrying an impossible date cannot be targeted by this tool — remove it with vault_delete_span or a manual edit.

  • "section not found: …" — no H2 heading matches; the error lists the file's available sections

  • "no entry matching …" — no bullet matched the given date and entry text; verify exact text via vault_get_memory(file, section).

  • "ambiguous: N entries match …" — more than one identical bullet exists in the section (e.g. from hand edits, sync conflicts, or entries predating duplicate protection; vault_update_memory refuses to write exact duplicates). Remove the extra copy with vault_delete_span (pass first_match: true — identical lines make every anchor ambiguous) or a manual edit, then retry.

  • "refusing memory write: … would shrink content" — safety guard blocked a write that would remove more than half the file. Re-read with vault_get_memory to confirm current content; an entry that really is that large needs vault_delete_span or a manual edit.

Returns: Confirmation message.

ParametersJSON Schema
NameRequiredDescriptionDefault
dateYesISO YYYY-MM-DD date of the entry (e.g. "2026-05-01"). Must match the date shown by vault_get_memory.
fileYesMemory file name without .md (e.g. "Principles"). Use the exact letter case.
entryYesExact entry text as shown by vault_get_memory — without the "- **YYYY-MM-DD**: " prefix or bullet.
sectionYesH2 section heading containing the entry. Matched case-insensitively, with or without the "(newest first)" suffix.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare destructiveHint=true and readOnlyHint=false, and the description is consistent with that while adding far more: the append-only default policy, the `entry-policy: living` exception, the ambiguity failure mode, and the 'refusing memory write: would shrink content' safety guard. This is unusually rich disclosure of destructive-operation semantics.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Purpose, example, when-to-use, parameters, and errors are cleanly headed and front-loaded, and the length is justified by a genuinely complex matching/error surface. The error list is exhaustive to the point of mild verbosity, but each entry maps to a distinct actionable recovery path.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive, non-idempotent tool with four required parameters and no output schema, the definition covers prerequisites, matching semantics, all failure modes with recovery steps, and the return value. Nothing needed to invoke it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds real meaning beyond it: date+entry together uniquely identify a bullet line, duplicate date+text pairs fail as ambiguous, and section scoping means an identical entry under a different heading will not match. Case-insensitive section matching is already covered by the schema, so it is not fully additive.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource ('Delete a single dated entry from a memory file in About Me/') and immediately scopes it against siblings by clarifying it removes one entry, not a note. The example makes the granularity concrete, so an agent can distinguish this from vault_delete_note without reading either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives explicit when-to-use ('removing an entry that was wrong when it was written'), explicit when-NOT-to-use ('do NOT delete to reflect a change: append via vault_update_memory instead'), and a named exception (files with `entry-policy: living`). It also routes to alternatives for adjacent cases (vault_delete_note for whole notes, vault_delete_span for duplicate/impossible-date lines).

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_delete_noteDelete NoteA
Destructive

Delete a markdown note, moving it to the vault's .trash/ folder or removing it for good as the vault's Obsidian "Deleted files" setting directs.

Example: vault_delete_note({ path: "Scratch/temp.md" }) Example: vault_delete_note({ path: "Archive/2024/old.md", prune_empty_folders: true }) — also remove "Archive/2024" (and "Archive") if deleting the note empties them.

When to use: Removing a note you no longer need. Prefer vault_delete_memory for removing individual dated entries from About Me/ memory files. To relocate a note, use vault_move_note instead. To replace a note's content, use vault_write_note with overwrite: true instead.

Behavior:

  • Unless the server syncs through Obsidian Sync, the "Deleted files" setting (trashOption in .obsidian/app.json) decides the outcome:

    • "Move to system trash" (system, also what an absent setting means) moves the note to .trash/, since the server has no system trash. The server deletes its own copies there after its TRASH_RETENTION_DAYS setting (default 30 days, or never when set to none), never touching notes Obsidian trashed.

    • "Move to Obsidian trash" (local) moves the note to .trash/ and keeps it forever.

    • "Permanently delete" (none) removes the note for good.

  • When the server syncs through Obsidian Sync, the setting is bypassed and the note is always deleted for good; recover it from Sync's version history (1 month on Standard, 12 months on Plus).

  • The caller can't choose or see the outcome in advance; the returned message says which happened.

  • Links to the note from other notes become broken (detectable via vault_get_backlinks). Protected paths (About Me/ and the daily notes folder (read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json, defaulting to Daily Notes/)) are refused.

Parameters:

  • prune_empty_folders removes each parent folder the delete leaves with zero entries, up to but never including the vault root; a folder holding any file, even a hidden .DS_Store, is kept. Pruning runs after the delete or trash move and is best-effort: a folder that can't be removed never fails the call. Without it, empty folders stay, matching Obsidian.

Errors:

  • "cannot delete protected path" — the path sits under a protected folder; use vault_delete_memory for memory entries

  • "path must end in …" — add the .md extension

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "concurrent write in progress" — another write to this note is in flight; retry

  • "note not found: …" — the note does not exist; verify the path with vault_list_notes before deleting

  • "cannot move to trash … — 100 collisions in .trash/" — .trash/ already holds this name and its numbered copies ("Plan 1.md" … "Plan 100.md"); clear old trash copies, then retry

  • any other "cannot move to trash …" — the .trash/ move failed (e.g. a plain file blocks a needed folder); the note stays put; fix .trash/, then retry

  • any other "cannot delete …" — the permanent delete failed (e.g. permissions); the note stays put; fix the cause, then retry

  • "cannot read trash config from .obsidian/app.json" — the file exists but is unreadable; the delete is blocked because a guessed setting could let the retention sweep remove a note set to be kept forever; repair the file, then retry

  • "cannot read daily notes config from .obsidian/daily-notes.json" — the file exists but is unreadable, so the daily notes folder to protect is unknown; repair it, or set DAILY_NOTES_FOLDER or PROTECTED_PATHS, then retry

Returns: Confirmation message naming the outcome — "Deleted " for permanent removal, "Moved to trash ()" when the note landed in .trash/. Notes how many empty folders were pruned when any were.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesVault-relative path of the note to delete, including the ".md" extension. Use the exact letter case.
prune_empty_foldersNoWhen true, also remove parent folders the delete leaves empty. Default false.

TDQS

A4.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the destructiveHint annotation: it discloses that the outcome depends on the vault's trashOption setting, how Obsidian Sync bypasses that setting (with recovery windows), that the caller cannot pre-select or see the outcome, that backlinks break, and that protected paths are refused. This is unusually rich behavioral disclosure for a mutation tool. Minor deduction only because the very long error catalog is more error-reference than behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads purpose, then usage, behavior, parameters, errors, returns — a sensible order. It is long, but most of the length is non-redundant behavioral/error detail. The error catalog is the one section that could be trimmed, keeping it just short of a 5.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given a two-parameter destructive tool with no output schema, the description covers outcome variability, protected paths, retention, failure modes, and the returned confirmation strings. Nothing an agent needs to call this correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3. The description nonetheless adds real meaning for prune_empty_folders: it prunes each emptied parent up to but not including the vault root, is best-effort and never fails the call, and keeps folders containing even hidden files like .DS_Store.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Delete a markdown note') with the scope of what happens to the file (trash vs permanent). It names the sibling operations it is not (vault_delete_memory, vault_move_note, vault_write_note), so an agent can route correctly without opening sibling schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Has an explicit 'When to use' line plus three named alternatives with the exact condition that selects each (use vault_delete_memory for dated memory entries, vault_move_note to relocate, vault_write_note overwrite to replace). Nothing is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_delete_spanDelete SpanA
Destructive

Delete a contiguous block of whole lines from a note's body by referencing short anchor substrings instead of reproducing the full block text. Each anchor locates a full line — the entire line is selected, not just the matching substring. Case-sensitive matching. Properties are preserved; YAML formatting may be normalized to block style on first edit. Operates on the body only.

Example: vault_delete_span({ path: "Tracker.md", start_anchor: "| 2024-03-02 | Acme" }) — deletes the one table row whose line contains that fragment. Example: vault_delete_span({ path: "Notes/Plan.md", start_anchor: "> [!warning] Stale", end_anchor: "remove after launch" }) — deletes from the start anchor line through the end anchor line.

When to use: Removing a block you have already read — a table row, callout, or run of list items — where reproducing it exactly as old_text would be error-prone. Pick a short, unique fragment of the first line for start_anchor and, for a multi-line block, the last line for end_anchor. Prefer vault_replace_in_note for small in-place edits (this tool only deletes). To replace a block, use vault_replace_span (one atomic step).

Parameters:

  • start_anchor + end_anchor define a line range, not a text range (never cuts mid-line). Omit end_anchor for a single-line delete. The empty lines above and below the removed lines join into one gap that keeps the larger of the two counts (only at the end of the note, the count above drops by one); no other empty line in the note changes. A line holding only spaces or tabs counts as text, not as an empty line.

  • end_anchor is searched at or after the start line, so the span can never run backward; it must be unique among those lines. If both match the same line, only that one line is deleted.

  • first_match applies to both anchors independently — when an anchor matches multiple lines, takes the first instead of erroring.

Errors:

  • "note not found" — verify path with vault_list_notes

  • "path must end in …" — add the .md extension

  • "start anchor not found" / "end anchor not found" — no line contains the fragment (for end_anchor, none at or after the start line); verify with vault_read_note

  • "ambiguous start anchor …" / "ambiguous end anchor …" — the anchor matches multiple lines; use a longer fragment or set first_match: true

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "concurrent write in progress" — another write to this note is in flight; re-read the note and retry

Returns: Confirmation with the number of lines the span covered and a preview of them, cut at 80 characters.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesVault-relative path to the note, including the ".md" extension (e.g. "Tracker.md", "Notes/Plan.md"). Use the exact letter case.
end_anchorNoShort substring that identifies the LAST line of the block. The entire line is selected. Omit to delete just the single line containing start_anchor.
first_matchNoIf an anchor matches more than one line, delete using the first match instead of erroring (default: false — ambiguity is an error).
start_anchorYesShort, unique substring that identifies the first line of the block (case-sensitive). The entire line is selected, not just the substring. Pick a brief fragment — do not paste the whole block.

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare destructiveHint=true and idempotentHint=false, but the description goes well past them: case-sensitive matching, properties preserved with YAML normalized to block style, body-only scope, the empty-line merge rule, forward-only end_anchor search, first_match semantics, and a full error catalogue including 'concurrent write in progress' and path-safety blocks. That is unusually rich disclosure for a destructive operation.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core mechanism, then examples, then routing guidance, then parameter and error detail — a logical order. It is long, and the parenthetical about empty-line counts at the end of the note is arguably over-specified for a description, but almost every sentence carries actionable information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, and the description compensates by stating the return value (line count plus an 80-character preview) and enumerating the failure modes with a remediation for each. For a destructive, 4-parameter tool, an agent has everything needed to call it correctly and recover from errors.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is already 100%, yet the description adds semantics the schema does not: anchors define a line range rather than a text range and never cut mid-line, end_anchor is searched at or after the start line so the span cannot run backward, and first_match applies to each anchor independently. It also clarifies that a whitespace-only line counts as text, not as empty.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('delete a contiguous block of whole lines from a note's body') and immediately distinguishes its mechanism (anchor substrings instead of full block text) from the siblings that do similar work. An agent can tell it apart from vault_replace_in_note and vault_replace_span without opening a schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

An explicit 'When to use' section names the scenario (a block already read, where reproducing old_text is error-prone) and names the alternatives: vault_replace_in_note for small in-place edits, vault_replace_span for block replacement. Both the positive case and the boundary are stated.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_find_orphansFind OrphansA
Read-onlyIdempotent

Find notes with no incoming links from other notes or canvases — orphans are disconnected from the knowledge graph and may be forgotten or need linking. A note that only links to itself still counts as an orphan (self-links are ignored).

Example: vault_find_orphans({}) Example: vault_find_orphans({ exclude_folders: ["Archive"], limit: 10 })

When to use: Vault maintenance — surfacing notes to integrate into the graph. Link an orphan by mentioning it from a relevant note with vault_patch_note. Prefer vault_get_backlinks to check the connectivity of one specific note rather than scanning the whole vault.

Parameters:

  • The daily notes folder is resolved on each call (DAILY_NOTES_FOLDER → .obsidian/daily-notes.json → "Daily Notes"). ORPHAN_EXCLUDE_FOLDERS replaces the defaults. For unreadable daily settings, the server logs a warning and uses "Daily Notes".

  • exclude_folders replaces the defaults (including an environment override), it does not add to them — include the defaults yourself to keep them. Pass [] for no exclusions. Each entry names a whole folder, subfolders included ("Projects" also excludes "Projects/Archive" but not "ProjectsOld/"), ignoring ASCII letter case.

  • limit applies after exclusions and sorting by most recently modified. Nothing in the response signals truncation: exactly limit results may mean more exist, so raise limit to check.

Errors:

  • An empty array means no orphans were found (after exclusions), not an error.

  • "too many excluded folders" — pass a shorter exclude_folders list, then retry.

Returns: JSON array of note metadata (path, title, tags, related, folder, type, created, modified, bytes, leading_callout?, additional_properties?), sorted by most recently modified. bytes is the on-disk file size.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMax results (default 50)
exclude_foldersNoFolder paths to exclude (e.g. Projects; default: daily notes folder, Templates, "About Me")

TDQS

A4.5/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, destructiveHint=false and openWorldHint=false, so the safety profile is fully covered. The description adds genuinely useful behavior beyond that: the daily-notes folder resolution order, that ORPHAN_EXCLUDE_FOLDERS replaces defaults, and — most importantly — that truncation is invisible because exactly 'limit' results may mean more exist.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the definition and edge case, then cleanly sectioned into When to use / Parameters / Errors / Returns. Nearly every sentence earns its place, though the two inline Example calls are somewhat redundant given the parameter bullets, and the daily-notes resolution detail is dense for a two-parameter tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, and the description compensates fully with a Returns section enumerating the metadata fields (path, title, tags, folder, type, created, modified, bytes, etc.) and the sort order. It also documents the empty-array and 'too many excluded folders' cases, so nothing needed to call or interpret it is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description goes well past the schema: exclude_folders replaces rather than augments defaults (include defaults yourself, pass [] for none), each entry covers subfolders, matching ignores ASCII case, and limit applies after exclusions and most-recently-modified sorting. This is meaning the schema does not carry.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description gives a specific verb and resource ('Find notes with no incoming links') and immediately defines the term 'orphans' as notes disconnected from the knowledge graph. It even resolves the edge case of self-links, so an agent knows exactly what this tool returns and how it differs from link-listing siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It states the use case ('Vault maintenance — surfacing notes to integrate into the graph'), names the follow-up action (link via vault_patch_note), and explicitly routes the agent elsewhere for the adjacent task ('Prefer vault_get_backlinks to check the connectivity of one specific note'). Both when-to-use and the alternative are given.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_get_daily_noteGet Daily NoteA
Read-onlyIdempotent

Read a daily note by date, using the vault's configured Daily Notes folder and filename date format. Each setting comes from the DAILY_NOTES_FOLDER / DAILY_NOTES_FORMAT env vars, falling back to the vault's .obsidian/daily-notes.json, then to "Daily Notes" and YYYY-MM-DD.

Example: vault_get_daily_note({ date: "2026-05-13" }) Example: vault_get_daily_note({}) — returns today's daily note

When to use: When you need today's or a specific date's daily note. Handles path resolution automatically using the vault's Obsidian config — you don't need to know the folder name or filename format. To append content to a daily note section, use the returned path with vault_patch_note. Use vault_recent_notes to review recent vault activity around a date (not date-filtered — returns globally recent notes).

Parameters:

  • date: past and future dates are both valid — the tool resolves the configured path for any date and reports exists: false if the note hasn't been created yet.

Errors:

  • "invalid date" — use YYYY-MM-DD format

  • "daily note format contains unsupported token(s): ..." — the configured format uses tokens the server cannot reproduce (ordinals like Do/Mo, dd, d, e, k/kk, w, Q, Z/ZZ, or the L-family localized formats); change the format in Obsidian or set DAILY_NOTES_FORMAT to a supported alternative

Returns: JSON with path (string — resolved vault-relative path), content (string|null — full note body, or null when the note doesn't exist), and exists (boolean). When exists is false, create the note with vault_write_note using the returned path.

ParametersJSON Schema
NameRequiredDescriptionDefault
dateNoYYYY-MM-DD (e.g. "2026-05-13", "2025-12-31"). Defaults to today in the server's timezone. Invalid formats like "May 13" return an error.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly/idempotent/non-destructive, but the description goes well beyond them: it discloses the config resolution chain (env vars → .obsidian/daily-notes.json → defaults), the exists:false contract for not-yet-created notes, and two named error conditions with remediation. This is rich behavioral context the annotations cannot supply.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose, then examples, when-to-use, parameters, errors, and returns — a clean, scannable structure where nearly every line carries information. It runs slightly long (the full env-var fallback chain and the exhaustive unsupported-token list) but that detail is load-bearing for error diagnosis, not filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description fully specifies the return shape (path, content, exists) and even the follow-up action when exists is false. Config resolution, valid inputs, error conditions, and sibling handoffs are all covered, so nothing an agent needs to call this correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% for the single date parameter, so the schema already carries format and default semantics (baseline 3). The description adds meaning beyond it: past and future dates are both valid, and a non-existent date yields exists:false rather than an error. That is genuine added semantics, though it stops short of anything like timezone nuance beyond the schema's server-timezone note.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (Read) and resource (daily note by date) and immediately scopes it with the vault's configured folder/format resolution. It explicitly distinguishes itself from siblings: vault_recent_notes is described as 'not date-filtered', and vault_patch_note is named for appending. An agent can route correctly without opening any other schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

A dedicated 'When to use' section covers both today's and arbitrary dates, and names two alternatives with the conditions that select them (vault_patch_note to append content, vault_recent_notes for date-adjacent vault activity). Exclusions and handoffs are explicit rather than inferred.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_get_memoryGet MemoryA
Read-onlyIdempotent

Read semantic memory from About Me/ files. These are structured memory files containing dated bullet entries organized under H2 headings. With file: single file content. With file+section: just that H2 section's entries. No args: all files concatenated (frontmatter stripped) — can be large. Returns empty string when no memory files exist yet.

With file+on_or_after: returns structured JSON entries dated on or after the boundary date (inclusive), in document order (newest first when new entries go at the top, the default). Add section to scope to one H2 section; omit it to read every H2 section's entries in the file, each keeping its section attribution. It gives complete coverage from a known date without re-parsing the section.

Example: vault_get_memory({ file: "Principles", section: "Decision heuristics (newest first)" }) Example: vault_get_memory({ file: "Opinions", section: "Code patterns", on_or_after: "2026-09-01" }) Example: vault_get_memory({ file: "Opinions", on_or_after: "2026-09-01" }) — every section's entries since the date

When to use: Reading user preferences, principles, opinions, or other persistent context stored in About Me/ files. Call vault_list_memory_files first to discover valid file and section names. Use on_or_after when you need entries from a known date forward (e.g. reconciliation boundaries). Prefer vault_read_note for reading non-memory notes.

Errors:

  • "section requires a file" / "on_or_after requires a file" — section or on_or_after was passed without file; add file

  • "memory file not found" — file does not exist in About Me/; call vault_list_memory_files to discover valid names

  • "memory file must not start with a dot" / "memory file must be a bare name without path separators" — pass the file's bare name: no folder or slash, and no leading dot (that would be a hidden file; memory files are always visible notes)

  • "section not found: …" — no H2 heading matches; the error lists the file's available sections

  • "date must be a real ISO calendar date" — on_or_after must be a valid YYYY-MM-DD date

Returns: Without on_or_after, raw markdown text. With on_or_after, JSON { entries, total, on_or_after } where each entry is { file, section, date, text } — text is the full raw entry markdown (bullet + continuation lines, wikilinks intact), same shape as vault_memory_recall entries. An empty match returns { entries: [], total: 0 }.

ParametersJSON Schema
NameRequiredDescriptionDefault
fileNoMemory file name without .md (e.g. "Principles", "Opinions"). Use the exact letter case.
sectionNoH2 section heading (e.g. "Decision heuristics (newest first)"). Matched case-insensitively, with or without the "(newest first)" suffix. Omit to read the whole file (with on_or_after, every H2 section's entries). Call vault_list_memory_files first to discover valid names.
on_or_afterNoInclusive date filter (YYYY-MM-DD). When provided with file, returns structured JSON entries dated on or after this date instead of raw markdown. Requires a file; add section to scope to one H2 section.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly/idempotent/non-destructive, and the description adds substantial context beyond them: the empty-string return when no memory files exist, the 'can be large' warning on the no-arg concatenation, frontmatter stripping, the markdown-vs-JSON output switch keyed on on_or_after, and a full enumerated error catalogue with remedies. This is genuinely rich disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Well front-loaded: the first sentence gives the core purpose, modes follow, then examples, then usage, errors, and returns. Nothing is wasted for a three-mode tool, but three near-duplicate examples plus a six-item error list make it longer than strictly necessary.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, so the description correctly carries the return contract itself, specifying raw markdown vs JSON { entries, total, on_or_after } and the entry shape, plus the empty-match case. Combined with the error catalogue and prerequisites, an agent has everything needed to call and interpret this tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the per-parameter definitions are already documented. The description still adds meaning the schema does not: inter-parameter dependencies ('section requires a file', 'on_or_after requires a file'), how section scopes the result set, and how on_or_after changes the output type. It stops short of the full 5 because format details (ISO date shape, case-insensitivity) largely mirror the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Read semantic memory from About Me/ files') and immediately distinguishes the three behavioral modes (file only, file+section, no args). It also names the siblings it is not (vault_read_note for non-memory notes, vault_list_memory_files for discovery), so an agent can route correctly without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Has an explicit 'When to use' block (user preferences, principles, opinions, persistent context), an explicit prerequisite (call vault_list_memory_files first), a conditional trigger for on_or_after (reconciliation boundaries), and an explicit alternative rule ('Prefer vault_read_note for reading non-memory notes'). When/when-not/alternatives are all present.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_insert_at_anchorInsert at AnchorA

Insert content as whole lines before or after a specific line identified by a short anchor substring. Case-sensitive matching; an anchor matching more than one line is an error unless first_match is set. Same anchor resolution as vault_delete_span. Properties are preserved; YAML formatting may be normalized to block style on first edit. Operates on the body only.

Example: vault_insert_at_anchor({ path: "Tracker.md", anchor: "| 2024-03-02 | Acme", position: "after", content: "| 2024-03-03 | Beta Corp | New entry |" }) — inserts a new table row after the matched row. Example: vault_insert_at_anchor({ path: "Notes/Plan.md", anchor: "## Phase 2", position: "before", content: "> [!note] Phase 1 must close before this starts.\n" }) — inserts a callout and a blank line above the Phase 2 heading.

When to use: Adding content at a precise location identified by a nearby line's text, without needing to know the heading structure. Good for inserting rows into tables, adding items into lists at a specific position, or placing content relative to a known landmark line. Prefer vault_patch_note for heading-targeted inserts (append/prepend to a section). Prefer vault_replace_span when replacing a block rather than inserting next to it.

Parameters:

  • anchor locates a full line — the insert never splits a line.

  • content is inserted verbatim — blank lines inside it are kept, and a trailing newline adds a blank line after the inserted block.

Errors:

  • "note not found" — verify path with vault_list_notes

  • "path must end in …" — add the .md extension

  • "anchor not found" — fragment not on any line; verify with vault_read_note

  • "ambiguous anchor …" — the anchor matches multiple lines; use a longer fragment or set first_match: true

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "concurrent write in progress" — another write to this note is in flight; re-read the note and retry

  • "content contains a control character" — content includes a non-printable control byte; remove it before writing

Obsidian syntax: content is Obsidian Flavored Markdown (no escaping applied). Watch for: #word = tag, [[ = wikilink, %% = comment block.

Returns: Confirmation message "Inserted lines <before|after> anchor in " — N counts the lines content supplied.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesVault-relative path to the note, including the ".md" extension (e.g. "Notes/Plan.md", "Tracker.md"). Use the exact letter case.
anchorYesShort, unique substring on the line to insert next to (case-sensitive). Pick a brief fragment — do not paste the whole line.
contentYesContent to insert (one or more lines).
positionYes"before" places the content on the lines above the anchor line; "after" places it on the lines below. The anchor line itself is never changed.
first_matchNoIf the anchor matches more than one line, use the first match instead of erroring (default: false — ambiguity is an error).

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (readOnlyHint=false, destructiveHint=false, idempotentHint=false), the description discloses case-sensitive matching, the ambiguity-is-an-error rule unless first_match is set, that properties are preserved but YAML may normalize to block style on first edit, and that only the body is touched. It also enumerates nine specific error strings with remedies, which annotations cannot convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The content is long but well-organized and front-loaded: core behavior, two worked examples, when-to-use routing, parameter notes, then errors. The error catalogue is extensive but each entry earns its place by pairing a message with a fix. Slightly verbose overall, but no sentence is pure filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, but the description supplies the return contract verbatim ('Inserted <N> lines <before|after> anchor in <path>') and defines N. Combined with the error catalogue and Obsidian syntax caveats (#, [[, %%), an agent has everything needed to call this correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds real meaning: the anchor locates a full line and the insert never splits one, content is inserted verbatim with internal blank lines preserved, and a trailing newline adds a blank line after the block. These are semantics the schema does not capture.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource ('Insert content as whole lines before or after a specific line identified by a short anchor substring') and immediately scopes it ('Operates on the body only'). It explicitly distinguishes itself from vault_patch_note and vault_replace_span, so an agent can route correctly without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It provides an explicit 'When to use' section with concrete scenarios (table rows, list items, landmarks) and names two alternatives with the conditions that select them: vault_patch_note for heading-targeted inserts and vault_replace_span when replacing a block rather than inserting next to it. Nothing is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_list_filesList FilesA
Read-onlyIdempotent

List non-markdown files in the vault or a folder — images, canvases, PDFs, data files — with per-file byte sizes and per-extension counts.

Example: vault_list_files({}) — every non-markdown file in the vault Example: vault_list_files({ folder: "attachments" }) Example: vault_list_files({ extensions: [".png", ".jpg"], limit: 20 })

When to use: discovering what files exist before reading them with vault_read_file. vault_list_notes and vault_search_by_folder cover only markdown notes, and beyond notes vault_search indexes only canvas, PDF, and text-format files, so this is the discovery surface for everything else. For the files one specific note links to, prefer vault_get_outgoing_links.

Behavior: Reads the filesystem rather than the search index, so use the folder's exact letter case; on a case-sensitive filesystem a different case finds nothing.

Errors:

  • A visible folder containing no files — or one that doesn't exist — returns an empty listing, not an error.

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — the folder starts at the filesystem root, escapes the vault (e.g. "../elsewhere") or names the vault root itself (e.g. "."), or is hidden like ".obsidian" (hidden folders are not listable, matching Obsidian); use a vault-relative folder outside hidden folders, and omit folder to list the whole vault.

Returns: JSON with files (array of { path, extension, bytes }, sorted by path; extension is "(none)" for a file without one), extension_counts (per-extension totals over the full filtered set), total (full filtered count), and truncated (true when total exceeds limit). bytes is the on-disk file size, not the delivery cost: reading an image via vault_read_file returns a copy shrunk to fit when needed, so a large listed image is still cheap to read. Text formats return verbatim, so their listed size is what a read delivers; one over 100 KiB must be read in windows with vault_read_file's start_line and limit. Only supported types are readable via vault_read_file.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMax entries returned (default 50).
folderNoFolder path to search recursively (e.g. "attachments" or "Projects/media"). Omit to list the whole vault.
extensionsNoOnly include these extensions, case-insensitive, leading dot optional (e.g. [".png", "jpg"]).

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly/idempotent/non-destructive, yet the description adds substantially more: reads the filesystem rather than the index (explaining the case-sensitivity rule), empty-vs-error behavior for missing folders, three named error strings with their causes and remedies, and how 'bytes' relates to actual read cost (images shrunk, text over 100 KiB needing windowed reads).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core purpose and three illustrations, then organized under 'When to use', 'Behavior', 'Errors', and 'Returns'. It is long for a listing tool and the Returns paragraph drifts into read-path advice, but nearly every sentence carries non-obvious information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, so the description fully documents the return shape (files/extension_counts/total/truncated, path sorting, '(none)' extension). Combined with error handling, case sensitivity, and sibling routing, an agent has everything needed to call this correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so per-parameter docs already exist and the baseline is 3. The description adds real meaning on top: it demonstrates each parameter with worked examples and supplies the case-sensitivity rule for 'folder' and the truncation semantics tied to 'limit' via the 'truncated' return field.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('List non-markdown files in the vault or a folder') with an explicit scope qualifier ('non-markdown') that immediately separates it from note-oriented siblings. The examples make the resource and filter axes concrete.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

A dedicated 'When to use' block names the alternative tools (vault_read_file, vault_list_notes, vault_search_by_folder, vault_search, vault_get_outgoing_links) and the exact condition that selects each. It also states which file types other search surfaces index, so the boundary is not left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_list_memory_filesList Memory FilesA
Read-onlyIdempotent

Discovery tool — lists About Me/ memory files with each file's heading outline, per-section entry counts, and leading callout. An entry is a dated bullet line ("- YYYY-MM-DD: text"). Does NOT return actual entries.

Example: vault_list_memory_files() returns [{ file: "Principles", title: "Principles", bytes: 2048, entry_policy: "append-only", leading_callout: null, headings: [{ level: 2, text: "Decision heuristics (newest first)", entry_count: 12 }] }, ...]

When to use: Discovering what memory files and sections exist — and what each file is for — BEFORE calling vault_get_memory, vault_update_memory, or vault_delete_memory. Always call this first to get valid file and section names, and to check a file's entry_policy before pruning entries.

Behavior: Lists every .md file directly inside About Me/, sorted by file name, whether or not it has frontmatter or a scope callout. Subfolders are not read, and hidden (dot-prefixed) files are skipped.

Errors:

  • An empty or nonexistent memory folder returns an empty array, not an error.

Returns: JSON array of file outlines, each { file, title, bytes, entry_policy, leading_callout, headings } — file is the name the other memory tools take as file (no .md); bytes is the on-disk file size; headings lists H1 and H2 headings in order, with entry_count on H2s; leading_callout is the top-of-file callout ({ type, title, body }; by convention a "Scope of this file" block describing what belongs in the file), or null; entry_policy is "append-only" (the default: by convention, entries are never edited or deleted) or "living" (a current-state file whose expired entries may be pruned; declared via entry-policy frontmatter). The server does not enforce either policy.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (read-only, idempotent), and the description adds substantial context beyond them: hidden files are skipped, subfolders are not read, an empty folder returns an empty array instead of an error, entries are dated bullets, and entry_policy semantics are explained including that the server does not enforce either policy.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Content is front-loaded (purpose, example, when-to-use, behavior, errors, returns) and every section carries information, but the embedded JSON example is long and the description as a whole is heavier than strictly necessary for a no-argument listing tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description fully compensates by enumerating every returned field (file, title, bytes, entry_policy, leading_callout, headings) and its meaning, plus the error case and the entry-policy convention. An agent has everything needed to call and interpret it.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, which is the baseline-4 case. The description does enrich the semantics of the returned object fields, but those are output semantics rather than input parameter meaning, so it does not exceed the zero-parameter baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource ('lists About Me/ memory files') plus exactly what is and is not included ('heading outline, per-section entry counts, and leading callout... Does NOT return actual entries'). This cleanly separates it from vault_get_memory, vault_list_files, and vault_search, which the agent can distinguish without opening schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit 'When to use' section names the downstream tools (vault_get_memory, vault_update_memory, vault_delete_memory) and the sequencing rule ('Always call this first to get valid file and section names'). It also gives a distinct reason to call it, checking entry_policy before pruning.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_list_notesList NotesA
Read-onlyIdempotent

List .md file paths in the vault, optionally filtered by folder and/or glob pattern. Returns paths only — not content or metadata.

Example: vault_list_notes({ folder: "Projects" }) Example: vault_list_notes({ glob: "**/session-log.md" }) Example: vault_list_notes({ folder: "Projects", glob: "*.md" }) — the folder's top-level notes only

When to use: Browsing what exists in a folder by filename, or finding notes matching a path pattern. Prefer vault_search_by_folder when you need metadata (tags, type, related) along with paths. Prefer vault_search for content-based discovery. Use vault_read_note to read a note from the results.

Parameters:

  • folder names a whole folder and includes its subfolders: "Projects" covers "Projects/Archive" but not "ProjectsOld/". This tool reads the filesystem rather than the search index, so use the folder's exact letter case, as other results show it; on a case-sensitive filesystem a different case finds nothing.

  • glob matches each note's path inside folder (its vault-relative path when folder is omitted), case-sensitively. * stays within one folder level and ** spans any depth: with folder "Projects", ".md" lists the folder's top-level notes and "**/.md" every note under it. Returned paths are always vault-relative.

Behavior: Paths come back sorted by vault-relative path, uppercase before lowercase. Hidden (dot-prefixed) notes and folders are never listed, matching Obsidian; symlinked notes are included.

Errors:

  • A nonexistent folder or no glob matches returns an empty array, not an error.

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — the folder starts at the filesystem root, escapes the vault or names the vault root itself (e.g. "."), or is hidden like ".obsidian"; use a vault-relative folder outside hidden folders, and omit folder to list the whole vault.

Returns: JSON array of vault-relative path strings (e.g. ["Notes/idea.md", "Projects/plan.md"]).

ParametersJSON Schema
NameRequiredDescriptionDefault
globNoGlob pattern for note paths (e.g. "**/*session-log*.md").
folderNoVault-relative folder to list (e.g. "About Me", "Projects").

TDQS

A5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well past the annotations (readOnly/idempotent/non-destructive), disclosing sort order (uppercase before lowercase), hidden dot-file exclusion matching Obsidian, symlink inclusion, filesystem-vs-index sourcing, case sensitivity, and exact error semantics (empty array vs 'absolute path blocked'/'path traversal blocked'/'hidden path blocked'). This is rich context an agent cannot derive from any structured field.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Long but tightly organized with headers (When to use / Parameters / Behavior / Errors / Returns), examples front-loaded after the first sentence, and no filler. Each section earns its space by covering a distinct decision an agent has to make.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 2-param, no-output-schema read tool, the definition covers purpose, routing, parameter edge cases, ordering, hidden/symlink handling, and the full error taxonomy including remediation. Nothing needed to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Even though schema coverage is 100%, the description adds real meaning: folder includes subfolders but 'Projects' does not match 'ProjectsOld/', exact letter case is required on case-sensitive filesystems, and glob semantics are spelled out ('* stays within one level, ** spans any depth', matched against the vault-relative path, case-sensitive). Far exceeds the terse schema descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with a precise verb+resource+scope ('List .md file paths in the vault, optionally filtered by folder and/or glob pattern') and immediately bounds the output ('paths only — not content or metadata'). This distinguishes it cleanly from vault_search, vault_search_by_folder and vault_read_note.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit 'When to use' line plus two explicit routing rules: 'Prefer vault_search_by_folder when you need metadata... Prefer vault_search for content-based discovery. Use vault_read_note to read a note from the results.' Names both alternatives and the condition that selects each.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_list_property_keysList Property KeysA
Read-onlyIdempotent

Discover all property keys in the vault with note counts and sample values. Lets you understand the vault's metadata schema without reading individual notes.

Example: vault_list_property_keys() returns [{ key: "tags", count: 342, sample_values: ["session-log", "project"] }, ...]

When to use: Discovering what properties exist before searching by property. Good first step for vault orientation alongside vault_list_tags. Prefer vault_list_property_values when you need the full list of values for a specific key. Prefer vault_search_by_property to find notes matching a specific key-value pair.

Parameters:

  • folder names a whole folder and includes its subfolders: "Projects" covers "Projects/Archive" but not "ProjectsOld/". Matching ignores ASCII letter case; omit folder to scan the entire vault.

Behavior:

  • Only frontmatter properties count; inline Dataview fields (key:: value) are not listed.

  • count is the number of notes that have the key, including notes where its value is empty (null).

  • sample_values are the key's 3 most frequent displayed strings. Values with the same string are grouped before choosing samples, counting each array element separately; ties use binary text order.

  • Checkbox values appear as "1" and "0"; null values are skipped.

Errors:

  • An empty vault or folder returns an empty array, not an error.

Returns: JSON array of { key, count, sample_values } sorted by count descending, then by key.

ParametersJSON Schema
NameRequiredDescriptionDefault
folderNoRestrict to a folder (e.g. "Projects")

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive), and the description adds substantial context beyond that: only frontmatter counts (inline Dataview ignored), count includes null-valued notes, sample_values selection rules and tie-breaking, checkbox rendering as '1'/'0', and the empty-vault behavior. This genuinely enriches understanding rather than repeating annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose and example, then organized under When to use / Parameters / Behavior / Errors / Returns. Long but every section carries needed information, and the header structure makes it skimmable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, but the description fully specifies the return shape (JSON array of {key, count, sample_values}, sorted by count desc then key) and error behavior. For a single-param read tool, nothing an agent needs is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the single param has a terse schema description, but the description adds real meaning: folder includes subfolders ('Projects' covers 'Projects/Archive' but not 'ProjectsOld/'), matching is ASCII-case-insensitive, and omitting folder scans the whole vault. This goes beyond the schema text, though it is a single parameter.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Discover all property keys in the vault with note counts and sample values') and scopes it as metadata-schema inspection without reading notes. The example concretely anchors the shape. Clearly distinguishable from siblings like vault_list_tags and vault_list_property_values.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit 'When to use' plus two named alternatives with the conditions that select them: vault_list_property_values for values of a specific key, vault_search_by_property for key-value matching. Nothing is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_list_property_valuesList Property ValuesA
Read-onlyIdempotent

List distinct values for a specific property key with how often each occurs.

Example: vault_list_property_values({ key: "status" }) returns [{ value: "done", count: 211 }, { value: "active", count: 47 }, ...]

When to use: Enumerating possible values for a property key before calling vault_search_by_property. Call vault_list_property_keys first to discover valid key names.

Parameters:

  • key is case-sensitive and must match exactly as returned by vault_list_property_keys.

  • folder names a whole folder and includes its subfolders: "Projects" covers "Projects/Archive" but not "ProjectsOld/". Matching ignores ASCII letter case.

  • limit applies after sorting by count descending, so you always get the most-used values first. Nothing in the response signals truncation: exactly limit values may mean more exist, which is common for keys with many distinct values like "title" or "created"; raise limit to check.

Behavior:

  • Handles both scalar properties (status: "active") and array properties (tags: ["a", "b"]). Array elements are unpacked and counted individually, so the sum of counts may exceed the note count.

  • Values with the same displayed string share one row with combined occurrence counts: number 1 and text "1" count together, while text "1.0" stays separate. Grouping happens before limit.

  • Checkbox values are stored as 1 and 0, so true and false come back as "1" and "0", counted with the numbers 1 and 0.

  • vault_search_by_property matches stored numbers numerically and text exactly; value "1" matches the number 1, the text "1", and a checked checkbox.

  • null values are skipped.

Errors:

  • An unknown key or empty folder returns an empty array, not an error.

Returns: JSON array of { value, count } sorted by count descending, then by value in binary text order ("10" before "2").

ParametersJSON Schema
NameRequiredDescriptionDefault
keyYesProperty key name — use vault_list_property_keys to discover valid keys (e.g. "status", "type", "tags").
limitNoMax values to return (default 50).
folderNoRestrict to a folder (e.g. "Projects")

TDQS

A5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive), but the description adds substantial non-obvious behavior: array elements unpacked and counted individually, scalar/array handling, numeric-vs-text grouping quirks ('1' vs '1.0'), checkbox stored as 1/0, null skipping, and the silent-truncation caveat at limit. These are things an agent genuinely could not infer from annotations alone.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with a concrete example, then organized under clear headers (When to use, Parameters, Behavior, Errors, Returns). Every paragraph is dense functional content; nothing is filler or repeated from the schema or annotations.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only listing tool with no output schema, the description fully specifies the return shape, sort order (count descending then binary text order), and error behavior (unknown key or empty folder yields an empty array, not an error). An agent has everything needed to call and interpret it.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, yet the description adds real meaning beyond it: 'key' is case-sensitive and must match exactly, 'folder' includes subfolders with case-insensitive matching ('Projects' covers 'Projects/Archive' but not 'ProjectsOld/'), and 'limit' applies after count-descending sort with no truncation signal. This goes well past restating the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('List distinct values for a specific property key with how often each occurs'), which unambiguously separates it from vault_list_property_keys (keys) and vault_search_by_property (notes). The inline example with the exact response shape removes any ambiguity about output.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states when to use it ('Enumerating possible values ... before calling vault_search_by_property') and the prerequisite sequencing ('Call vault_list_property_keys first to discover valid key names'). The routing to siblings is stated, not inferred.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_list_tagsList TagsA
Read-onlyIdempotent

List all tags in the vault with note counts, ordered by count descending. Only frontmatter tags are counted (inline #tags in note bodies are not indexed). Each hierarchical tag (e.g. "project/vault-cortex") appears as one full entry, not split into segments. Count is unique notes, not occurrences.

Example: vault_list_tags() returns [{ tag: "session-log", count: 42 }, { tag: "project/vault-cortex", count: 8 }, ...]

When to use: Discovering what tags exist before searching by tag. Good first step for vault orientation. Prefer vault_search_by_tag once you know which tag to query — it supports hierarchical prefix matching ("project" matches "project/*").

Errors:

  • A vault with no tagged notes returns an empty array, not an error.

Returns: JSON array of { tag, count }; tag omits the "#" prefix.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive, closed-world), yet the description adds substantial behavioral context beyond them: only frontmatter tags are indexed (inline #tags ignored), hierarchical tags are returned whole rather than split, count is unique notes not occurrences, and the # prefix is stripped. It also discloses the empty-vault behavior (empty array, not an error), which no annotation conveys.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core behavior, then example, usage, errors, and returns, each under a clear label. Every sentence carries new information; even the example earns its place by showing the exact record shape. No filler or hedging.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the full burden of describing the return value, and it does so with both a concrete example and a prose summary ('JSON array of { tag, count }'). Error behavior for the empty case is covered, so an agent has everything needed to call and interpret this tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool takes zero parameters, so there is nothing for the description to disambiguate; the baseline for a no-param tool is 4. It does clarify the shape of each returned entry and the tag format, which is useful context but belongs to output semantics rather than parameter semantics.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('List all tags in the vault with note counts') plus the ordering ('count descending'), which is more than a bare restatement of the title. It also implicitly separates itself from siblings like vault_search_by_tag and vault_list_property_keys by scoping to tags only.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly names when to use it ('Discovering what tags exist before searching by tag. Good first step for vault orientation') and names the alternative with the condition that selects it ('Prefer vault_search_by_tag once you know which tag to query — it supports hierarchical prefix matching'). This is textbook when/when-not/alternative guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_list_tasksList TasksA
Read-onlyIdempotent

List checkbox tasks across the whole vault with structured filters — the Tasks-plugin data model over MCP. Both task metadata formats are indexed: emoji signifiers (📅 due, ⏳ scheduled, 🛫 start, ➕ created, ✅ done, ❌ cancelled, 🔺⏫🔼🔽⏬ priority, 🔁 recurrence, 🏁 onCompletion, 🆔/⛔ dependencies) and Dataview inline fields ([due:: 2026-07-04], [priority:: high], ...). Every result carries its attribution — note path, folder, line number, and the nearest heading when the task sits under one (the lane on a Kanban board) — so no follow-up reads are needed to locate a task. Task lines inside fenced code blocks and %% %% comment blocks are not indexed. Checkboxes typed NON_TASK in the Tasks plugin's status registry are also excluded.

Example: vault_list_tasks({ due: { before: "2026-07-04" } }) — overdue triage; the default status (not_done) and sort (due ascending) make this the "what's overdue?" call Example: vault_list_tasks({ path: "Code Projects/vault-cortex/TASKS.md", heading: ["Active", "Up Next", "Waiting On"], sort_by: "position" }) — actionable Kanban lanes in board order Example: vault_list_tasks({ folder: "Code Projects/vault-cortex" }) — all open tasks across a project tree (TASKS.md + task-notes/ subdirectories) Example: vault_list_tasks({ status: "done", done: { after: "2026-06-26" } }) — what got completed this week Example: vault_list_tasks({ top_level_only: true, path: "TASKS.md" }) — board cards only, excluding checklist sub-items

When to use: Reading task status and order on one board (path + sort_by: "position"; add status: "all" to include done and cancelled cards). Also any vault-wide task triage question — "what's overdue?", "what's open per project?", "what did I finish this week?" — in one call instead of per-board reads. Prefer vault_read_note (heading mode) only when you need a lane's verbatim Markdown or a task's state right after a write. Prefer vault_search for full-text queries over note content.

Behavior: Reads the search index, which picks up a file change within a few seconds, so a task written moments ago may still show its old state.

Parameters:

  • status: virtual values expand in arrays — ["not_done", "done"] matches todo + in_progress + done.

  • due / scheduled / start / done / created / cancelled: a date filter only matches tasks that HAVE that date.

  • folder: a whole folder, subfolders included ("Projects" covers "Projects/Archive" but not "ProjectsOld/"), ignoring ASCII letter case.

Errors:

  • A malformed or calendar-invalid date filter throws with remediation text ("Use YYYY-MM-DD")

  • path without the ".md" extension is rejected

  • No matches returns { total: 0, tasks: [] }, not an error

Returns: JSON { total, tasks }. Every task carries path, line, status, status_char, description, folder, depth (0 for top-level, 1+ for sub-tasks), is_kanban_task, depends_on, and tags (the arrays are [] when empty). Every other field appears only when the task has it: heading (nearest heading above the task), created/scheduled/start/due/done/cancelled dates, priority, recurrence, on_completion, task_id, block_id, parent_block_id (sub-tasks whose parent carries a ^block-id), done_lanes (Kanban boards only), and subtask_progress — { done, total } over the task's DIRECT checklist children, present only when the task has a checklist; done counts status "done" only (a cancelled child counts toward total, not done), and the counts ignore the query's filters — so a filtered or top_level_only read still shows each card's checklist progress.

ParametersJSON Schema
NameRequiredDescriptionDefault
dueNoDue date (📅 / [due:: ]) bounds
tagNoInline task tag, bare name without "#"; parent tags match children
doneNoDone date (✅ / [completion:: ]) bounds
pathNoRestrict to one note (vault-relative path ending ".md", case-sensitive)
limitNoMax results (default 50); total always reports the full match count
startNoStart date (🛫 / [start:: ]) bounds
folderNoRestrict to a folder (e.g. "Code Projects/vault-cortex")
statusNoStatus filter, OR-combined (default "not_done" = todo + in_progress, excluding done and cancelled). "all" includes every status.not_done
createdNoCreated date (➕ / [created:: ]) bounds
headingNoExact heading text or array of headings, OR-combined, case-sensitive (e.g. "Active" or ["Active", "Up Next"])
sort_byNoSort key (default "due"). Date sorts cascade through related fields when the primary is absent (through the rest of due → scheduled → start → created, in that order; done does not cascade); each fallback uses its own natural direction. "position" sorts by file path then line number — the natural order for Kanban boards.due
priorityNoPriority levels, OR-combined; "none" selects tasks with no priority signifier
cancelledNoCancelled date (❌ / [cancelled:: ]) bounds
scheduledNoScheduled date (⏳ / [scheduled:: ]) bounds
sort_directionNoSort direction. Default per field: "asc" for due/scheduled/priority/position, "desc" for start/created/done/note_mtime. Within a date cascade, each fallback uses its own default; an explicit value overrides all fields uniformly.
top_level_onlyNoWhen true, only top-level tasks (depth 0) are returned — excludes indented sub-tasks and checklist items. Default false.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly/idempotent/non-destructive, yet the description adds substantial behavior beyond them: index lag ('a task written moments ago may still show its old state'), explicit exclusions (fenced code blocks, %% %% comments, NON_TASK statuses), and error semantics (malformed dates throw, no-match is not an error). This is exactly the context an agent needs to avoid misreading stale results.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose, then examples, usage, behavior, parameters, errors, returns in clear sections — every section earns its place for a 16-parameter tool. It is long, and some example redundancy exists, but the structure makes it scannable rather than bloated.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, so the description carries the full return-shape burden, and it does so thoroughly (total/tasks, always-present vs conditional fields, subtask_progress semantics including the cancelled-child edge case and filter independence). For a complex 16-param read tool, nothing material is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds genuine meaning beyond it: 'virtual values expand in arrays' for status, the rule that 'a date filter only matches tasks that HAVE that date', and folder case-insensitivity with subfolder inclusion. These semantics are not obvious from the schema alone.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (list checkbox tasks across the vault) and immediately scopes it against the Tasks-plugin data model, naming what metadata formats are indexed. It explicitly routes away from siblings: 'Prefer vault_read_note (heading mode)... Prefer vault_search for full-text queries'.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Has a dedicated 'When to use' block plus five concrete examples covering triage, Kanban lanes, project trees, and weekly done queries, and explicitly names alternatives (vault_read_note, vault_search) with the condition that selects each. Nothing is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_memory_recallMemory RecallA
Read-onlyIdempotent

Recall memory entries about a topic — entry-granular hybrid (keyword + semantic) retrieval across ALL About Me/ files and ALL time. Returns every relevant dated entry sorted oldest-first, so the full evolution of a preference, opinion, or fact is visible — semantic matching finds early entries even when their phrasing differs from the query. Tuned for recall over precision: expect some marginal entries and judge relevance yourself when synthesizing an answer. Content-word queries ("testing philosophy", "sustainable pacing") rank best. A meta-framed query ("opinions on testing") that scores below the relevance threshold degrades to relaxed any-term keyword matching instead of returning nothing.

Example: vault_memory_recall({ query: "working hours and pacing" }) Example: vault_memory_recall({ query: "testing philosophy", file: "Opinions" })

When to use: Answering "what does my memory say about X?" or "how has my view on Y evolved?" — topic-based recall across memory files. Prefer vault_get_memory to read a known file or section verbatim; prefer vault_search for notes outside the memory layer.

Errors:

  • No matching entries returns { entries: [], total: 0 }, not an error

  • An unknown file returns empty results — call vault_list_memory_files to discover valid names

Returns: JSON { entries, total, truncated, search_mode, reranked }. Each entry is { file, section, date, text } — text is the raw entry markdown (wikilinks intact, continuation lines included); file and section feed directly into vault_get_memory or vault_delete_memory. entries ascend by date (oldest first). total counts all matched entries; truncated=true means limit dropped the least-relevant matches — never a date range — so raise limit or narrow the query for the complete set. file is applied before limit, so limit keeps the most relevant matches from that file. search_mode is "hybrid" when vector matching contributed, "fts" when the entries came from keyword matching alone — including the any-term fallback that rescues a would-be-empty result; reranked is true when the cross-encoder relevance cut was applied.

ParametersJSON Schema
NameRequiredDescriptionDefault
fileNoOptional: restrict to one memory file, name without .md (e.g. "Opinions"), in its exact letter case. Omit for cross-file recall — the default and usual choice.
limitNoCap on returned entries (default 50).
queryYesTopic to recall — natural language works best (semantic matching bridges phrasing drift across months); content words about the topic rank better than meta framing ("testing philosophy" over "opinions on testing")

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare read-only/idempotent/non-destructive, but the description adds substantial behavioral context beyond them: recall-over-precision tuning (expect marginal entries), the any-term keyword fallback that rescues a would-be-empty result, that unknown files return empty rather than erroring, and the meaning of truncated/search_mode/reranked.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose then usage then errors then returns, so scanning is easy. It is long and the Returns paragraph is dense, but nearly every sentence carries non-redundant semantics; only marginal tightening is possible.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description fully specifies the return shape ({entries, total, truncated, search_mode, reranked}), per-entry fields, sort order, and error semantics. Nothing an agent needs to interpret results correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description genuinely extends it: query phrasing guidance (content words rank better than meta framing), that file is applied before limit, and that limit drops least-relevant matches rather than a date range. The file parameter's case-sensitivity and default omission are covered by the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (recall), resource (memory entries), retrieval mechanism (entry-granular hybrid keyword + semantic), and scope (ALL About Me/ files, ALL time). It explicitly distinguishes itself from vault_get_memory and vault_search, so an agent can route without opening schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The 'When to use' block gives concrete trigger questions ('what does my memory say about X?') and names the two alternatives with the conditions that select them: vault_get_memory for a known file/section verbatim, vault_search for notes outside the memory layer. Exclusions are explicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_move_noteMove NoteA
Destructive

Move or rename a note and rewrite every link across the vault that points to it, like Obsidian's built-in rename. Incoming links in other notes — [[wikilinks]], [[wikilink|aliases]], [[wikilink#headings]], ![[embeds]], markdown, and frontmatter links (e.g. related:) — are updated to the new path; the moved note's own relative links are fixed so they still resolve from the new folder, including relative links to attachments (e.g. ![[../assets/photo.png]], img). A link is only rewritten when leaving it unchanged would break it, so a short [[Note]] that stays unambiguous after a folder move is left alone. Moving a note any other way can silently break its backlinks.

Example: vault_move_note({ old_path: "Inbox/Draft.md", new_path: "Inbox/Spec.md" }) — pure rename. Example: vault_move_note({ old_path: "Inbox/spec.md", new_path: "Inbox/Spec.md" }) — case-only rename; works even where the filesystem treats both spellings as one file. Example: vault_move_note({ old_path: "Inbox/Spec.md", new_path: "Projects/Spec.md" }) — move to another folder, updating links and the note's own relative links. Example: vault_move_note({ old_path: "Inbox/Spec.md", new_path: "Projects/Spec.md", prune_empty_folders: true }) — also remove "Inbox" if the move empties it.

When to use: Renaming a note or relocating it to a different folder while keeping the link graph intact. Prefer this over vault_write_note + vault_delete_note, which would orphan every backlink. To only change a note's body or properties, use vault_patch_note or vault_update_properties. Protected paths (About Me/ and the daily notes folder (read from DAILY_NOTES_FOLDER or .obsidian/daily-notes.json, defaulting to Daily Notes/)) cannot be moved.

Parameters:

  • prune_empty_folders removes each parent folder of old_path that the move leaves with zero entries, up to but never including the vault root; a folder holding any file, even a hidden .DS_Store, is kept. An in-place rename or a move into a subfolder of the source prunes nothing. Pruning is best-effort: a folder that can't be removed never fails the call. Without it, empty folders stay, matching Obsidian.

Errors:

  • "destination exists: …" — a note already lives at new_path; this tool never overwrites. Pick a free path or delete the existing note first.

  • "note not found: …" — old_path does not exist; verify it with vault_list_notes.

  • "source and destination are the same path" — old_path and new_path name the same note, so there is nothing to move.

  • "cannot move protected path …" / "cannot move into protected path …" — old_path or new_path sits under a protected folder.

  • "cannot read daily notes config from .obsidian/daily-notes.json" — the file exists but is unreadable, so the daily notes folder to protect is unknown; repair it, or set DAILY_NOTES_FOLDER or PROTECTED_PATHS, then retry.

  • "path must end in …" — both old_path and new_path must end in .md.

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use vault-relative paths with no hidden (dot-prefixed) file or folder in them (notes cannot move from or into hidden paths, matching Obsidian).

  • "concurrent write in progress" — a write is in flight on the note, the destination, or one of its backlink sources (the move locks all of them as one unit); retry the move.

  • "backlink set did not stabilize" — the vault was modified during the move and new backlink sources kept appearing across retries; nothing was written; retry the move.

  • An ordinary move that fails partway (rare: a permission or disk error) — no data is lost, and the error names what failed and the resulting state. The original is deleted last, after the destination and every backlink are written. If a backlink write failed: new_path exists and old_path is intact, so delete the partial new_path, then re-run the move. If the final delete failed: both paths exist, so delete old_path to finish.

  • A case-only rename that fails partway — the note is renamed in place first. If the rename failed: nothing was written. If a later link write failed: the note already lives at new_path and old_path is gone, so fix the remaining links in place (the error names the note whose update failed) instead of re-running the move.

Obsidian syntax: Link rewrites preserve each link's existing form — embed marker (!), heading anchor (#…), and alias (|…) are kept; a markdown link keeps its original extension and link text. Only the target path is changed.

Returns: JSON with moved_to (the new path), links_updated (count of link occurrences rewritten, including the moved note's own relative links), updated_notes (sorted paths of the other notes that were edited; the moved note is implied by moved_to), and pruned_empty_folders (count of empty parent folders removed — 0 unless prune_empty_folders was set).

ParametersJSON Schema
NameRequiredDescriptionDefault
new_pathYesDestination vault-relative path (e.g. "Projects/Spec.md"). Must end in .md and must not already exist; parent folders are created as needed. Use the exact letter case of existing folders; a different case can create a second folder.
old_pathYesCurrent vault-relative path of the note to move (e.g. "Inbox/Draft.md"). Must end in .md. Use the exact letter case.
prune_empty_foldersNoWhen true, also remove parent folders of old_path that the move leaves empty. Default false.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and idempotentHint=false, but the description adds far more: exactly which link forms are rewritten, the 'only rewrite when leaving it unchanged would break it' rule, write ordering (original deleted last), partial-failure recovery for both ordinary and case-only renames, lock scope, and pruning semantics. This is behavioral context an agent cannot get from the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core behavior, then examples, when-to-use, parameters, errors, syntax, and returns — clearly sectioned and skimmable. It is long, but the length is justified by the number of distinct error/recovery paths; the four examples earn their place by disambiguating rename vs move vs prune.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite having no output schema, the description fully specifies the return payload (moved_to, links_updated, updated_notes, pruned_empty_folders), enumerates the failure modes and their recovery, and covers the preconditions (protected paths, path form). Nothing an agent needs to invoke or recover from this call is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the 'Parameters:' section meaningfully extends prune_empty_folders beyond the schema (per-parent behavior, hidden-file caveat, no-op on in-place rename or moves into source subfolders, best-effort failure tolerance). old_path/new_path behavior such as case-only renames and the .md requirement is also elaborated, though much of that duplicates the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The opening sentence states a specific verb (move or rename), a specific resource (a note), and the distinctive side effect (rewriting every incoming and outgoing link across the vault). It explicitly distinguishes itself from siblings by naming vault_write_note + vault_delete_note, vault_patch_note, and vault_update_properties as the wrong tools for adjacent tasks.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

A dedicated 'When to use' line gives the triggering scenario (rename or relocate while keeping the link graph intact), and the description states both when-not (use vault_patch_note/vault_update_properties for body or property edits) and the anti-pattern (write+delete orphans backlinks). It also discloses the protected-path precondition that blocks the call.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_patch_notePatch NoteA
Destructive

Surgical edits to a markdown note — append, prepend, replace, or insert content by heading. Frontmatter values are preserved; YAML formatting may be normalized to block style on first edit.

Example: vault_patch_note({ path: "Projects/plan.md", operation: "append", heading: "Open questions", content: "- Which region hosts the backup?" })

When to use: Modifying part of an existing note without overwriting the entire body. Prefer vault_write_note for creating new notes, or full rewrites (with overwrite: true). Prefer vault_replace_in_note for in-place text changes (typos, renaming) that stay in the same location. Prefer vault_create_task for adding a task. Prefer vault_update_task for completing or moving a task in one write.

Operations:

  • append: add content at end of section (or end of file if no heading)

  • prepend: add content after heading line (or at the top of the body, below frontmatter, if no heading — how you add a leading callout). To start a new section above the note's current first heading, use insert_before on that heading, not a no-heading prepend.

  • replace: replace section body (heading preserved; requires heading; errors if the target has child headings unless include_children is set)

  • insert_before: insert content above the heading line (requires heading)

Heading-targeted ops keep the matched heading and write content verbatim. No separator is added around the content — end it with a newline to leave a blank line after the inserted block.

Limitation: A no-heading prepend inserts at body line 0. If the note has content above its first heading and your content starts with a heading, the pre-existing content becomes the new section's body. The write still succeeds and the confirmation says so — use insert_before on the first heading to place a section above it instead.

Section boundaries: a section spans from its heading to the next heading of the same or higher level (or EOF), so it includes its child headings. Empty headings ("##" with no text) act as boundaries but cannot be targeted — edit their content via vault_replace_in_note instead.

Editing a leading callout: read it via vault_read_note(outline: true), then vault_replace_in_note the old block for the new one (a no-heading prepend would stack a second callout above it).

Errors:

  • "note not found" — path does not exist; check vault_list_notes for valid paths

  • "path must end in …" — add the .md extension

  • "heading not found" — no heading matches the text; error lists available headings

  • "ambiguous heading" — multiple headings match; use heading_level to disambiguate, or use vault_replace_in_note to target by text content when headings share the same level

  • "operation … requires a heading target" — replace and insert_before need a heading

  • "heading cannot be empty" — heading is whitespace only; pass the heading's text

  • "content begins with the heading … which would duplicate it" — content's first line repeats the target heading; omit it (the matched heading is kept automatically)

  • "section … has N child headings …" — the target section contains child headings that replace would destroy; pass include_children: true to confirm, or target the child heading directly

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "concurrent write in progress" — another write to this note is in flight; re-read the note and retry

  • "content contains a control character" — content includes a non-printable control byte; remove it before writing

Obsidian syntax: Content is Obsidian Flavored Markdown (no escaping applied). Watch for: #word = tag, [[ = wikilink, %% = comment block. Inserting heading-level content (## New Section) changes the note's structure — future heading-targeted ops may resolve differently. Table rows: send only the data row ("| cell1 | cell2 |"), not the header or separator — duplicating them splits the table.

Returns: Confirmation message — "Applied to → ", where target is the matched heading (e.g. "## Active") or "file body" for a no-heading append/prepend. A no-heading prepend that nested existing content under an inserted heading adds a sentence naming the content's size and the call that would have avoided it.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesVault-relative path to the note, including the ".md" extension (e.g. "TASKS.md", "Projects/plan.md"). Use the exact letter case.
contentYesMarkdown content to insert. Must not begin with the target heading text (it would duplicate the heading, which is kept automatically).
headingNoTarget heading text (case-sensitive exact match). Omit for a file-level append or prepend.
operationYesappend | prepend | replace | insert_before.
heading_levelNoHeading level (1-6) for disambiguation when multiple headings share the same text
include_childrenNoWhen true, allows replace to overwrite a section that contains child headings. Without this, replace errors if children exist — preventing silent data loss.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and non-idempotent, but the description goes far beyond them: frontmatter preservation and YAML normalization to block style, no separator insertion around content, the data-loss risk of replace on sections with child headings, the no-heading prepend nesting trap, section-boundary semantics, empty-heading non-targetability, and a full error catalogue with recovery actions.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Purpose and when-to-use are front-loaded and the body is cleanly partitioned into Operations, Limitation, Section boundaries, Errors, Obsidian syntax, and Returns. It is long, and the 13-entry error list plus the table-row and Obsidian-syntax asides push past what most calls need, but nearly every line carries actionable information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive, non-idempotent mutation tool with no output schema, the description covers safety, failure modes, structural side effects, and the exact return string format. Nothing an agent needs to invoke it correctly or recover from errors is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds real meaning beyond the enum: per-operation targeting rules (which ops require a heading), how heading matching behaves, how heading_level disambiguates, and what include_children actually authorizes. It stops short of documenting path/content syntax further because the schema already does that.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Surgical edits to a markdown note') and enumerates the four operations up front. It explicitly distinguishes itself from siblings by naming vault_write_note, vault_replace_in_note, vault_create_task, and vault_update_task with the condition that selects each.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is an explicit 'When to use' line plus four named alternatives with the scenario each covers (new notes, full rewrites, in-place typo fixes, task creation/completion). Edge cases such as 'to start a new section above the first heading use insert_before, not a no-heading prepend' make the routing unambiguous.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_read_fileRead FileA
Read-onlyIdempotent

Read a non-markdown vault file in its most useful form per type — the read-side companion to vault_read_note for everything that isn't a note.

Example: vault_read_file({ path: "attachments/diagram.png" }) — the image itself, shrunk when too large Example: vault_read_file({ path: "Boards/Roadmap.canvas" }) — a readable outline of the canvas Example: vault_read_file({ path: "exports/data.json" }) — the file content as text Example: vault_read_file({ path: "exports/big.csv", limit: 500 }) — the first 500 lines, preceded by a metadata line stating the window and total line count Example: vault_read_file({ path: "papers/research.pdf" }) — structured text with title, headings, and links

What each file type returns:

  • Images (.png/.jpg/.jpeg/.gif/.webp): the image as a viewable image block — downscaled and recompressed server-side when it exceeds the image output budget (MAX_IMAGE_OUTPUT_BYTES, 49152 bytes) or 1568 pixels on its longer side, delivered untouched otherwise — plus a text line stating the path, delivered format/dimensions/bytes, and the original dimensions when shrunk. Animated GIFs are reduced to their first frame when recompressed.

  • Canvas (.canvas): a readable markdown outline per JSON Canvas 1.0 — groups (by visual containment), node content in reading order, and a connections list with edge labels.

  • PDFs (.pdf): structured text with document metadata — title, page count, heading hierarchy (from font sizes relative to the body text), code blocks and inline code (from monospace fonts), page separators, and a deduplicated links footer. Richer than flat text extraction: headings, code, and hyperlinks that flat extraction loses are preserved.

  • Text formats (.svg/.json/.txt/.csv/.xml/.log/.yaml/.yml/.base): the file content verbatim as text. .svg is returned as its XML source; .base as its YAML source.

raw: true switches a canvas or PDF to its other form:

  • Canvas: the exact JSON source (geometry, ids, colors — full fidelity) instead of the outline.

  • PDF: each page rendered and returned as an image block instead of extracted text, showing layout, diagrams, tables, and formatting that text extraction cannot preserve. Image-only and scanned PDFs work in raw mode. Only the first 5 pages are rendered; the text read (without raw) covers every page.

Line paging: start_line and limit page any text result — text formats, canvas outlines and raw JSON, PDF-extracted text — as a 1-based line window, preceded by a metadata line stating the window, the total line count, and where to continue ("data.csv — lines 51–100 of 400 (continue with start_line: 101)"). The text output cap (100 KiB) applies to each window, so one very long line can still overflow it; paging never gets around the file-size cap. Paged windows come back with \n line endings and no trailing newline; a read without paging inputs stays byte-exact.

When to use: whenever a note references a file you need to actually see or read — an embedded diagram, a linked canvas, data file, or PDF. Find the files a note links to (with byte sizes) via vault_get_outgoing_links; browse a folder's files via vault_list_files. vault_search also indexes canvas, PDF, and text-format content, but not images or other files. For .md notes use vault_read_note — this tool rejects them. To check a large file's line count before reading it whole, request start_line: 1 with limit: 1 — one line plus the total.

Errors:

  • "not a file" — the path ends in .md; read notes with vault_read_note

  • "file not found" — nothing exists at that path; discover valid paths via vault_list_files

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it (hidden files are not readable, matching Obsidian)

  • "file too large" — the file exceeds the file-size cap (MAX_FILE_BYTES, default 50 MiB)

  • "text output too large" — a text file, canvas, or PDF renders past the text output cap; page it with start_line and limit, or reduce limit when a single window overflows

  • "start line past the end" — start_line exceeds the file's line count; the error states the total, so retry with a smaller start_line

  • "line range is not available" (start_line or limit on an image, or on a PDF read with raw: true) / "raw source is not available for images" (raw on an image) — drop that input; paging applies only to text results, and an image always comes back as its image block

  • "not valid UTF-8" — the file's bytes aren't UTF-8 text; returning them would silently corrupt the content

  • "invalid .canvas JSON" — the canvas file is empty or not valid JSON, so no outline can be built; set raw: true to read its source as text

  • "PDF has no extractable text" — the PDF contains no text (scanned or image-only); the error states the page count. Set raw: true to render pages as images instead

  • "PDF page rendering failed" — raw: true was set but no pages could be rendered; the PDF may be corrupt

  • "image cannot be fitted" — the image could not be compressed under the image output budget

  • an image that cannot be decoded (corrupt, empty, or not an image despite its extension) fails with the decoder's message, e.g. "Input buffer contains unsupported image format"; replace or re-export the file

  • unsupported types (audio, archives, …) return an error naming the readable types plus the file's existence and size

Returns: for images, an image content block plus a one-line metadata text block; for PDFs with raw: true, a metadata text block followed by alternating image and text blocks (one pair per page); for every other supported type, a single text content block — preceded by a window-metadata text block when start_line or limit was given.

ParametersJSON Schema
NameRequiredDescriptionDefault
rawNoReturn the file's alternative form: JSON source for .canvas, page images for .pdf. Changes nothing for text formats, which already return their source. Rejected for images.
pathYesVault-relative path to the file, including its extension (e.g. "attachments/photo.png", "Boards/Roadmap.canvas"). Must NOT end in ".md" — notes are read with vault_read_note. Use the exact letter case.
limitNoMaximum lines returned (default: all remaining).
start_lineNoFirst line to return, 1-based (default 1).

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations cover the safety profile (read-only, idempotent, non-destructive), and the description layers on rich behavior: server-side downscaling thresholds (49152 bytes / 1568px), animated GIF first-frame reduction, the 5-page raw PDF render limit, per-window text caps, and byte-exactness of unpaged reads. This is well beyond what structured fields provide.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with examples, then a per-type return table, paging rules, usage, errors, and returns — logically ordered and each section scannable. However it is unusually long for a read tool, and the exhaustive error catalogue (13 entries) is closer to reference documentation than agent-facing guidance.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description fully compensates by enumerating return shapes per type (image block + metadata line, alternating image/text page pairs, single text block with optional window metadata). Combined with paging, error, and size-cap coverage, an agent has everything needed to call and interpret this tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so baseline is 3; the description adds genuine meaning on top — how start_line/limit produce a metadata prefix with window and total, the 'continue with start_line: 101' hint, and the trick of start_line:1 with limit:1 to probe line count. It slightly understates raw's rejection for images in the paging context, but coverage is strong.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('read a non-markdown vault file') and immediately positions itself as the read-side companion to vault_read_note, explicitly rejecting .md. The per-type return breakdown makes the scope unambiguous relative to siblings like vault_read_note and vault_list_files.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Has a dedicated 'When to use' section naming triggers (a note references a file you need to see), plus explicit alternatives: vault_get_outgoing_links to find linked files, vault_list_files to browse, vault_search for indexed content, vault_read_note for .md. It even states exclusions ('not images', 'this tool rejects them').

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_read_noteRead NoteA
Read-onlyIdempotent

Read a markdown note by its vault-relative path. By default returns the full raw content including properties; optional modes return just the properties, just the heading outline, or just one section — so large notes don't blow the token budget.

Example: vault_read_note({ path: "Projects/vault-cortex.md" }) Example: vault_read_note({ path: "Projects/vault-cortex.md", properties_only: true }) Example: vault_read_note({ path: "TASKS.md", outline: true }) Example: vault_read_note({ path: "TASKS.md", heading: "Active" }) Example: vault_read_note({ path: "TASKS.md", heading: "Done", heading_level: 2 }) // disambiguate when several "Done" headings exist Example: vault_read_note({ path: "TASKS.md", heading: "Done", start_line: 1, limit: 20 }) // first 20 lines of an oversized section

When to use: You know the exact path and need a specific note's content. For a large note (a long board or doc), use outline: true to see its headings and any text sitting above them, then heading: "..." to read just the one section you need — both far cheaper than pulling the whole file. Use properties_only: true when you only need properties. For an oversized note or section, page it with start_line and limit to read a window at a time. To check a note's or section's line count, request start_line: 1 with limit: 1 — one line plus the total. Prefer vault_search when you don't know the path. For task status or order on a board, prefer vault_list_tasks; heading mode returns a lane's verbatim Markdown. Prefer vault_get_memory for About Me/ files (returns content without properties). To edit a section you've read, use vault_patch_note. To explore what links to this note or what it links to, use vault_get_backlinks and vault_get_outgoing_links.

Section boundaries: a section spans from its heading to the next heading of the same or higher level (or EOF). Child headings are included. Modes are mutually exclusive — set at most one of properties_only, outline, or heading. Paged reads normalize line endings to LF; unpaged reads stay byte-identical.

Errors:

  • "note not found" — no note exists at this path; verify it with vault_list_notes

  • "heading not found" — no heading matches the text; error lists available headings

  • "ambiguous heading" — multiple headings match; use heading_level to disambiguate, or read the full note (omit heading) when headings share the same level

  • "outline, heading, and properties_only are mutually exclusive" — only one mode per call

  • "heading_level requires a heading" — heading_level only disambiguates a heading; pass heading with it

  • "heading cannot be empty" — heading is whitespace only; pass the heading's text

  • "line paging is not available in outline mode" / "... properties_only mode" — start_line/limit only work on text renditions (full read or heading section)

  • "start line past the end" — start_line exceeds the rendition's line count; error states the total

  • 'path must end in ".md"' — the path names a non-markdown file; read files (images, .canvas, data files) with vault_read_file instead

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

Returns: Raw markdown string (default); JSON object of properties (properties_only); JSON outline object, shaped as the outline parameter describes (outline); raw markdown of the section, heading line included (heading). When start_line or limit is given, the result is preceded by a window-metadata text block ("path — lines 1–20 of 250 (continue with start_line: 21)").

Outline: bytes at the root is the whole file's on-disk size and modified is its filesystem modification time; each heading's bytes is the exact UTF-8 byte length of the text that heading mode returns for that section. Empty headings ("##" with no text) appear with text: "" — they act as section boundaries but cannot be targeted by the heading parameter; read the parent section (which includes child headings) or the full note, and edit via vault_replace_in_note.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesVault-relative path to the note, including the ".md" extension (e.g. "About Me/Principles.md"). Use the exact letter case.
limitNoMaximum lines returned (default: all remaining).
headingNoReturn only this section. Case-sensitive exact match.
outlineNoIf true, returns { bytes, modified, leading_callout?, leading_content?, headings } as JSON instead of body content — a cheap structure fetch for large notes. headings: [{ level, text, bytes }]; leading_callout: { type, title, body } when the note has a top-of-file callout; leading_content: the rest of the body text above the first heading (callout lines excluded) when the note has any.
start_lineNoFirst line to return, 1-based (default 1). Pages the text output (full body or a heading section). Not valid for outline or properties_only (JSON modes).
heading_levelNoHeading level (1-6) for disambiguation when multiple headings share the same text; only applies with heading
properties_onlyNoIf true, returns parsed properties as JSON instead of full note content

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive, closed-world), and the description adds substantial non-obvious behavior: mode mutual exclusivity, LF normalization on paged reads vs byte-identical unpaged reads, section-boundary rules, security blocks on absolute/traversal/hidden paths, and a full error catalog. This is well beyond what the annotations convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose then examples, and nearly every sentence earns its place given seven interacting parameters. Slightly long: the Returns and Outline paragraphs restate shape details already present in the schema descriptions, and the six examples are more than strictly needed.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the full return-value burden and does so: raw markdown default, JSON for properties_only and outline, section markdown with heading line included, and the window-metadata prefix on paged reads. Error recovery paths are also covered, so nothing needed to call this correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% (baseline 3), but the description adds semantics the schema cannot express: properties_only/outline/heading are mutually exclusive, heading_level only applies with heading and exists to disambiguate same-text headings, start_line/limit are invalid in JSON modes, and the 'start_line: 1, limit: 1' trick to obtain line counts.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource (read a markdown note) scoped by vault-relative path, and immediately distinguishes itself from vault_read_file via the '.md' requirement and from vault_search via 'you know the exact path'. An agent can tell it apart from every sibling without opening a schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit routing: vault_search when the path is unknown, vault_list_tasks for task status/order, vault_get_memory for About Me files, vault_patch_note to edit, vault_get_backlinks/vault_get_outgoing_links for link exploration. It also gives mode-selection guidance (outline first, then heading; properties_only when only properties are needed) and paging advice for oversized notes.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_recent_notesRecent NotesA
Read-onlyIdempotent

List recently modified or created notes, sorted by timestamp — a time-ordered window into the vault, not a date-range filter.

Example: vault_recent_notes({ sort_by: "modified", limit: 10 }) Example: vault_recent_notes({ sort_by: "created", limit: 5 })

When to use: Catching up on vault changes, finding recent work, or orienting after a break. Prefer vault_search for content-based discovery. Prefer vault_search_by_folder for browsing a specific folder.

Parameters:

  • sort_by + limit interact: "modified" (default) uses filesystem mtime, so every note has a value and limit works predictably. "created" uses the frontmatter created property — notes without it sort last (not excluded), so a small limit may return only notes that have the property; increase limit or use "modified" for broader coverage.

  • "modified" includes any file write (content edits, property changes, sync touches), so recently-synced notes appear recent even without user edits.

Errors:

  • An empty vault returns an empty array, not an error.

Returns: JSON array of note metadata (path, title, tags, related, folder, type, created, modified, bytes, leading_callout?, additional_properties), sorted descending by chosen timestamp. created is null when the property is missing; bytes is on-disk file size.

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMax results (default 20, no upper cap)
sort_byNoSort order (default "modified")modified

TDQS

A5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already mark this read-only and idempotent, and the description adds valuable behavior beyond that: 'created' sorts notes without the property last rather than excluding them, 'modified' catches sync touches and property changes, and an empty vault returns an empty array. These behavioral details will help an agent predict results accurately.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is organized into clear sections: overview, examples, when to use, parameter interactions, errors, and return format. It is longer than a one-liner, but every sentence adds needed operational context, and the core purpose is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite having no output schema, the description fully documents the return shape: JSON array of note metadata with field names and nullability. It also covers empty-vault behavior and parameter edge cases, so an agent has enough information to call and interpret the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Although the input schema already covers parameter names and defaults, the description explains how sort_by and limit interact, including the pitfall that a small limit with sort_by 'created' may return only notes that have the property. This adds important meaning beyond the schema's minimal descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource: 'List recently modified or created notes, sorted by timestamp.' It also distinguishes itself from a date-range filter and shows examples, making the tool's purpose unambiguous and distinct from sibling search tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description includes a dedicated 'When to use' section and explicitly names alternatives: 'Prefer vault_search for content-based discovery. Prefer vault_search_by_folder for browsing a specific folder.' This gives clear routing guidance and conditions for choosing this tool versus siblings.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_replace_in_noteReplace in NoteA
Destructive

Find and replace text in a markdown note's body. Matches exact text (case-sensitive). Properties are preserved; YAML formatting may be normalized to block style on first edit. Operates on the body only — properties must be edited via vault_update_properties or vault_write_note's properties parameter.

Example: vault_replace_in_note({ path: "Projects/plan.md", old_text: "TODO: write summary", new_text: "Summary complete." }) Example: vault_replace_in_note({ path: "Projects/plan.md", old_text: "- [ ] draft outline\n", new_text: "" }) — removes the whole line, line break included.

When to use: Targeted text changes within a single location — fixing typos, updating values, renaming terms, or removing a short line (new_text=""). Replaces text in place; does not move content across sections. To delete a large multi-line block, prefer vault_delete_span (short anchors instead of full old_text). To replace a large block by anchors instead of reproducing the full old_text, use vault_replace_span. To relocate content between headings, use vault_patch_note to add at the target first, then remove from source (new_text="") — add-before-delete, so a failure duplicates the block instead of losing it.

Parameters:

  • old_text: include enough surrounding context to ensure uniqueness when the target text appears in multiple places. No regex.

  • new_text: non-empty new_text replaces the match exactly. A deletion (new_text="") that leaves an empty line where the match was joins the empty lines above and below it into one gap that keeps the larger of the two counts (only at the end of the note, the count above drops by one); where matches empty their lines, the gap keeps at least one empty line unless it ends the note, so include the line break in old_text to remove the line. Any other deletion, such as text inside a line or a line break that joins two lines, is written exactly as asked. Empty lines outside the joined gaps never change. A line holding only spaces or tabs counts as text, not as an empty line.

  • replace_all_occurrences: replacing only the first match is a safety default for when old_text appears in multiple places. Set true for deliberate bulk renames or term replacements.

Errors:

  • "note not found" — path does not exist; check vault_list_notes for valid paths

  • "path must end in …" — add the .md extension

  • "text not found" — old_text does not appear in the note body; verify exact text with vault_read_note

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "concurrent write in progress" — another write to this note is in flight; re-read the note and retry

  • "new_text contains a control character" — new_text includes a non-printable control byte; remove it before writing

Obsidian syntax: new_text is Obsidian Flavored Markdown (no escaping applied). Watch for: #word = tag, [[ = wikilink, %% = comment block in replacement text.

Returns: Confirmation message with replacement count (number of occurrences replaced).

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesVault-relative path to the note, including the ".md" extension (e.g. "Projects/plan.md"). Use the exact letter case.
new_textYesReplacement text. Empty string ("") deletes the matched text.
old_textYesExact text to find (case-sensitive). Matches in the body only — text inside frontmatter properties is not searched.
replace_all_occurrencesNoReplace all occurrences (default: false — replaces first occurrence only)

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already flag destructiveHint=true and idempotentHint=false, but the description adds substantial context beyond them: properties are preserved, YAML may be normalized to block style, edits are body-only, replace_all defaults to first-match for safety, and a full error catalogue (concurrent writes, blocked paths, control characters) is enumerated.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose, then examples, when-to-use, parameters, errors — a logical order. However, the paragraph explaining empty-line joining on deletion is dense and hard to parse, and could be tightened given how narrow the case is.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive, non-idempotent mutation tool with no output schema, the definition covers scope boundaries, side effects, safety defaults, error recovery paths, and the return value (confirmation with replacement count). Nothing an agent needs to call it safely is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% (baseline 3), yet the description adds real meaning: old_text requires enough context for uniqueness and is not regex; new_text is Obsidian Flavored Markdown with no escaping, with tag/wikilink/comment caveats; and the long empty-line deletion semantics and replace_all rationale go well beyond the schema's one-line defaults.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Find and replace text in a markdown note's body') and immediately scopes it (body only, not properties). It explicitly distinguishes itself from vault_replace_span, vault_delete_span, and vault_patch_note, so an agent can route without opening schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides an explicit 'When to use' section with concrete scenarios (typos, renaming, deleting a short line) and names three alternatives with the precise conditions that select each (large multi-line block → vault_delete_span; anchor-based block replace → vault_replace_span; relocation between headings → vault_patch_note).

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_replace_spanReplace SpanA
Destructive

Replace a contiguous block of whole lines in a note's body with new content, identified by short anchor substrings instead of the block's full text. Each anchor locates a full line — the entire line is selected, not just the matching substring. Case-sensitive matching. Properties are preserved; YAML formatting may be normalized to block style on first edit. Operates on the body only.

Example: vault_replace_span({ path: "Tracker.md", start_anchor: "| 2024-03-02 | Acme", content: "| 2024-03-02 | Acme Corp | Updated |" }) — replaces the one table row whose line contains that fragment. Example: vault_replace_span({ path: "Notes/Plan.md", start_anchor: "> [!warning] Stale", end_anchor: "remove after launch", content: "> [!info] Current\n> Updated for v2." }) — replaces the callout block with a new one.

When to use: Replacing a block you have already read — a table row, callout, or run of list items — where reproducing it exactly as old_text would be error-prone. Pick a short, unique fragment of the first line for start_anchor and, for a multi-line block, the last line for end_anchor. Prefer vault_replace_in_note for small in-place text changes (typos, renaming). Prefer vault_delete_span when removing without replacement.

Parameters:

  • end_anchor is searched at or after the start line, so the span can never run backward; it must be unique among those lines. If both match the same line, only that one line is replaced.

  • content: empty lines at its start and end join the empty lines around the replaced lines, and each joined gap keeps the larger of the two counts (only at the end of the note, the count above drops by one). So content can widen a gap but not narrow it: a trailing newline leaves at least one empty line after the new block unless the block ends the note. Content made only of empty lines joins both sides into one gap. Empty lines inside content are written as given, and no other empty line in the note changes. A line holding only spaces or tabs counts as text, not as an empty line.

  • first_match applies to both anchors independently.

Errors:

  • "note not found" — verify path with vault_list_notes

  • "path must end in …" — add the .md extension

  • "start anchor not found" / "end anchor not found" — no line contains the fragment (for end_anchor, none at or after the start line); verify with vault_read_note

  • "ambiguous start anchor …" / "ambiguous end anchor …" — the anchor matches multiple lines; use a longer fragment or set first_match: true

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "concurrent write in progress" — another write to this note is in flight; re-read the note and retry

  • "content contains a control character" — content includes a non-printable control byte; remove it before writing

Obsidian syntax: content is Obsidian Flavored Markdown (no escaping applied). Watch for: #word = tag, [[ = wikilink, %% = comment block.

Returns: Confirmation message "Replaced lines with lines in " — N counts the lines the span covered, M the line breaks in content plus one.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesVault-relative path to the note, including the ".md" extension (e.g. "Tracker.md", "Notes/Plan.md"). Use the exact letter case.
contentYesReplacement content (one or more lines) — replaces every line of the matched span. Must be non-empty.
end_anchorNoShort substring that identifies the LAST line of the block. The entire line is selected. Omit to replace just the single line containing start_anchor.
first_matchNoIf an anchor matches more than one line, use the first match instead of erroring (default: false — ambiguity is an error).
start_anchorYesShort, unique substring that identifies the first line of the block (case-sensitive). The entire line is selected, not just the substring. Pick a brief fragment — do not paste the whole block.

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only declare destructiveHint/readOnlyHint/idempotentHint; the description goes far beyond by disclosing whole-line selection semantics, case sensitivity, property preservation, YAML normalization to block style, body-only scope, and concurrency behavior ('concurrent write in progress'). It even documents the full error surface and Obsidian syntax pitfalls, none of which structured fields convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Well front-loaded (purpose, examples, when-to-use, parameters, errors, returns) with clear section labels, and the length is largely justified by the operation's complexity. However, the empty-line joining rules are convoluted and slightly redundant with the Returns section, so it is not maximally tight.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive 5-parameter tool with no output schema, the description covers everything needed: return format with N/M semantics, the complete error catalog with remediation, and Obsidian syntax hazards. Nothing an agent needs to invoke it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% (baseline 3), but the description adds genuinely new semantics: end_anchor is searched at or after the start line so spans cannot run backward, first_match applies to both anchors independently, and content empty-line behavior is spelled out in detail. This meaningfully exceeds the schema's own parameter text.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The first sentence names a specific verb and resource ('Replace a contiguous block of whole lines in a note's body') and immediately states the distinguishing mechanism (anchor substrings rather than full text). It explicitly contrasts with vault_replace_in_note and vault_delete_span, so an agent can select it without opening sibling schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

A dedicated 'When to use' paragraph describes the exact scenario (a block already read, where reproducing old_text would be error-prone) and names two alternatives with their selecting conditions. It also gives practical anchor-selection guidance (short unique fragment of first line, last line for end_anchor).

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_search_by_folderSearch by FolderA
Read-onlyIdempotent

Browse notes in a folder with full metadata (tags, type, related, created, modified) — unlike vault_list_notes, which returns paths only.

Example: vault_search_by_folder({ folder: "Projects" }) or vault_search_by_folder({ folder: "About Me", recursive: false })

When to use: Exploring a folder's contents with full context for vault orientation. Prefer vault_list_notes when you only need paths. Prefer vault_search when you have a text query. Use vault_get_backlinks or vault_get_outgoing_links to explore how notes in a folder connect to the rest of the vault.

Parameters:

  • folder names a whole folder, not a text prefix: "Projects" matches notes under "Projects/" but not "ProjectsOld/". Matching ignores ASCII letter case, and a trailing slash is ignored.

  • limit applies after sorting, so you get the most recently modified notes. Nothing in the response signals truncation: exactly limit results may mean more exist, so raise limit to check.

Behavior: Reads the search index, which picks up a file change within a few seconds, so a note written moments ago may not appear yet. Notes in hidden (dot-prefixed) folders are never indexed, so never appear.

Errors:

  • An empty or nonexistent folder returns an empty array, not an error.

Returns: JSON array of note metadata sorted by most recently modified, then by path: path, title, tags, related, folder, type, created (frontmatter; null when missing), modified (file time), bytes (on-disk size), plus, when present, leading_callout (the note's opening callout, { type, title, body }) and additional_properties (other frontmatter keys).

ParametersJSON Schema
NameRequiredDescriptionDefault
limitNoMax results (default 20)
folderYesFolder path (e.g. "Projects", "About Me")
recursiveNoInclude subfolders (default: true); false lists only the folder's top level

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the readOnly/idempotent annotations, it discloses index lag ('a few seconds'), that hidden dot-folders are never indexed, that truncation is not signaled ('exactly limit results may mean more exist'), result sort order, and that a nonexistent folder returns an empty array rather than an error. This is rich, non-obvious behavioral context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose, then a contrast, then when-to-use, parameters, behavior, errors, and returns — a clean scaffold. It is longer than strictly minimal, and the Returns field list is dense, but nearly every sentence carries information an agent needs.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description fully covers the return shape (fields, sort order, nullable created, conditional leading_callout/additional_properties), error behavior, and freshness caveats. Nothing needed to call or interpret the tool is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is already 100%, but the description adds real semantics: folder matches a whole folder not a prefix ('Projects' not 'ProjectsOld/'), case-insensitive ASCII matching, trailing slash ignored, and that limit applies after sorting with no truncation indicator. These are behaviors the schema cannot express.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (browse/search) and resource (notes in a folder) with scope, and explicitly contrasts with vault_list_notes which 'returns paths only.' An agent can distinguish it from siblings without opening a schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides explicit when-to-use guidance ('Exploring a folder's contents with full context') plus named alternatives: vault_list_notes for paths, vault_search for text queries, and the backlink/outgoing-link tools for graph traversal. Routing is unambiguous.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_search_by_propertySearch by PropertyA
Read-onlyIdempotent

Find notes where a frontmatter property matches a value — metadata-only search, no text query needed. Handles both scalar properties (status: "active") and array properties (tags, related): for arrays, matches if any element equals the value (contains check, not exact array match).

Example: vault_search_by_property({ key: "status", value: "in-progress" }) Example: vault_search_by_property({ key: "type", value: "session-log", folder: "Code Projects" })

When to use: Finding notes by metadata when you don't have a text query. Prefer vault_search when you also have a text query (it supports property filters too). Prefer vault_search_by_tag for tag-specific queries (supports hierarchical prefix matching). Use vault_list_property_keys to discover valid keys and vault_list_property_values to see what values a key takes.

Parameters:

  • key is exact and case-sensitive. Text values match exactly and case-sensitively, with no partial matching or globbing. Stored numbers also match numerically: "04" and "4.0" match number 4 and their own literal text, but not text "4".

  • Numeric matching accepts complete finite YAML core numeric forms: signed decimals, leading-zero decimals, .5, 4., exponents, 0x hexadecimal and 0o octal. Whitespace, final line breaks, prefixes like "4abc", comments, expressions, 0b binary, separators, non-finite values and overflow match only literal text.

  • Numeric equality uses stored number precision: large integers can round to the same value, and underflow such as "1e-999" matches stored zero.

  • Pass a checkbox as "1" or "0" (true is stored as 1, false as 0); "1.0" does not match a checked checkbox.

  • An array element must equal value in full: "blog" matches tags: ["blog", "draft"] but not tags: ["my-blog"].

  • folder names a whole folder and includes its subfolders: "Projects" covers "Projects/Archive" but not "ProjectsOld/". Matching ignores ASCII letter case; omit folder to search the entire vault.

  • limit applies after sorting. Nothing in the response signals truncation: exactly limit results may mean more exist, so raise limit to check.

Errors:

  • An unknown key or unmatched value returns an empty array, not an error.

Returns: JSON array of note metadata (path, title, tags, related, folder, type, created, modified, bytes, leading_callout?, additional_properties), sorted by filesystem mtime descending — recently-synced notes may sort ahead of older content edits.

  • leading_callout appears only when the note has a leading callout.

  • additional_properties appears only when frontmatter has keys outside title, tags, type, created, and related.

ParametersJSON Schema
NameRequiredDescriptionDefault
keyYesProperty key name (e.g. "status", "type", "tags"). Use vault_list_property_keys to discover valid keys.
limitNoMax results (default 20)
valueYesValue to match (e.g. "active", "4", "1e-7"). Use vault_list_property_values to discover valid values for a key.
folderNoRestrict to a folder (e.g. "Projects")

TDQS

A4.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive), so the bar is lower. The description adds substantial non-obvious behavior: exact/case-sensitive matching, numeric coercion rules, checkbox '1'/'0' encoding, subfolder inclusion, silent truncation when limit is hit, and that an unknown key returns an empty array rather than an error. This is well above what annotations provide.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Well front-loaded with purpose, examples, routing, then parameter detail. The numeric-matching paragraph is dense and covers edge cases beyond what most callers need, but the sectioning keeps it navigable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, yet the description fully specifies the return shape (metadata fields, optional leading_callout/additional_properties, sort order) and the truncation caveat. Nothing an agent needs to call or interpret results correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so baseline is 3. The 'Parameters' block does add meaning beyond the schema (case-sensitivity, numeric/checkbox forms, folder covering subfolders, limit applied post-sort), but much of it restates or elaborates fields the schema already names.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Find notes where a frontmatter property matches a value') and immediately scopes it as metadata-only with no text query. It clarifies the scalar-vs-array matching behavior, which is the key behavioral distinction from sibling search tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit 'When to use' section, plus named alternatives with selection conditions: prefer vault_search with a text query, prefer vault_search_by_tag for hierarchical tag matching, and use vault_list_property_keys/values for discovery. Routing is unambiguous.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_search_by_tagSearch by TagA
Read-onlyIdempotent

Find notes with a specific tag. By default uses hierarchical prefix matching — a parent tag matches all children (e.g. "project" matches "project/vault-cortex", "project/blog"). Set exact=true for exact match only.

Example: vault_search_by_tag({ tag: "project" })

When to use: Tag-only lookups, for one tag or a whole tag hierarchy, with no text query. Prefer vault_search when you also need text-based relevance ranking. Use vault_list_tags first to discover available tags.

Parameters:

  • tag + exact interact: the prefix match follows the "/" separator, so "project" matches itself and its children but does NOT match "my-project" or "projects". exact=true matches only the literal tag, excluding children.

Errors:

  • An unknown tag or no matches returns an empty array, not an error — don't use as an existence check.

Returns: JSON array of note metadata (path, title, tags, related, folder, type, created, modified, bytes, leading_callout?, additional_properties?), sorted by most recently modified and capped at 20, with no truncation signal: exactly 20 results may mean more exist. bytes is the on-disk file size. Promoted keys are in top-level fields; additional_properties contains only unpromoted keys.

ParametersJSON Schema
NameRequiredDescriptionDefault
tagYesTag name without "#" prefix (e.g. "project", "session-log"). Hierarchical tags use "/" separators (e.g. "project/vault-cortex").
exactNoExact match only (default: false, prefix match)

TDQS

A4.7/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover readOnly/idempotent/non-destructive, yet the description adds genuinely new behavior: an unknown tag or no match returns an empty array rather than an error and should not be used as an existence check, plus a result cap of 20 with no truncation signal so exactly 20 may mean more. That cap/truncation caveat is important and is not expressible in the annotations. Minor gap: no pagination/offset guidance for retrieving past the cap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the one-line purpose, then labeled blocks (Example, When to use, Parameters, Errors, Returns) that make scanning cheap. The Returns block is dense but earns its length because there is no output schema; the Parameters block repeats a little of what the schema already states.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description supplies the full return contract (field list, promoted vs additional_properties keys, sort order, cap of 20), plus error semantics and the exact-vs-prefix interaction. Nothing an agent needs to call this correctly or interpret results is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, but the description still adds meaning beyond it: the prefix match follows the '/' separator, so 'project' matches its children but NOT 'my-project' or 'projects', and exact=true excludes children entirely. Those boundary/negative examples are the exact failure modes an agent would hit and are absent from the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with a specific verb+resource ('Find notes with a specific tag') and immediately scopes the tool's distinct capability (hierarchical prefix matching on a tag, with an exact override). The 'When to use' block explicitly separates it from vault_search (text relevance) and vault_list_tags (tag discovery), so an agent can route without opening sibling schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

States the selection condition plainly ('Tag-only lookups ... with no text query'), names the alternative to prefer when text ranking is needed, and gives a prerequisite step ('Use vault_list_tags first to discover available tags'). Exclusions and alternatives are both explicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_update_memoryUpdate MemoryA
Idempotent

Append a dated entry to a section of a memory file in About Me/. The server prefixes the date automatically ("- YYYY-MM-DD: entry text") and inserts newest-first by default. Idempotent — an exact duplicate (same date + text in the same section) is a no-op, so retrying a timed-out call is safe. Memory files are append-only by default: when a preference changes, append the new state (newest wins) rather than deleting the old one. A file may declare entry-policy: living in frontmatter (surfaced by vault_list_memory_files) — a current-state file where pruning expired entries is expected maintenance rather than a violation.

Example: vault_update_memory({ file: "Opinions", section: "Code patterns (newest first)", entry: "Prefer immutable data structures" })

When to use: Recording a new preference, principle, opinion, or fact about the user. Call vault_list_memory_files first and reuse existing file and section names so entries stay grouped. Prefer vault_write_note for creating non-memory notes. A missing file or section is created automatically (new sections get "(newest first)" appended; new files get a placeholder scope callout to fill in via vault_replace_in_note). A new section name nearly identical to an existing heading (an HTML-entity slip, typo, or spacing variation) is rejected, so a mistyped name cannot silently fragment the file — names differing only in digits (e.g. "2025" vs "2026") are distinct.

Parameters:

  • options.position — "top" (default, newest-first) inserts above existing entries; "bottom" appends below them.

Obsidian syntax: Entry text is Obsidian Flavored Markdown. Watch for: #word = tag, [[ = wikilink. Escape with # or backticks when unintentional.

Errors:

  • "refusing memory write: … would shrink content" — safety guard: the write would leave the file at under half its size, which happens when the file holds content a rewrite cannot keep (for example long YAML comments in its properties). A retry returns the same refusal until a manual edit removes that content; inspect the file with vault_read_note to find it.

  • "entry must be a single line" — memory entries are single dated bullets; collapse newlines or append multiple entries.

  • "section must be a single line" — section names become H2 headings; remove line breaks.

  • "date must be a real ISO calendar date" — options.date only accepts an existing calendar date in bare YYYY-MM-DD form (e.g. "2026-07-02"), not a timestamp.

  • "entry contains a control character" / "section contains a control character" — the value includes a non-printable control byte; remove it before writing.

  • "memory file must not start with a dot" / "memory file must be a bare name without path separators" — use a bare file name: no folder or slash, and no leading dot (that would create a hidden file, invisible in Obsidian and to every listing).

  • "section not created: … is nearly identical to existing section …" — near-duplicate guard; pass the exact existing heading (listed in the error) to append there, or choose a clearly different name for a genuinely new section.

Returns: Confirmation message (notes when an identical entry already existed and nothing was written).

ParametersJSON Schema
NameRequiredDescriptionDefault
fileYesMemory file name without .md (e.g. "Principles"). Use the exact letter case; a different case can create a second file.
entryYesRaw entry text — a single line (newlines are rejected); the server prepends "- **YYYY-MM-DD**: " automatically. Do not include the date or bullet prefix.
optionsNoOptional date and position overrides
sectionYesH2 section heading (e.g. "Decision heuristics (newest first)"). Matched case-insensitively, with or without the "(newest first)" suffix.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only declare idempotentHint/destructiveHint/readOnlyHint, but the description adds substantial behavioral context: automatic date prefixing, newest-first insertion, append-only policy with the entry-policy: living exception, auto-creation of missing files/sections, the near-duplicate heading guard, and the shrink-guard refusal behavior. This far exceeds what the annotations convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action and behavior, then organized into example, when-to-use, parameters, syntax, errors, and returns. Every section earns its place, though the extensive error catalog makes it long; the density is justified by the tool's complexity but is near the upper bound of acceptable size.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite having no output schema, the description explicitly covers the return value ('Confirmation message... notes when an identical entry already existed'), plus edge cases (auto-creation, near-duplicate guard, shrink refusal). Nothing an agent needs to invoke this correctly or interpret failures is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, and the description modestly exceeds it by tying parameter constraints to concrete error conditions (single-line entry/section, bare YYYY-MM-DD date, bare file name with no dot or slash). It adds operational meaning beyond the schema field descriptions rather than merely restating them.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a precise verb and resource: 'Append a dated entry to a section of a memory file in About Me/.' It explicitly differentiates from siblings by naming vault_write_note for non-memory notes and vault_list_memory_files for discovery, so an agent can route correctly without opening either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides an explicit 'When to use' clause (recording a preference, principle, opinion, or fact about the user) plus a prerequisite workflow ('Call vault_list_memory_files first and reuse existing file and section names'). It also names the alternative for a different case ('Prefer vault_write_note for creating non-memory notes').

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_update_propertiesUpdate PropertiesA
DestructiveIdempotent

Update a note's frontmatter properties via shallow merge — new keys added, matching keys overwritten, null deletes a key, unmentioned keys preserved. Body is never modified.

Example: vault_update_properties({ path: "Projects/todo.md", properties: { status: "active", draft: null } })

When to use: Changing tags, status, type, or any property without reading/rewriting the full note body. Prefer vault_write_note when creating a new note, or replacing the body (with overwrite: true). Read current properties first with vault_read_note({ properties_only: true }) — arrays are replaced entirely, not appended to.

Errors:

  • "note not found" — path does not exist; create the note first with vault_write_note

  • "path must end in …" — add the .md extension

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "concurrent write in progress" — another write to this note is in flight; re-read the note and retry

Obsidian syntax: Use arrays for multi-value fields (tags: [a, b]), quote wikilinks ("[[Note]]"), keep types consistent (mismatches cause silent query failures).

Returns: Confirmation message.

ParametersJSON Schema
NameRequiredDescriptionDefault
pathYesVault-relative path to the note, including the ".md" extension. Use the exact letter case.
propertiesYesProperties to merge; a null value deletes that key.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare the write/destructive/idempotent profile, and the description adds substantial non-redundant behavior: shallow-merge semantics, null-deletes-a-key, unmentioned keys preserved, body untouched, and a full error catalog including concurrency retry guidance. The null-delete behavior is exactly the kind of detail annotations cannot express, and it is consistent with destructiveHint=true.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the merge contract, then example, when-to-use, errors, syntax notes, return value — a well-labeled structure where each block earns its place. It is on the longer side, and the Obsidian syntax paragraph is slightly tangential to tool selection, but nothing is padding.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, so the 'Returns: Confirmation message.' line covers the return contract, and the error list, merge semantics, and format caveats cover the rest of what an agent needs. For a 2-param nested-object mutation tool, this is complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, and the description genuinely adds meaning on top: a concrete call example, the rule that arrays are replaced entirely rather than appended, and Obsidian type/quoting conventions for wikilinks and multi-value fields. Only the 'exact letter case' nuance of the path param is left to the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Update a note's frontmatter properties via shallow merge') and immediately scopes the operation: body is never modified. This cleanly separates it from siblings like vault_write_note, vault_patch_note, and vault_replace_in_note.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit 'When to use' clause plus an explicit alternative ('Prefer vault_write_note when creating a new note, or replacing the body with overwrite: true') and a prerequisite step pointing at vault_read_note({ properties_only: true }). Both the when and the when-not are named.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_update_taskUpdate TaskA
Destructive

Update a task's status, priority, description, dates, dependencies, block_id, checklist items, or heading placement in one call. Any combination of these can change together — every field passed is written in a single edit.

Example: vault_update_task({ path: "TASKS.md", block_id: "my-task", status: "done" }) — complete a task; on a Kanban board, auto-moves to the done lane; a recurring task (🔁) spawns its next occurrence Example: vault_update_task({ path: "TASKS.md", block_id: "my-task", recurrence: "every week" }) — make a task recurring (null removes the rule) Example: vault_update_task({ path: "TASKS.md", block_id: "my-task", heading: "Done" }) — move a task to a different heading (lands at the top of the lane by default) Example: vault_update_task({ path: "TASKS.md", block_id: "my-task", description: "Updated task name", due: "2026-10-01", scheduled: null }) — change the description, set one date, and clear another Example: vault_update_task({ path: "TASKS.md", block_id: "my-task", status: "in_progress", add_subtasks: ["Design", "Implement", "Test"] }) — start working and add checklist stages Example: vault_update_task({ path: "TASKS.md", line: 42, assign_block_id: "my-task" }) — add a block_id to a task that lacks one Example: vault_update_task({ path: "TASKS.md", block_id: "my-task", heading: "Active", position: 3 }) — move to the 3rd position in a lane

When to use: Any change to an existing task — completing, starting, re-prioritizing, editing text, setting or clearing dates, adding checklist items, assigning block_ids, moving between headings, or reordering within a lane. Use vault_list_tasks first to get identification fields (path + block_id or line). For creating a new task, use vault_create_task instead.

Parameters:

  • Exactly one of block_id or line is required to identify the task.

  • At least one change is required. Clearing is always explicit null — omitting a field leaves it untouched.

  • status manages the checkbox and the done/cancelled dates. Kanban: "done" moves the card and its checklist sub-items to the done lane (sub-item checkboxes left as they are); a sub-task stays under its parent. Recurring (🔁): spawns the next occurrence above the completed one (below with the plugin's "next line" setting), dates advanced per the rule. The spawn stays in the source lane with no block_id, 🆔, or ⛔ — follow up with assign_block_id on next_occurrence.line. Completing by line is NOT idempotent for recurring tasks (the spawn occupies the old line); prefer block_id. Delete (🏁 delete / [onCompletion:: delete]): removes the task line and children instead of moving to done. With 🔁 + 🏁, the spawn is created first, then the completed line is removed; with "next line", children transfer to the spawn. Result carries on_completion_applied: "delete".

  • recurrence: a rule ending "when done" bases the next occurrence on the completion day. When set together with status "done", the new rule governs the spawn. Setting recurrence to null while completing removes the rule and completes without spawning.

  • on_completion: passed together with status, the submitted value governs the delete decision — "keep" while completing a "delete" task prevents the deletion.

  • position: applies to a heading move or an auto-done-lane move. Without a heading, it triggers a same-lane reorder to the given position; omitting position performs no reorder. Ignored when the task is deleted on completion. Not valid on sub-tasks.

Errors:

  • "note not found" — path does not exist

  • "path must end in …" — add the .md extension

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "exactly one of blockId or line is required" / "blockId and line are mutually exclusive" — pass exactly one of block_id or line

  • "blockId ... not found" — no task line in the note ends with ^block_id

  • "blockId ... is inside a fenced code block or comment" — the block_id matches a line inside a fenced code block or %% %% comment; target a line outside the fence

  • "no task at line N" — line doesn't contain a task checkbox

  • "line N is inside a fenced code block or comment" — the line is inside a fenced code block or %% %% comment; target a line outside the fence

  • "checkbox "[c]" is a NON_TASK status" — the task's checkbox char is typed NON_TASK in the Tasks plugin's status registry, so it is not a task; to change that, retype it there and restart the server

  • "no checkbox symbol for status ..." — the status registry has no symbol for the target status and the built-in default is retyped; update the plugin's status registry to include a symbol for this status, then restart the server

  • "at least one mutation" — no change params provided

  • "cannot move a sub-task to a heading" — explicit heading on a task nested under another task (depth > 0 in vault_list_tasks)

  • "cannot reposition a sub-task" — explicit position on a sub-task (sub-tasks move with their parent)

  • "cannot reorder a task that sits above the first heading" — position without a heading on a task before the first section heading

  • "cannot reorder within "X" — the heading appears N times" — same-lane reorder on a card whose heading name is duplicated in the note; rename one section to make it unique

  • "cannot place at position N under "X" — the heading appears N times" — cross-lane move with an integer position to a heading name that appears more than once; rename one section to make it unique

  • "heading "X" not found; available: ..." — target heading doesn't exist; the error lists the note's headings

  • "multiple done lanes detected" — status "done" on a Kanban board with more than one Complete-marked lane; pass heading to pick the lane

  • "no done lane detected" — status "done" on a Kanban board with no Complete marker and no "Done" heading; pass heading explicitly

  • "blockId ... already exists" / "blockId ... contains invalid characters" — assign_block_id must be unique in the note and match [a-zA-Z0-9-]+

  • "invalid date" — a date param fails calendar validation

  • "description cannot be empty" / "addSubtasks cannot contain an empty item" — whitespace-only description or checklist item

  • "description must be a single line" / "addSubtasks items must be a single line" — a task is one file line; a line break in the text would split its metadata onto a line the parser never reads

  • "taskId ... contains invalid characters" / "dependsOn entry ... contains invalid characters" — task_id and every depends_on entry must match [a-zA-Z0-9_-]+ (the Tasks plugin's id grammar)

  • "unrecognized recurrence rule ..." — the rule text is not Tasks-plugin natural language; written as-is it would silently never recur

  • "concurrent write in progress" — another write to this note is in flight; retry

Obsidian syntax: The Tasks plugin reads metadata off the END of a task line. A trailing signifier in description or add_subtasks text (an emoji field like "🔁 every week", or a Dataview [key:: value] field) that the plugin's parser recognizes as a field — followed only by other recognized fields — is read back as metadata, not text. Whether it is captured depends on the field's value grammar: 🔁 reads any trailing words as its recurrence rule, while 📅 followed by non-date words stays description text. The same interference can change the value an adjacent field reads back with, or make a field appear that was never set. The write still succeeds either way; when the stored line would read back differently than this call set, the result carries an advisories array naming each divergence. The dates a status change stamps or clears (the ✅/❌ dates) produce no advisories on their own — but a description signifier that changes what the stamped date parses back as is still reported.

Returns: JSON { path, line, description, block_id, heading, subtasks, next_occurrence, changes, advisories, on_completion_applied } — line is the final 1-based position (when on_completion_applied is "delete", it is the position the task occupied before removal); description is the current text; block_id and heading reflect the task after the update (block_id is omitted when the task has none, heading when the task sits above the first heading); subtasks lists each checklist item added by add_subtasks as { line, description } (omitted when none were added) — checklist items carry no block_id, so line is the handle for a follow-up update; next_occurrence is present only when a completion spawned a recurring task's next occurrence: { line, description, due?, scheduled?, start? } with only the dates the occurrence has — it carries no block_id, so line is its handle; changes lists every field applied as "field: before → after", with "(none)" for an absent value (for subtasks the two sides are checklist-item counts, and a spawn adds "next_occurrence: (none) → line N"); advisories (omitted when there are none) lists one sentence for each: a stored line that parses back differently than submitted (see Obsidian syntax above), a duplicate tag removed from the line, or a completed recurring task whose rule yields no next occurrence (unreadable rule text or a rule with no dates left); on_completion_applied (present only when the effective on_completion was delete — pre-existing on the task or set in the same call — and it was transitioned to done) is always "delete".

ParametersJSON Schema
NameRequiredDescriptionDefault
dueNoDue date (YYYY-MM-DD) to set, or null to clear.
lineNo1-based line number from vault_list_tasks. Fragile if the file changed since the query.
pathYesVault-relative path to the note containing the task (must end in ".md"). Use the exact letter case.
startNoStart date (YYYY-MM-DD) to set, or null to clear.
formatNoField format for new metadata. Default: auto-detected from .obsidian/ config, falling back to emoji.
statusNoTarget status. "done" appends the ✅ date; "cancelled" appends the ❌ date.
createdNoCreated date (YYYY-MM-DD) to set or clear. Typically auto-stamped; use for corrections.
headingNoTarget heading to move the task to. On Kanban boards this is a lane move; works on any note with headings. Not valid on sub-tasks.
task_idNoTasks plugin 🆔 identifier to set, or null to clear.
block_idNoStable task identifier — the ^block-id at the end of the task line, without the ^. Preferred over line.
positionNoWhere within the target heading the task lands. "top" or "bottom" for the extremes; an integer (1-based) for an exact position among the lane's top-level cards (sub-tasks move with their parent and are not counted). Position 1 is the first card. A position past the card count lands directly below the last card (unlike "bottom", which appends after any non-task text at the end of the section). Defaults to "top" on heading moves.
priorityNoPriority signifier to set, or null to remove it.
scheduledNoScheduled date (YYYY-MM-DD) to set, or null to clear.
depends_onNoTasks plugin ⛔ dependency IDs to set (non-empty), or null to clear.
recurrenceNoTasks plugin 🔁 rule in natural language (e.g. "every week", "every month on the 15th", "every 2 weeks when done") to set, or null to remove it. Completing the task spawns its next occurrence.
descriptionNoNew task description text. Replaces the existing description; metadata fields and block_id are preserved.
add_subtasksNoChecklist items to append, one indented todo line each, under the task's existing items — never replaces them. Can be combined with any other change; not appended when the same call removes the task (on_completion delete). For full sub-tasks with metadata, use vault_create_task with parent_block_id.
on_completionNoTasks plugin 🏁 onCompletion action to set, or null to remove it. "delete" removes the task line on completion; "keep" leaves it in place (which is also the behavior when no 🏁 field exists on the task). Omitting this parameter leaves the field unchanged.
assign_block_idNoAdd or replace the ^block-id on the task line. Letters, digits, and hyphens only; must be unique within the note.

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations flag destructiveHint=true and idempotentHint=false, and the description substantiates both with concrete detail: Kanban lane moves, the delete-on-completion path that removes the line and children, the recurring spawn's loss of block_id/🆔/⛔, and the explicit caveat that completing by line is NOT idempotent for recurring tasks. It goes well beyond the annotation surface, covering concurrency ('concurrent write in progress'), auth/path blocking, and the advisories divergence mechanism.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The structure is strong — purpose, examples, usage, parameters, errors, syntax notes, and returns are clearly headed and front-loaded. However, the description is enormous relative to the task, and the exhaustive error catalog (24 entries) plus seven examples is heavier than an agent needs to select and invoke correctly, so it is complete rather than concise.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the 'Returns' section carries the full burden and documents every returned field including next_occurrence, changes, advisories, and on_completion_applied. Combined with the mutation/error/recurrence semantics, the definition is complete for a 19-parameter mutating tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3; the description earns above that by documenting cross-parameter semantics the schema cannot express: exactly-one-of block_id/line, mutual exclusivity, the explicit-null clearing convention, position's interaction with heading moves (and its invalidity on sub-tasks), and how on_completion/recurrence govern the status='done' transition. Some field-level restatement overlaps the schema, keeping this from a 5.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb+resource ('Update a task's status, priority, description, dates...') and enumerates the full set of mutable fields. It explicitly distinguishes itself from siblings: vault_list_tasks for identification and vault_create_task for creation. An agent can place this tool precisely without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The 'When to use' paragraph gives explicit conditions (completing, starting, re-prioritizing, editing, setting/clearing dates, moving headings, reordering) and names the alternatives to use first or instead (vault_list_tasks, vault_create_task). It also states the preconditions for a valid call — exactly one of block_id/line, at least one change, explicit null for clearing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

vault_write_noteWrite NoteA
Destructive

Create a markdown note. Errors if a note already exists at the path unless overwrite is set. Body replaces the entire note content: existing content will be lost unless you include it in body, so do not use this tool for surgical edits to large files. Properties are passed separately and merged with any existing properties when overwriting (new keys added, matching keys overwritten, keys set to null removed, unmentioned keys preserved); overwriting without properties keeps the existing property values.

Example: vault_write_note({ path: "Projects/notes.md", body: "# Notes\n\nProject notes here.", properties: { tags: ["project"], type: "project" } }) Example: vault_write_note({ path: "Projects/notes.md", body: "Updated content.", overwrite: true })

When to use: Creating a new note. Set overwrite: true only when you intend to replace an existing note's body. Prefer vault_update_properties for property-only edits (no body round-trip). Prefer vault_update_memory for appending dated entries to About Me/ memory files.

Errors:

  • "note already exists" — a note already lives at this path; set overwrite: true to replace it, or use vault_patch_note / vault_replace_in_note for partial edits

  • "path must end in …" — add the .md extension

  • "cannot write note …: that path is not a file" — a folder already has this name; choose another path

  • "absolute path blocked" / "path traversal blocked" / "hidden path blocked" — use a vault-relative path with no hidden (dot-prefixed) file or folder in it

  • "concurrent write in progress" — another write to this note is in flight; re-read the note and retry

  • "body contains a control character" — body includes a non-printable control byte; remove it before writing

Obsidian syntax: Body is Obsidian Flavored Markdown (no escaping applied). Watch for: #word = tag (escape with #), [[ = wikilink, %% = comment block. In properties: quote wikilink values ("[[Note]]"), use YAML lists for tags, keep property types consistent (string/number/list mismatches cause silent query failures).

Returns: Confirmation message.

ParametersJSON Schema
NameRequiredDescriptionDefault
bodyYesMarkdown body content — do not include frontmatter fences (---); use the properties parameter instead.
pathYesVault-relative path including the ".md" extension (e.g. "Projects/notes.md"). Parent folders are created as needed. Use the exact letter case; a different case can create a duplicate note or folder.
overwriteNoAllow overwriting an existing note (default: false — errors if file exists).
propertiesNoOptional properties to merge; a null value deletes that key.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations declare destructiveHint=true and idempotentHint=false, but the description goes well past them: it explains exactly what is destroyed (body replaces the entire note content), how properties merge on overwrite (new keys added, matching overwritten, null removes, unmentioned preserved), concurrency behavior, and an enumerated error catalogue including path-traversal and control-character failures. This is materially richer than the annotations alone.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads purpose and the irreversible body-replacement warning before examples and error codes; each block (when-to-use, errors, syntax) earns its place. It is longer than strictly necessary — the error catalogue is exhaustive — but the information density remains high and scannable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive, non-idempotent, 4-parameter write tool with a nested properties object and no output schema, the description covers data-loss risk, overwrite semantics, sibling routing, path rules, syntax pitfalls, and failure modes. Nothing an agent needs to call this safely is missing; the 'Returns: Confirmation message.' line closes the output gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3, but the description adds real meaning beyond it: the merge semantics for properties (what null does to a key, what happens to unmentioned keys when overwriting without properties) and the overwrite gating rule. It also flags Obsidian-specific quirks (#, [[, %%) that affect body and property values, which the schema does not cover.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Create a markdown note') and immediately distinguishes itself from sibling write tools by contrast: vault_patch_note / vault_replace_in_note for partial edits and vault_update_properties for property-only edits. An agent can route correctly without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Contains an explicit 'When to use' section, a conditional rule for overwrite ('only when you intend to replace an existing note's body'), and names two preferred alternatives with the conditions that select them (property-only edits, appending dated memory entries). No exclusions are left implicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 18 tool updatesv0.54.9
    • Changedvault_create_task5 fields changed
      • changedInput schema / properties / heading / description
        Previous value: -"Target heading. Required on Kanban boards; optional on regular notes (omit to append at end of body)."New value: +"Target heading. On a regular note, omit to append at end of body."
      • changedInput schema / properties / parent_block_id / description
        Previous value: -"^block-id (without the ^) of an existing task to nest under as a sub-task. Mutually exclusive with parent_line and heading."New value: +"^block-id (without the ^) of an existing task to nest under as a sub-task."
      • changedInput schema / properties / parent_line / description
        Previous value: -"1-based line number of an existing task to nest under as a sub-task. Mutually exclusive with parent_block_id and heading. Fragile if the file changed since the line was read."New value: +"1-based line number of an existing task to nest under as a sub-task. Fragile if the file changed since the line was read."
      • changedInput schema / properties / position / description
        Previous value: -"Where within the heading section the task is placed. \"top\" or \"bottom\" for the extremes; an integer (1-based) for an exact position among the lane's top-level cards (sub-tasks move with their parent and are not counted). Position 1 is the first card. A position past the card count lands directly below the last card (unlike \"bottom\", which appends after any trailing section content). Defaults to bottom. Kanban boards with new-card-insertion-method set to prepend default to top instead. Ignored when no heading or when placing under a parent."New value: +"Where within the heading section the task is placed. \"top\" or \"bottom\" for the extremes; an integer (1-based) for an exact position among the lane's top-level cards (sub-tasks move with their parent and are not counted). Position 1 is the first card. A position past the card count lands directly below the last card (unlike \"bottom\", which appends after any non-task text at the end of the section). Defaults to bottom."
      • changedInput schema / properties / recurrence / description
        Previous value: -"Tasks plugin 🔁 rule in natural language (e.g. \"every week\", \"every 2 weeks when done\"). Completing the task spawns its next occurrence."New value: +"Tasks plugin 🔁 rule in natural language (e.g. \"every week\", \"every month on the 15th\", \"every 2 weeks when done\"). Completing the task spawns its next occurrence."
    • Changedvault_delete_memory1 field changed
      • changedInput schema / properties / entry / description
        Previous value: -"Exact entry text as shown by vault_get_memory — without the \"- **YYYY-MM-DD**: \" prefix or bullet. Both date and entry must match for deletion."New value: +"Exact entry text as shown by vault_get_memory — without the \"- **YYYY-MM-DD**: \" prefix or bullet."
    • Changedvault_delete_span1 field changed
      • changedInput schema / properties / end_anchor / description
        Previous value: -"Short, unique substring that identifies the LAST line of the block, searched at or after the start_anchor line. The entire line is selected. Omit to delete just the single line containing start_anchor."New value: +"Short substring that identifies the LAST line of the block. The entire line is selected. Omit to delete just the single line containing start_anchor."
    • Changedvault_find_orphans1 field changed
      • changedInput schema / properties / exclude_folders / description
        Previous value: -"Folders to exclude — replaces the defaults ([\"Daily Notes\",\"Templates\",\"About Me\"]), not merged"New value: +"Folder paths to exclude (e.g. Projects; default: daily notes folder, Templates, \"About Me\")"
    • Changedvault_insert_at_anchor1 field changed
      • changedInput schema / properties / content / description
        Previous value: -"Content to insert (one or more lines), inserted verbatim as whole lines — blank lines are kept, and a trailing newline adds a blank line after the block."New value: +"Content to insert (one or more lines)."
    • Changedvault_list_files2 fields changed
      • addedInput schema / properties / extensions / minItems
        Added value: +1
      • changedInput schema / properties / folder / description
        Previous value: -"Folder path to search recursively (e.g. \"attachments\"). Omit to list the whole vault."New value: +"Folder path to search recursively (e.g. \"attachments\" or \"Projects/media\"). Omit to list the whole vault."
    • Changedvault_list_tasks3 fields changed
      • addedInput schema / properties / priority / minItems
        Added value: +1
      • changedInput schema / properties / sort_by / description
        Previous value: -"Sort key (default \"due\"). Date sorts cascade through related fields when the primary is absent; each fallback uses its own natural direction. \"position\" sorts by file path then line number — the natural order for Kanban boards."New value: +"Sort key (default \"due\"). Date sorts cascade through related fields when the primary is absent (through the rest of due → scheduled → start → created, in that order; done does not cascade); each fallback uses its own natural direction. \"position\" sorts by file path then line number — the natural order for Kanban boards."
      • changedInput schema / properties / status / description
        Previous value: -"Status filter, OR-combined (default \"not_done\" = todo + in_progress, excluding done and cancelled). Virtual values expand in arrays: \"not_done\" adds todo + in_progress, \"all\" includes every status."New value: +"Status filter, OR-combined (default \"not_done\" = todo + in_progress, excluding done and cancelled). \"all\" includes every status."
    • Changedvault_memory_recall1 field changed
      • changedInput schema / properties / limit / description
        Previous value: -"Cap on returned entries (default 50). When more match, the least-relevant are dropped and truncated=true — never a date range."New value: +"Cap on returned entries (default 50)."
    • Changedvault_patch_note3 fields changed
      • changedInput schema / properties / content / description
        Previous value: -"Markdown content to insert, written verbatim with no separator added — end it with a newline to leave a blank line after the inserted block. Must not begin with the target heading text (it would duplicate the heading, which is kept automatically)."New value: +"Markdown content to insert. Must not begin with the target heading text (it would duplicate the heading, which is kept automatically)."
      • changedInput schema / properties / heading / description
        Previous value: -"Target heading text (case-sensitive exact match). Required for replace and insert_before. Optional for append/prepend (omit for file-level operation)."New value: +"Target heading text (case-sensitive exact match). Omit for a file-level append or prepend."
      • changedInput schema / properties / operation / description
        Previous value: -"append | prepend | replace | insert_before. replace and insert_before require a heading; append and prepend work with or without one."New value: +"append | prepend | replace | insert_before."
    • Changedvault_read_note3 fields changed
      • changedInput schema / properties / heading / description
        Previous value: -"Return only this section (heading line + body, through the next same-or-higher heading). Case-sensitive exact match."New value: +"Return only this section. Case-sensitive exact match."
      • changedInput schema / properties / limit / description
        Previous value: -"Maximum lines returned (default: all remaining). A paged read's metadata line states the window, the total line count, and the next start_line."New value: +"Maximum lines returned (default: all remaining)."
      • changedInput schema / properties / start_line / description
        Previous value: -"First line to return, 1-based (default 1). Pages the delivered rendition (full body or a heading section). Not valid for outline or properties_only (JSON modes)."New value: +"First line to return, 1-based (default 1). Pages the text output (full body or a heading section). Not valid for outline or properties_only (JSON modes)."
    • Changedvault_replace_span2 fields changed
      • changedInput schema / properties / content / description
        Previous value: -"Replacement content (one or more lines) — replaces every line of the matched span. Must be non-empty; use vault_delete_span to delete without replacement."New value: +"Replacement content (one or more lines) — replaces every line of the matched span. Must be non-empty."
      • changedInput schema / properties / end_anchor / description
        Previous value: -"Short, unique substring that identifies the LAST line of the block, searched at or after the start_anchor line. The entire line is selected. Omit to replace just the single line containing start_anchor."New value: +"Short substring that identifies the LAST line of the block. The entire line is selected. Omit to replace just the single line containing start_anchor."
    • Changedvault_search5 fields changed
      • changedInput schema / properties / filters / description
        Previous value: -"Optional structured filters — all conditions AND-combine with each other and with the text query"New value: +"Optional structured filters"
      • changedInput schema / properties / filters / properties / created / description
        Previous value: -"Created date bounds (YYYY-MM-DD) on the frontmatter \"created\" property — notes without a parseable value never match"New value: +"Created date bounds (YYYY-MM-DD) on the frontmatter \"created\" property"
      • changedInput schema / properties / include_leading_callout / description
        Previous value: -"If true, each result includes its leading_callout ({ type, title, body }) when present. Off by default to keep results lean."New value: +"If true, include each result's leading callout. Off by default to keep results lean."
      • changedInput schema / properties / query / description
        Previous value: -"Search query text — unquoted terms use implicit AND with stemming; wrap in double quotes for exact phrases"New value: +"Search query text"
      • changedInput schema / properties / snippet_tokens / description
        Previous value: -"Snippet length in tokens (default 30)"New value: +"Snippet length in words (default 30)"
    • Changedvault_search_by_folder1 field changed
      • changedInput schema / properties / recursive / description
        Previous value: -"Include subfolders (default: true)"New value: +"Include subfolders (default: true); false lists only the folder's top level"
    • Changedvault_search_by_property1 field changed
      • changedInput schema / properties / value / description
        Previous value: -"Value to match (exact, case-sensitive, e.g. \"active\", \"session-log\"). Use vault_list_property_values to discover valid values for a key."New value: +"Value to match (e.g. \"active\", \"4\", \"1e-7\"). Use vault_list_property_values to discover valid values for a key."
    • Changedvault_update_memory1 field changed
      • changedInput schema / properties / options / properties / date / description
        Previous value: -"ISO YYYY-MM-DD date (defaults to today)"New value: +"ISO YYYY-MM-DD date (defaults to today, server timezone)"
    • Changedvault_update_properties1 field changed
      • changedInput schema / properties / properties / description
        Previous value: -"Properties to merge. New keys are added; existing keys are overwritten; a null value deletes that key; unmentioned keys are preserved."New value: +"Properties to merge; a null value deletes that key."
    • Changedvault_update_task3 fields changed
      • changedInput schema / properties / position / description
        Previous value: -"Where within the target heading the task lands after a heading move or auto-done-lane move. \"top\" or \"bottom\" for the extremes; an integer (1-based) for an exact position among the lane's top-level cards (sub-tasks move with their parent and are not counted). Position 1 is the first card. A position past the card count lands directly below the last card (unlike \"bottom\", which appends after any trailing section content). Defaults to \"top\" on heading moves. Without a heading, triggers a same-lane reorder to the given position; omitting position entirely performs no reorder. Ignored when the task is deleted on completion. Not valid on sub-tasks."New value: +"Where within the target heading the task lands. \"top\" or \"bottom\" for the extremes; an integer (1-based) for an exact position among the lane's top-level cards (sub-tasks move with their parent and are not counted). Position 1 is the first card. A position past the card count lands directly below the last card (unlike \"bottom\", which appends after any non-task text at the end of the section). Defaults to \"top\" on heading moves."
      • changedInput schema / properties / recurrence / description
        Previous value: -"Tasks plugin 🔁 rule in natural language (e.g. \"every week\", \"every 2 weeks when done\") to set, or null to remove it. Completing the task spawns its next occurrence."New value: +"Tasks plugin 🔁 rule in natural language (e.g. \"every week\", \"every month on the 15th\", \"every 2 weeks when done\") to set, or null to remove it. Completing the task spawns its next occurrence."
      • changedInput schema / properties / status / description
        Previous value: -"Target status. \"done\" appends the ✅ date and, on a Kanban board, moves the card and its checklist sub-items to the done lane (sub-item checkboxes are left as they are); a task with 🏁 delete / [onCompletion:: delete] is removed from the file instead. \"cancelled\" appends the ❌ date."New value: +"Target status. \"done\" appends the ✅ date; \"cancelled\" appends the ❌ date."
    • Changedvault_write_note1 field changed
      • changedInput schema / properties / properties / description
        Previous value: -"Optional properties to merge. New keys are added; existing keys with matching names are overwritten; a null value deletes that key; unmentioned keys are preserved from the existing file."New value: +"Optional properties to merge; a null value deletes that key."
  2. 23 tool updatesv0.54.7
    • Changedvault_create_task1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the note (must end in \".md\"). The note must already exist."New value: +"Vault-relative path to the note (must end in \".md\"). The note must already exist. Use the exact letter case."
    • Changedvault_delete_memory2 fields changed
      • addedInput schema / properties / entry / minLength
        Added value: +1
      • changedInput schema / properties / file / description
        Previous value: -"Memory file name without .md (e.g. \"Principles\")"New value: +"Memory file name without .md (e.g. \"Principles\"). Use the exact letter case."
    • Changedvault_delete_note2 fields changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path of the note to delete, including the \".md\" extension"New value: +"Vault-relative path of the note to delete, including the \".md\" extension. Use the exact letter case."
      • changedInput schema / properties / prune_empty_folders / description
        Previous value: -"When true, remove the note's parent folder(s) if deleting it leaves them empty, walking up to (but never including) the vault root. Default false matches Obsidian, which leaves empty folders in place. Only removes a folder with zero entries — a folder still holding any file, including a hidden one like .DS_Store, is left alone."New value: +"When true, also remove parent folders the delete leaves empty. Default false."
    • Changedvault_delete_span1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the note, including the \".md\" extension (e.g. \"Tracker.md\", \"Notes/Plan.md\")"New value: +"Vault-relative path to the note, including the \".md\" extension (e.g. \"Tracker.md\", \"Notes/Plan.md\"). Use the exact letter case."
    • Changedvault_get_daily_note1 field changed
      • addedInput schema / properties / date / minLength
        Added value: +1
    • Changedvault_get_memory1 field changed
      • changedInput schema / properties / file / description
        Previous value: -"Memory file name without .md (e.g. \"Principles\", \"Opinions\")"New value: +"Memory file name without .md (e.g. \"Principles\", \"Opinions\"). Use the exact letter case."
    • Changedvault_insert_at_anchor1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the note, including the \".md\" extension (e.g. \"Notes/Plan.md\", \"Tracker.md\")"New value: +"Vault-relative path to the note, including the \".md\" extension (e.g. \"Notes/Plan.md\", \"Tracker.md\"). Use the exact letter case."
    • Changedvault_list_notes4 fields changed
      • changedInput schema / properties / folder / description
        Previous value: -"Folder path prefix (e.g. \"About Me\", \"Projects\"). Includes all subfolders."New value: +"Vault-relative folder to list (e.g. \"About Me\", \"Projects\")."
      • addedInput schema / properties / folder / minLength
        Added value: +1
      • changedInput schema / properties / glob / description
        Previous value: -"Glob pattern for path filtering (e.g. \"**/*session-log*.md\"). Supports * and ** wildcards. Combined with folder when both are set."New value: +"Glob pattern for note paths (e.g. \"**/*session-log*.md\")."
      • addedInput schema / properties / glob / minLength
        Added value: +1
    • Changedvault_list_property_values2 fields changed
      • changedInput schema / properties / folder / description
        Previous value: -"Restrict to a folder prefix (e.g. \"Projects\")"New value: +"Restrict to a folder (e.g. \"Projects\")"
      • changedInput schema / properties / limit / description
        Previous value: -"Max values to return (default 50). Increase for high-cardinality properties."New value: +"Max values to return (default 50)."
    • Changedvault_list_tasks2 fields changed
      • changedInput schema / properties / folder / description
        Previous value: -"Restrict to a note-path prefix (e.g. \"Code Projects/vault-cortex\")"New value: +"Restrict to a folder (e.g. \"Code Projects/vault-cortex\")"
      • changedInput schema / properties / path / description
        Previous value: -"Restrict to one note (vault-relative path ending \".md\")"New value: +"Restrict to one note (vault-relative path ending \".md\", case-sensitive)"
    • Changedvault_memory_recall1 field changed
      • changedInput schema / properties / file / description
        Previous value: -"Optional: restrict to one memory file, name without .md (e.g. \"Opinions\"). Omit for cross-file recall — the default and usual choice."New value: +"Optional: restrict to one memory file, name without .md (e.g. \"Opinions\"), in its exact letter case. Omit for cross-file recall — the default and usual choice."
    • Changedvault_move_note3 fields changed
      • changedInput schema / properties / new_path / description
        Previous value: -"Destination vault-relative path (e.g. \"Projects/Spec.md\"). Must end in .md and must not already exist; parent folders are created as needed."New value: +"Destination vault-relative path (e.g. \"Projects/Spec.md\"). Must end in .md and must not already exist; parent folders are created as needed. Use the exact letter case of existing folders; a different case can create a second folder."
      • changedInput schema / properties / old_path / description
        Previous value: -"Current vault-relative path of the note to move (e.g. \"Inbox/Draft.md\"). Must end in .md."New value: +"Current vault-relative path of the note to move (e.g. \"Inbox/Draft.md\"). Must end in .md. Use the exact letter case."
      • changedInput schema / properties / prune_empty_folders / description
        Previous value: -"When true, remove the source folder(s) if the move leaves them empty, walking up to (but never including) the vault root. Default false matches Obsidian, which leaves empty folders in place. Only removes a folder with zero entries — an in-place rename or a move into a subfolder of the source leaves it non-empty and prunes nothing."New value: +"When true, also remove parent folders of old_path that the move leaves empty. Default false."
    • Changedvault_patch_note1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the note, including the \".md\" extension (e.g. \"TASKS.md\", \"Projects/plan.md\")"New value: +"Vault-relative path to the note, including the \".md\" extension (e.g. \"TASKS.md\", \"Projects/plan.md\"). Use the exact letter case."
    • Changedvault_read_file4 fields changed
      • changedInput schema / properties / limit / description
        Previous value: -"Maximum lines returned (default: all remaining). A paged read's metadata line states the window, the total line count, and the next start_line. The output byte cap still applies to the window — reduce limit if it overflows."New value: +"Maximum lines returned (default: all remaining)."
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the file, including its extension (e.g. \"attachments/photo.png\", \"Boards/Roadmap.canvas\"). Must NOT end in \".md\" — notes are read with vault_read_note."New value: +"Vault-relative path to the file, including its extension (e.g. \"attachments/photo.png\", \"Boards/Roadmap.canvas\"). Must NOT end in \".md\" — notes are read with vault_read_note. Use the exact letter case."
      • changedInput schema / properties / raw / description
        Previous value: -"Return an alternative representation of the file. For .canvas this is the JSON Canvas source (geometry, ids, colors); for .pdf this renders pages as images instead of extracting text — useful for scanned documents, diagrams, and layout-sensitive content. Text formats already return their source, so raw changes nothing there. Images have no text source — raw returns an error."New value: +"Return the file's alternative form: JSON source for .canvas, page images for .pdf. Changes nothing for text formats, which already return their source. Rejected for images."
      • changedInput schema / properties / start_line / description
        Previous value: -"First line to return, 1-based (default 1). Pages any text result — text formats, canvas outlines and raw JSON, PDF-extracted text. Not valid for images or for PDFs with raw: true."New value: +"First line to return, 1-based (default 1)."
    • Changedvault_read_note1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the note, including the \".md\" extension (e.g. \"About Me/Principles.md\")"New value: +"Vault-relative path to the note, including the \".md\" extension (e.g. \"About Me/Principles.md\"). Use the exact letter case."
    • Changedvault_replace_in_note1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the note, including the \".md\" extension (e.g. \"Projects/plan.md\")"New value: +"Vault-relative path to the note, including the \".md\" extension (e.g. \"Projects/plan.md\"). Use the exact letter case."
    • Changedvault_replace_span1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the note, including the \".md\" extension (e.g. \"Tracker.md\", \"Notes/Plan.md\")"New value: +"Vault-relative path to the note, including the \".md\" extension (e.g. \"Tracker.md\", \"Notes/Plan.md\"). Use the exact letter case."
    • Changedvault_search1 field changed
      • changedInput schema / properties / filters / properties / folder / description
        Previous value: -"Restrict to a folder path prefix (e.g. \"Projects\")"New value: +"Restrict to a folder (e.g. \"Projects\")"
    • Changedvault_search_by_property2 fields changed
      • changedInput schema / properties / folder / description
        Previous value: -"Restrict to a folder prefix (e.g. \"Projects\")"New value: +"Restrict to a folder (e.g. \"Projects\")"
      • changedInput schema / properties / limit / description
        Previous value: -"Max results (default 20). Increase for broad metadata queries."New value: +"Max results (default 20)"
    • Changedvault_update_memory1 field changed
      • changedInput schema / properties / file / description
        Previous value: -"Memory file name without .md (e.g. \"Principles\")"New value: +"Memory file name without .md (e.g. \"Principles\"). Use the exact letter case; a different case can create a second file."
    • Changedvault_update_properties1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the note, including the \".md\" extension"New value: +"Vault-relative path to the note, including the \".md\" extension. Use the exact letter case."
    • Changedvault_update_task1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path to the note containing the task (must end in \".md\")"New value: +"Vault-relative path to the note containing the task (must end in \".md\"). Use the exact letter case."
    • Changedvault_write_note1 field changed
      • changedInput schema / properties / path / description
        Previous value: -"Vault-relative path including the \".md\" extension (e.g. \"Projects/notes.md\"). Parent folders are created as needed."New value: +"Vault-relative path including the \".md\" extension (e.g. \"Projects/notes.md\"). Parent folders are created as needed. Use the exact letter case; a different case can create a duplicate note or folder."
  3. 1 tool updatev0.54.1
    • Changedvault_get_memory2 fields changed
      • changedInput schema / properties / on_or_after / description
        Previous value: -"Inclusive date filter (YYYY-MM-DD). When provided with file and section, returns structured JSON entries dated on or after this date instead of raw markdown. Requires both file and section."New value: +"Inclusive date filter (YYYY-MM-DD). When provided with file, returns structured JSON entries dated on or after this date instead of raw markdown. Requires a file; add section to scope to one H2 section."
      • changedInput schema / properties / section / description
        Previous value: -"H2 section heading (e.g. \"Decision heuristics (newest first)\"). Matched case-insensitively, with or without the \"(newest first)\" suffix. Call vault_list_memory_files first to discover valid names."New value: +"H2 section heading (e.g. \"Decision heuristics (newest first)\"). Matched case-insensitively, with or without the \"(newest first)\" suffix. Omit to read the whole file (with on_or_after, every H2 section's entries). Call vault_list_memory_files first to discover valid names."
  4. 2 tool updatesv0.54.0
    • Changedvault_create_task1 field changed
      • changedInput schema / properties / subtasks / description
        Previous value: -"Checklist item descriptions — created as indented [ ] lines under the card (no metadata). For full sub-tasks with dates, priority, and block_id, make a separate call with parent_block_id."New value: +"Checklist item descriptions — created as indented todo lines under the card (no metadata). For full sub-tasks with dates, priority, and block_id, make a separate call with parent_block_id."
    • Changedvault_update_task1 field changed
      • changedInput schema / properties / add_subtasks / description
        Previous value: -"Checklist items to append, one indented [ ] line each, under the task's existing items — never replaces them. Can be combined with any other change; not appended when the same call removes the task (on_completion delete). For full sub-tasks with metadata, use vault_create_task with parent_block_id."New value: +"Checklist items to append, one indented todo line each, under the task's existing items — never replaces them. Can be combined with any other change; not appended when the same call removes the task (on_completion delete). For full sub-tasks with metadata, use vault_create_task with parent_block_id."
  5. 4 tool updatesv0.53.0
    • Changedvault_create_task4 fields changed
      • addedInput schema / properties / position / anyOf
        Added value: +[
        +  {
        +    "enum": [
        +      "top",
        +      "bottom"
        +    ],
        +    "type": "string"
        +  },
        +  {
        +    "maximum": 9007199254740991,
        +    "minimum": 1,
        +    "type": "integer"
        +  }
        +]
      • changedInput schema / properties / position / description
        Previous value: -"Where within the heading section the task is placed. Defaults to bottom. Kanban boards with new-card-insertion-method set to prepend default to top instead. Ignored when no heading or when placing under a parent."New value: +"Where within the heading section the task is placed. \"top\" or \"bottom\" for the extremes; an integer (1-based) for an exact position among the lane's top-level cards (sub-tasks move with their parent and are not counted). Position 1 is the first card. A position past the card count lands directly below the last card (unlike \"bottom\", which appends after any trailing section content). Defaults to bottom. Kanban boards with new-card-insertion-method set to prepend default to top instead. Ignored when no heading or when placing under a parent."
      • removedInput schema / properties / position / enum
        Removed value: -[
        -  "top",
        -  "bottom"
        -]
      • removedInput schema / properties / position / type
        Removed value: -"string"
    • Changedvault_get_memory1 field changed
      • addedInput schema / properties / on_or_after
        Added value: +{
        +  "description": "Inclusive date filter (YYYY-MM-DD). When provided with file and section, returns structured JSON entries dated on or after this date instead of raw markdown. Requires both file and section.",
        +  "minLength": 1,
        +  "type": "string"
        +}
    • Changedvault_read_note1 field changed
      • changedInput schema / properties / outline / description
        Previous value: -"If true, returns { leading_callout?, leading_content?, headings } as JSON instead of body content — a cheap structure fetch for large notes. headings: [{ level, text, bytes }]; leading_callout: { type, title, body } when the note has a top-of-file callout; leading_content: the rest of the body text above the first heading (callout lines excluded) when the note has any."New value: +"If true, returns { bytes, modified, leading_callout?, leading_content?, headings } as JSON instead of body content — a cheap structure fetch for large notes. headings: [{ level, text, bytes }]; leading_callout: { type, title, body } when the note has a top-of-file callout; leading_content: the rest of the body text above the first heading (callout lines excluded) when the note has any."
    • Changedvault_update_task5 fields changed
      • addedInput schema / properties / position / anyOf
        Added value: +[
        +  {
        +    "enum": [
        +      "top",
        +      "bottom"
        +    ],
        +    "type": "string"
        +  },
        +  {
        +    "maximum": 9007199254740991,
        +    "minimum": 1,
        +    "type": "integer"
        +  }
        +]
      • removedInput schema / properties / position / default
        Removed value: -"top"
      • changedInput schema / properties / position / description
        Previous value: -"Where within the target heading the task lands after a heading move or auto-done-lane move. Defaults to \"top\". Ignored when no heading move occurs."New value: +"Where within the target heading the task lands after a heading move or auto-done-lane move. \"top\" or \"bottom\" for the extremes; an integer (1-based) for an exact position among the lane's top-level cards (sub-tasks move with their parent and are not counted). Position 1 is the first card. A position past the card count lands directly below the last card (unlike \"bottom\", which appends after any trailing section content). Defaults to \"top\" on heading moves. Without a heading, triggers a same-lane reorder to the given position; omitting position entirely performs no reorder. Ignored when the task is deleted on completion. Not valid on sub-tasks."
      • removedInput schema / properties / position / enum
        Removed value: -[
        -  "top",
        -  "bottom"
        -]
      • removedInput schema / properties / position / type
        Removed value: -"string"
  6. 2 tool updatesv0.51.1
    • Changedvault_create_task1 field changed
      • addedInput schema / properties / on_completion
        Added value: +{
        +  "description": "Tasks plugin 🏁 onCompletion action. \"delete\" removes the task line on completion; \"keep\" leaves it in place.",
        +  "enum": [
        +    "delete",
        +    "keep"
        +  ],
        +  "type": "string"
        +}
    • Changedvault_update_task3 fields changed
      • changedInput schema / properties / add_subtasks / description
        Previous value: -"Checklist items to append, one indented [ ] line each, under the task's existing items — never replaces them. Can be combined with any other change. For full sub-tasks with metadata, use vault_create_task with parent_block_id."New value: +"Checklist items to append, one indented [ ] line each, under the task's existing items — never replaces them. Can be combined with any other change; not appended when the same call removes the task (on_completion delete). For full sub-tasks with metadata, use vault_create_task with parent_block_id."
      • addedInput schema / properties / on_completion
        Added value: +{
        +  "anyOf": [
        +    {
        +      "enum": [
        +        "delete",
        +        "keep"
        +      ],
        +      "type": "string"
        +    },
        +    {
        +      "type": "null"
        +    }
        +  ],
        +  "description": "Tasks plugin 🏁 onCompletion action to set, or null to remove it. \"delete\" removes the task line on completion; \"keep\" leaves it in place (which is also the behavior when no 🏁 field exists on the task). Omitting this parameter leaves the field unchanged."
        +}
      • changedInput schema / properties / status / description
        Previous value: -"Target status. \"done\" appends the ✅ date and, on a Kanban board, moves the card and its checklist sub-items to the done lane (sub-item checkboxes are left as they are). \"cancelled\" appends the ❌ date."New value: +"Target status. \"done\" appends the ✅ date and, on a Kanban board, moves the card and its checklist sub-items to the done lane (sub-item checkboxes are left as they are); a task with 🏁 delete / [onCompletion:: delete] is removed from the file instead. \"cancelled\" appends the ❌ date."
  7. 2 tool updatesv0.51.0
    • Changedvault_create_task1 field changed
      • addedInput schema / properties / recurrence
        Added value: +{
        +  "description": "Tasks plugin 🔁 rule in natural language (e.g. \"every week\", \"every 2 weeks when done\"). Completing the task spawns its next occurrence.",
        +  "minLength": 1,
        +  "type": "string"
        +}
    • Changedvault_update_task1 field changed
      • addedInput schema / properties / recurrence
        Added value: +{
        +  "anyOf": [
        +    {
        +      "minLength": 1,
        +      "type": "string"
        +    },
        +    {
        +      "type": "null"
        +    }
        +  ],
        +  "description": "Tasks plugin 🔁 rule in natural language (e.g. \"every week\", \"every 2 weeks when done\") to set, or null to remove it. Completing the task spawns its next occurrence."
        +}
  8. 17 tool updatesv0.50.0
    • Changedvault_delete_span1 field changed
      • addedInput schema / properties / first_match / default
        Added value: +false
    • Changedvault_find_orphans4 fields changed
      • addedInput schema / properties / limit / default
        Added value: +50
      • addedInput schema / properties / limit / maximum
        Added value: +9007199254740991
      • addedInput schema / properties / limit / minimum
        Added value: +1
      • changedInput schema / properties / limit / type
        Previous value: -"number"New value: +"integer"
    • Changedvault_insert_at_anchor1 field changed
      • addedInput schema / properties / first_match / default
        Added value: +false
    • Changedvault_list_files1 field changed
      • addedInput schema / properties / limit / default
        Added value: +50
    • Changedvault_list_property_values4 fields changed
      • addedInput schema / properties / limit / default
        Added value: +50
      • addedInput schema / properties / limit / maximum
        Added value: +9007199254740991
      • addedInput schema / properties / limit / minimum
        Added value: +1
      • changedInput schema / properties / limit / type
        Previous value: -"number"New value: +"integer"
    • Changedvault_list_tasks4 fields changed
      • addedInput schema / properties / limit / default
        Added value: +50
      • addedInput schema / properties / sort_by / default
        Added value: +"due"
      • addedInput schema / properties / status / default
        Added value: +"not_done"
      • addedInput schema / properties / top_level_only / default
        Added value: +false
    • Changedvault_memory_recall2 fields changed
      • addedInput schema / properties / limit
        Added value: +{
        +  "default": 50,
        +  "description": "Cap on returned entries (default 50). When more match, the least-relevant are dropped and truncated=true — never a date range.",
        +  "maximum": 9007199254740991,
        +  "minimum": 1,
        +  "type": "integer"
        +}
      • removedInput schema / properties / max_results
        Removed value: -{
        -  "description": "Cap on returned entries (default 50). When more match, the least-relevant are dropped and truncated=true — never a date range.",
        -  "type": "number"
        -}
    • Changedvault_recent_notes5 fields changed
      • addedInput schema / properties / limit / default
        Added value: +20
      • addedInput schema / properties / limit / maximum
        Added value: +9007199254740991
      • addedInput schema / properties / limit / minimum
        Added value: +1
      • changedInput schema / properties / limit / type
        Previous value: -"number"New value: +"integer"
      • addedInput schema / properties / sort_by / default
        Added value: +"modified"
    • Changedvault_replace_in_note1 field changed
      • addedInput schema / properties / replace_all_occurrences / default
        Added value: +false
    • Changedvault_replace_span1 field changed
      • addedInput schema / properties / first_match / default
        Added value: +false
    • Changedvault_search6 fields changed
      • removedInput schema / properties / filters / properties / include_leading_callout
        Removed value: -{
        -  "description": "If true, each result includes its leading_callout ({ type, title, body }) when present. Off by default to keep results lean.",
        -  "type": "boolean"
        -}
      • removedInput schema / properties / filters / properties / limit
        Removed value: -{
        -  "description": "Max results (default 20)",
        -  "type": "number"
        -}
      • removedInput schema / properties / filters / properties / snippet_tokens
        Removed value: -{
        -  "description": "Snippet length in tokens (default 30)",
        -  "type": "number"
        -}
      • addedInput schema / properties / include_leading_callout
        Added value: +{
        +  "default": false,
        +  "description": "If true, each result includes its leading_callout ({ type, title, body }) when present. Off by default to keep results lean.",
        +  "type": "boolean"
        +}
      • addedInput schema / properties / limit
        Added value: +{
        +  "default": 20,
        +  "description": "Max results (default 20)",
        +  "maximum": 9007199254740991,
        +  "minimum": 1,
        +  "type": "integer"
        +}
      • addedInput schema / properties / snippet_tokens
        Added value: +{
        +  "default": 30,
        +  "description": "Snippet length in tokens (default 30)",
        +  "maximum": 9007199254740991,
        +  "minimum": 1,
        +  "type": "integer"
        +}
    • Changedvault_search_by_folder5 fields changed
      • addedInput schema / properties / limit / default
        Added value: +20
      • addedInput schema / properties / limit / maximum
        Added value: +9007199254740991
      • addedInput schema / properties / limit / minimum
        Added value: +1
      • changedInput schema / properties / limit / type
        Previous value: -"number"New value: +"integer"
      • addedInput schema / properties / recursive / default
        Added value: +true
    • Changedvault_search_by_property4 fields changed
      • addedInput schema / properties / limit / default
        Added value: +20
      • addedInput schema / properties / limit / maximum
        Added value: +9007199254740991
      • addedInput schema / properties / limit / minimum
        Added value: +1
      • changedInput schema / properties / limit / type
        Previous value: -"number"New value: +"integer"
    • Changedvault_search_by_tag1 field changed
      • addedInput schema / properties / exact / default
        Added value: +false
    • Changedvault_update_memory1 field changed
      • addedInput schema / properties / options / properties / position / default
        Added value: +"top"
    • Changedvault_update_task1 field changed
      • addedInput schema / properties / position / default
        Added value: +"top"
    • Changedvault_write_note1 field changed
      • addedInput schema / properties / overwrite / default
        Added value: +false

TDQS

A4.2/5.0

Scored across 33 tools

Disambiguation3/5

The tool set has several overlapping clusters: five body-editing tools (vault_patch_note, vault_replace_in_note, vault_delete_span, vault_replace_span, vault_insert_at_anchor) and six discovery/search tools all target similar user intents. Descriptions are exhaustive and contain explicit 'Prefer X for Y' guidance, which mitigates misselection, but an agent still faces real choices among many narrowly differentiated options.

Naming Consistency4/5

All tools are snake_case with a consistent 'vault_' prefix, and most follow a verb_noun pattern (e.g. vault_delete_note, vault_list_tasks, vault_create_task). Minor deviations exist: vault_search, vault_recent_notes, and vault_memory_recall break the verb_noun convention, keeping this from a perfect score.

Tool Count2/5

At 33 tools, the set exceeds the 25+ threshold that the rubric treats as too many. Although the Obsidian vault domain is broad (notes, memory, tasks, search, files, daily notes), several editing and search tools could be consolidated without losing capability.

Completeness4/5

Coverage is strong: notes have full lifecycle support (create, read, update, move, delete, properties), plus search, backlinks, outgoing links, orphans, tags, property discovery, memory, tasks, daily notes, and file listing/reading. Minor gaps remain, such as no tool to delete or write non-markdown files (e.g. canvases, attachments) and no explicit folder creation/deletion.

Maintenance

ActivityActive
ResponsivenessResponsive

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    A server that enables AI agents to perform sophisticated knowledge discovery and analysis across Obsidian vaults through the Local REST API plugin, supporting complex multi-step workflows with advanced filtering and full content retrieval.
    3
    21
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    A third-party MCP server for interacting with HashiCorp Vault to manage ACL policies, audit devices, and secret engines like KV v2, PKI, and Transit. It provides tools for system backend administration and includes prompts for generating security policy configurations.
    MIT