Copilot for Obsidian adds an AI assistant to the note-taking app, and since version 4 that assistant is an agent. It can run opencode, Claude Code or Codex against your vault: reading notes, using tools, creating Obsidian files and working across several turns with permissions you control. Projects give ongoing work its own instructions, context and chat history, skills and saved commands are shared across agents, and Quick Ask answers a question about selected text without leaving the note.
You choose where the model runs. Add an API key for a cloud provider, point it at a local or OpenAI-compatible server, or connect the Claude Code or Codex login you already have; keys are kept in Obsidian's keychain on the device rather than in the vault. Agent features need the desktop app because they run local processes, while chat, commands and Quick Ask also work on mobile.
The plugin is made by Logan Yang's company Brevilabs, is AGPL-3.0 licensed, and has about 7,800 stars. A paid plan adds Copilot-hosted models and cloud features, which run on Brevilabs' own closed-source backend; the plugin itself is fully open source.
- Repository: github.com/logancyang/obsidian-copilot
- Licence: AGPL-3.0 (GNU Affero General Public License v3.0)
- Language: TypeScript. Stars: 7,779. Forks: 750. Last push: Oct 3, 2026.
- Scan: safe, Oct 3, 2026, commit adb441c
Who it is for
Obsidian users who want an assistant that works on their own notes, from researchers and writers to anyone keeping a personal knowledge base, particularly those who already pay for Claude, ChatGPT or an API, or prefer a local model.
Getting started
1. Install Copilot from Obsidian's Community Plugins (or open its directory page)
open https://obsidian.md/plugins?id=copilot2. Open the agent settings
# Settings > Copilot > Basic > Agents3. Choose Download opencode, or Auto-detect to connect an installed Claude Code, then start a chat
# Command palette: Open Copilot Agent Chat WindowThe free path needs your own model access: an API key, a local model, or an existing Claude Code or Codex login, each billed or limited by its own provider. The README notes that the free opencode Zen models may log or train on prompts, so check their terms before using them on private notes.
Safety scan
We cloned logancyang/obsidian-copilot at commit adb441c on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no suspicious patterns and no committed binaries across 1,635 files and about 272,000 lines of TypeScript. The two bare-IP URLs are in isSelfHostedProvider.test.ts, checking which addresses count as private networks.
- The one installer is docs/install-claude-agent-mode-windows.ps1, a 73-line helper that installs Claude Code on Windows by running Anthropic's own install.ps1 from claude.ai. The plugin can also download opencode for you. Both are the vendors' official installers.
- Network hosts are the model providers, the project's own obsidiancopilot.com and models.brevilabs.com for hosted models, and miyo.md for its local search add-on. A PostHog host appears in the documentation site's analytics code; we found no analytics in the plugin itself.
- The plugin's package-lock.json pins 1,290 packages with 21 advisories (9 high, 11 moderate, 1 low), mostly denial-of-service bugs in brace-expansion, braces, js-yaml and ip-address plus an old moment. The one critical, an Astro image-optimization RCE, is in docs/package-lock.json, the documentation site, which does not ship.
- Five workflows. The pull_request_target one, pr-size.yml, only labels pull requests by size with actions/github-script and does not check out code. No third-party actions. Licence and contributing guide present; no security policy, Dependabot or CodeQL.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | 1 npm lifecycle script. 1 installer script |
| Committed binaries | None. |
| CI workflows | 5 workflows. 1 uses pull_request_target, none check out the pull request head. No third-party actions. |
| Network hosts | 40 distinct hosts referenced from source; most often github.com, a.com, generativelanguage.googleapis.com, b.com. 2 URLs to a bare IP address, listed under the raw findings. |
| Known vulnerabilities | 46 advisories across 1,543 pinned packages: 1 critical, 19 high, 20 moderate, 6 low. docs/package-lock.json: 492 packages, 26 advisories; package-lock.json: 1,290 packages, 21 advisories. |
| Project hygiene | Has licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
URLs to bare IP addresses (2)
| Where | Rule | Match |
|---|---|---|
| src/modelManagement/providers/isSelfHostedProvider.test.ts:37 | ip-literal-url | "http://172.32.0.1", |
| src/modelManagement/providers/isSelfHostedProvider.test.ts:38 | ip-literal-url | "http://11.0.0.1", |
npm lifecycle scripts (1)
package.jsonprepare:husky
Installer scripts (1)
- docs/install-claude-agent-mode-windows.ps1, 73 lines; talks to claude.ai
Worst known vulnerabilities (24 of 46)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-26w7-cxv4-gfx2 | critical | astro@7.2.4 | Astro: Remote code execution through AVIF image optimization |
| GHSA-j22f-vq7h-c4qm | high | devalue@5.9.1 | devalue: `stringify`/`uneval` serialize shared memory |
| GHSA-mcm9-63f2-9j32 | high | devalue@5.9.1 | devalue: Repeated primitive strings cause quadratic expansion in uneval |
| GHSA-r9w8-h9r3-54w4 | high | devalue@5.9.1 | devalue: Custom ArrayBuffer revivers can bypass typed-array allocation validation |
| GHSA-x5rw-q4pp-hg5g | high | devalue@5.9.1 | devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise |
| GHSA-ch52-4w7c-c8xp | high | http-cache-semantics@4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses |
| GHSA-2883-xcg3-v3hh | high | js-yaml@4.3.1 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources |
| GHSA-rgj7-g3m4-5g8c | high | sharp@0.35.3 | sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 |
| GHSA-w27v-7q3p-w38r | high | svgo@4.0.2 | SVGO: removeScripts allows executable links through namespace and control-character bypasses |
| GHSA-rfgv-xxqx-mfg5 | high | undici@8.10.0 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol |
| GHSA-vp8m-p9jh-q5pm | high | undici@8.10.0 | undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors |
| GHSA-w293-vg96-wgc3 | high | undici@8.10.0 | undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool |
| GHSA-2883-xcg3-v3hh | high | js-yaml@3.15.1 | js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@5.0.9 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@5.0.9 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@1.1.18 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@1.1.18 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-vfj7-8cjw-p6xm | high | braces@3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@2.1.4 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@2.1.4 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-4q55-j62x-fr9h | moderate | devalue@5.9.1 | devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion |
| GHSA-9rgm-9g3h-6x36 | moderate | devalue@5.9.1 | Svelte devalue: DoS via malformed input |
| GHSA-hx4r-w6wj-j8fg | moderate | devalue@5.9.1 | devalue: Residual sparse-array CPU amplification in uneval |
| GHSA-4vpr-x523-8j87 | moderate | svgo@4.0.2 | SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements |
Workflows worth a look
- .github/workflows/pr-size.yml: pull_request_target
By the numbers
| Stars | 7,779 |
|---|---|
| Forks | 750 |
| Contributors | 49 |
| Commits | 1,343 |
| Open issues | 75 |
| Open pull requests | 71 |
| Releases | 129 |
| Latest release | 4.0.13 |
| Licence | AGPL-3.0 |
| Main language | TypeScript |
| Project age | 3 years |
| Last push | Oct 3, 2026 |
| Tracked files | 1,635 |
| Lines of code | 271.5K |
| Checkout size | 27 MB |
Lines by language: TypeScript 252K, Markdown 11.6K, JavaScript 4,353, Shell 1,115, CSS 1,107, YAML 752.
Questions
Is Copilot for Obsidian free?
The plugin is AGPL-3.0 and free with your own API key, a local model, or an existing Claude Code or Codex account. That covers single-agent chats, Projects, skills, commands, Quick Chat and Quick Ask. A paid plan adds Copilot-hosted models, cloud-backed tools and multi-agent requests, with a 14-day refund.
Does Copilot send my notes to Brevilabs?
Not on the free path. The README says messages and note context go only to the provider, local endpoint or CLI agent you configure. Brevilabs receives request content only when you use one of its hosted features, and says it processes that content transiently without keeping it or training on it.
Does Copilot for Obsidian work on mobile?
Partly. The agent features run local processes, so they are desktop only. Quick Chat, custom commands and Quick Ask work on mobile.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
