5 min read

Copilot for Obsidian: AI Agents Inside Your Vault (GitHub, Scanned)

An Obsidian plugin that brings AI chat and agents like Claude Code and Codex to your notes.

Copilot for Obsidian logo
✅
Scan: safe. Nothing malicious. One thing to know: agent mode runs Claude Code, Codex or opencode as local processes with access to your vault, and paid features send content to Brevilabs' closed-source backend. Scanned Oct 3, 2026; the full report is below.

Copilot for Obsidian adds an AI assistant to the note-taking app, and since version 4 that assistant is an agent. It can run opencode, Claude Code or Codex against your vault: reading notes, using tools, creating Obsidian files and working across several turns with permissions you control. Projects give ongoing work its own instructions, context and chat history, skills and saved commands are shared across agents, and Quick Ask answers a question about selected text without leaving the note.

You choose where the model runs. Add an API key for a cloud provider, point it at a local or OpenAI-compatible server, or connect the Claude Code or Codex login you already have; keys are kept in Obsidian's keychain on the device rather than in the vault. Agent features need the desktop app because they run local processes, while chat, commands and Quick Ask also work on mobile.

The plugin is made by Logan Yang's company Brevilabs, is AGPL-3.0 licensed, and has about 7,800 stars. A paid plan adds Copilot-hosted models and cloud features, which run on Brevilabs' own closed-source backend; the plugin itself is fully open source.

Who it is for

Obsidian users who want an assistant that works on their own notes, from researchers and writers to anyone keeping a personal knowledge base, particularly those who already pay for Claude, ChatGPT or an API, or prefer a local model.

Getting started

1. Install Copilot from Obsidian's Community Plugins (or open its directory page)

open https://obsidian.md/plugins?id=copilot

2. Open the agent settings

# Settings > Copilot > Basic > Agents

3. Choose Download opencode, or Auto-detect to connect an installed Claude Code, then start a chat

# Command palette: Open Copilot Agent Chat Window

The free path needs your own model access: an API key, a local model, or an existing Claude Code or Codex login, each billed or limited by its own provider. The README notes that the free opencode Zen models may log or train on prompts, so check their terms before using them on private notes.

Safety scan

We cloned logancyang/obsidian-copilot at commit adb441c on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious patterns and no committed binaries across 1,635 files and about 272,000 lines of TypeScript. The two bare-IP URLs are in isSelfHostedProvider.test.ts, checking which addresses count as private networks.
  • The one installer is docs/install-claude-agent-mode-windows.ps1, a 73-line helper that installs Claude Code on Windows by running Anthropic's own install.ps1 from claude.ai. The plugin can also download opencode for you. Both are the vendors' official installers.
  • Network hosts are the model providers, the project's own obsidiancopilot.com and models.brevilabs.com for hosted models, and miyo.md for its local search add-on. A PostHog host appears in the documentation site's analytics code; we found no analytics in the plugin itself.
  • The plugin's package-lock.json pins 1,290 packages with 21 advisories (9 high, 11 moderate, 1 low), mostly denial-of-service bugs in brace-expansion, braces, js-yaml and ip-address plus an old moment. The one critical, an Astro image-optimization RCE, is in docs/package-lock.json, the documentation site, which does not ship.
  • Five workflows. The pull_request_target one, pr-size.yml, only labels pull requests by size with actions/github-script and does not check out code. No third-party actions. Licence and contributing guide present; no security policy, Dependabot or CodeQL.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time code1 npm lifecycle script. 1 installer script
Committed binariesNone.
CI workflows5 workflows. 1 uses pull_request_target, none check out the pull request head. No third-party actions.
Network hosts40 distinct hosts referenced from source; most often github.com, a.com, generativelanguage.googleapis.com, b.com. 2 URLs to a bare IP address, listed under the raw findings.
Known vulnerabilities46 advisories across 1,543 pinned packages: 1 critical, 19 high, 20 moderate, 6 low. docs/package-lock.json: 492 packages, 26 advisories; package-lock.json: 1,290 packages, 21 advisories.
Project hygieneHas licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

URLs to bare IP addresses (2)
WhereRuleMatch
src/modelManagement/providers/isSelfHostedProvider.test.ts:37ip-literal-url"http://172.32.0.1",
src/modelManagement/providers/isSelfHostedProvider.test.ts:38ip-literal-url"http://11.0.0.1",
npm lifecycle scripts (1)
  • package.json prepare: husky
Installer scripts (1)
Worst known vulnerabilities (24 of 46)
AdvisorySeverityPackageSummary
GHSA-26w7-cxv4-gfx2criticalastro@7.2.4Astro: Remote code execution through AVIF image optimization
GHSA-j22f-vq7h-c4qmhighdevalue@5.9.1devalue: `stringify`/`uneval` serialize shared memory
GHSA-mcm9-63f2-9j32highdevalue@5.9.1devalue: Repeated primitive strings cause quadratic expansion in uneval
GHSA-r9w8-h9r3-54w4highdevalue@5.9.1devalue: Custom ArrayBuffer revivers can bypass typed-array allocation validation
GHSA-x5rw-q4pp-hg5ghighdevalue@5.9.1devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise
GHSA-ch52-4w7c-c8xphighhttp-cache-semantics@4.2.0http-cache-semantics max-stale handling can disclose cross-user cached responses
GHSA-2883-xcg3-v3hhhighjs-yaml@4.3.1js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
GHSA-rgj7-g3m4-5g8chighsharp@0.35.3sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
GHSA-w27v-7q3p-w38rhighsvgo@4.0.2SVGO: removeScripts allows executable links through namespace and control-character bypasses
GHSA-rfgv-xxqx-mfg5highundici@8.10.0undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
GHSA-vp8m-p9jh-q5pmhighundici@8.10.0undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
GHSA-w293-vg96-wgc3highundici@8.10.0undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
GHSA-2883-xcg3-v3hhhighjs-yaml@3.15.1js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
GHSA-6j4f-fj2g-mc7phighbrace-expansion@5.0.9brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@5.0.9brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-6j4f-fj2g-mc7phighbrace-expansion@1.1.18brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@1.1.18brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-vfj7-8cjw-p6xmhighbraces@3.0.3braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
GHSA-6j4f-fj2g-mc7phighbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-qhr7-859c-m2p7highbrace-expansion@2.1.4brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-4q55-j62x-fr9hmoderatedevalue@5.9.1devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion
GHSA-9rgm-9g3h-6x36moderatedevalue@5.9.1Svelte devalue: DoS via malformed input
GHSA-hx4r-w6wj-j8fgmoderatedevalue@5.9.1devalue: Residual sparse-array CPU amplification in uneval
GHSA-4vpr-x523-8j87moderatesvgo@4.0.2SVGO: removeScripts incompletely sanitizes executable HTML in SVG foreignObject elements
Workflows worth a look

By the numbers

Stars7,779
Forks750
Contributors49
Commits1,343
Open issues75
Open pull requests71
Releases129
Latest release4.0.13
LicenceAGPL-3.0
Main languageTypeScript
Project age3 years
Last pushOct 3, 2026
Tracked files1,635
Lines of code271.5K
Checkout size27 MB

Lines by language: TypeScript 252K, Markdown 11.6K, JavaScript 4,353, Shell 1,115, CSS 1,107, YAML 752.

Questions

Is Copilot for Obsidian free?

The plugin is AGPL-3.0 and free with your own API key, a local model, or an existing Claude Code or Codex account. That covers single-agent chats, Projects, skills, commands, Quick Chat and Quick Ask. A paid plan adds Copilot-hosted models, cloud-backed tools and multi-agent requests, with a 14-day refund.

Does Copilot send my notes to Brevilabs?

Not on the free path. The README says messages and note context go only to the provider, local endpoint or CLI agent you configure. Brevilabs receives request content only when you use one of its hosted features, and says it processes that content transiently without keeping it or training on it.

Does Copilot for Obsidian work on mobile?

Partly. The agent features run local processes, so they are desktop only. Quick Chat, custom commands and Quick Ask work on mobile.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.