Agent skill

Webobsidian

by xnohat in xnohat/webobsidian

Read, write, search, and manage notes in a WebObsidian vault through its Agent REST API (/api/v1).

MITAuto-check passedMarketing & SEO

Install Webobsidian

skills CLI
$ npx skills add xnohat/webobsidian --skill webobsidian -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xnohat/webobsidian webobsidian --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xnohat/webobsidian.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/agent-skill/webobsidian .claude/skills/webobsidian && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
webobsidian
GitHub stars
268
Token cost
~2.1k tokens
SKILL.md length
538 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Read, write, search, and manage notes in a WebObsidian vault through its Agent REST API (/api/v1).

  • Works in 3 steps: Ask the user for their WebObsidian base… → Save it (never echo the key back) → Verify with the health + an…
  • The user asks to find
  • SKILL.md covers Credentials (read these first,…, Sanity check, Authentication and Endpoint reference, plus 5 more sections
  • Calls curl and python3; needs API_KEY

What it does

Webobsidian is an agent skill from xnohat/webobsidian. Read, write, search, and manage notes in a WebObsidian vault through its Agent REST API (/api/v1). Use whenever the user asks to find, read, create, update, append to, or delete notes in their WebObsidian / Obsidian vault, list tags, get backlinks, or run a vault search. Credentials (base URL + API key) are stored in ~/.webobsidian/credentials.json; if missing, ask the user for them and save them before making requests.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Marketing & SEO, covering Link building and REST APIs. It works with Obsidian. The repository describes itself as: Web based Obsidian Notes App. The licence is MIT.

When your agent uses it

  • The user asks to find
  • Delete notes in their WebObsidian / Obsidian vault
  • Run a vault search

Example prompts

  • “/webobsidian”

Requirements

  • Python 3
  • A credential in API_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Ask the user for their WebObsidian base URL (e.g. https://notes.example.com or
  2. Save it (never echo the key back)
  3. Verify with the health + an authenticated call, then proceed.

What it can do on your machine

Read from SKILL.md and the folder at commit c41967a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Webobsidian loads about 2.1k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 538 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from xnohat/webobsidian at commit c41967a, republished under its MIT licence (© xnohat). 538 words, ~2,057 tokens.

Download SKILL.mdSave it as .claude/skills/webobsidian/SKILL.md (or your agent's skills folder).
name
webobsidian
description
Read, write, search, and manage notes in a WebObsidian vault through its Agent REST API (/api/v1). Use whenever the user asks to find, read, create, update, append to, or delete notes in their WebObsidian / Obsidian vault, list tags, get backlinks, or run a vault search. Credentials (base URL + API key) are stored in ~/.webobsidian/credentials.json; if missing, ask the user for them and save them before making requests.

WebObsidian Agent skill

Operate a WebObsidian vault over its Agent REST API at /api/v1. Everything is a plain HTTP call authenticated with an API key.

Credentials (read these first, every session)

Credentials live in ~/.webobsidian/credentials.json:

json
{ "baseUrl": "https://your-webobsidian.example.com", "apiKey": "wok_xxxxxxxx" }

Before the first request in a session, load them into shell variables:

bash
BASE=$(python3 -c 'import json,os;print(json.load(open(os.path.expanduser("~/.webobsidian/credentials.json")))["baseUrl"].rstrip("/"))')
KEY=$(python3 -c 'import json,os;print(json.load(open(os.path.expanduser("~/.webobsidian/credentials.json")))["apiKey"])')

If ~/.webobsidian/credentials.json does not exist or a call returns 401:

  1. Ask the user for their WebObsidian base URL (e.g. https://notes.example.com or http://host:8787) and their API key. They create the key in the app at Settings → API Keys (choose scopes read / write / search). Keys look like wok_….
  2. Save it (never echo the key back):
    bash
    mkdir -p ~/.webobsidian && chmod 700 ~/.webobsidian
    cat > ~/.webobsidian/credentials.json <<JSON
    { "baseUrl": "<BASE_URL>", "apiKey": "<API_KEY>" }
    JSON
    chmod 600 ~/.webobsidian/credentials.json
  3. Verify with the health + an authenticated call, then proceed.

Security rules: never print, log, or commit the API key. Never write it into vault notes. If a command would expose it, redact it.

Sanity check

bash
curl -s "$BASE/api/v1/health"                          # liveness, no auth
curl -s -H "X-API-Key: $KEY" "$BASE/api/v1/tags" | head # confirms the key works

Authentication

Send the key as a header on every /api/v1 request (either form works):

X-API-Key: wok_xxx
Authorization: Bearer wok_xxx

Scopes per key: read, write, search. A call outside the key's scope returns 403. Rate-limited (default 120 req/min/key) → 429 when exceeded; back off and retry.

Endpoint reference

All {path} values are vault-relative and must be URL-encoded (curl -G --data-urlencode for queries; encode /-containing paths in the URL path, e.g. Notes/Ideas.md → Notes%2FIdeas.md is accepted, plain Notes/Ideas.md also works).

MethodPathScopeDescription
GET/api/v1/health–Liveness check
GET/api/v1/notes?offset=&limit=readList markdown notes (paginated)
GET/api/v1/notes/{path}readRead a note + parsed metadata
PUT/api/v1/notes/{path}writeCreate / overwrite a note — body {"content":"..."}
PATCH/api/v1/notes/{path}writeAppend — body {"append":"..."}
DELETE/api/v1/notes/{path}writeMove note to trash
GET/api/v1/search?q=&limit=searchQMD search (fielded: tag:, path:, title:)
GET/api/v1/backlinks?path=readNotes linking to a path
GET/api/v1/tagsreadAll tags with counts

Recipes

bash
# List 10 notes
curl -s -H "X-API-Key: $KEY" "$BASE/api/v1/notes?limit=10"

# Read a note (URL-encode the path's query value if it has spaces/slashes)
curl -s -H "X-API-Key: $KEY" "$BASE/api/v1/notes/Welcome.md"

# Create or overwrite a note
curl -s -X PUT -H "X-API-Key: $KEY" -H 'Content-Type: application/json' \
  -d '{"content":"# Title\n\nBody written by the agent."}' \
  "$BASE/api/v1/notes/Agent/Generated.md"

# Append to a note (creates it if missing)
curl -s -X PATCH -H "X-API-Key: $KEY" -H 'Content-Type: application/json' \
  -d '{"append":"\n- another bullet"}' \
  "$BASE/api/v1/notes/Agent/Generated.md"

# Delete a note (→ trash)
curl -s -X DELETE -H "X-API-Key: $KEY" "$BASE/api/v1/notes/Agent/Generated.md"

# Full-text search (fielded queries supported)
curl -s -G -H "X-API-Key: $KEY" "$BASE/api/v1/search" \
  --data-urlencode "q=tag:idea graph" --data-urlencode "limit=5"

# Backlinks for a note
curl -s -G -H "X-API-Key: $KEY" "$BASE/api/v1/backlinks" --data-urlencode "path=Welcome.md"

# All tags with counts
curl -s -H "X-API-Key: $KEY" "$BASE/api/v1/tags"

Response shapes

jsonc
// GET /api/v1/notes/{path}
{ "path": "Welcome.md", "content": "...", "title": "Welcome",
  "frontmatter": { "tags": ["welcome"] }, "tags": ["welcome"], "links": ["Notes/Ideas"] }

// GET /api/v1/search
{ "query": "graph", "hits": [
  { "path": "Notes/Ideas.md", "title": "Ideas", "score": 4.2, "tags": ["idea"], "snippet": "…" } ] }

Obsidian Flavored Markdown (write notes in this dialect)

The vault is a real Obsidian vault — the user also opens these files in the Obsidian app, so write Obsidian Flavored Markdown, not plain Markdown. Use [[wikilinks]] for links between vault notes (Obsidian tracks renames); use [text](url) only for external URLs.

Show full SKILL.md (208 more words)Show less
Properties (YAML frontmatter)

At the very top of the note, between --- fences. Default keys: tags, aliases, cssclasses. Preserve existing frontmatter on overwrite.

markdown
---
title: My Note
date: 2024-01-15
tags:
  - project
  - active
aliases:
  - Alternative Name
---
markdown
[[Note Name]]                 Link to a note
[[Note Name|Display Text]]    Custom display text
[[Note Name#Heading]]         Link to a heading
[[Note Name#^block-id]]       Link to a block
[[#Heading in same note]]     Same-note link
Block references

Append ^block-id to a paragraph; for lists/quotes put the id on its own line after the block.

markdown
This paragraph can be linked to. ^my-block-id
markdown
![[Note Name]]                Embed a whole note
![[Note Name#Heading]]        Embed one section
![[image.png]]                Embed an image
![[image.png|300]]            Embed with width
![[document.pdf#page=3]]      Embed a PDF page
Callouts
markdown
> [!note]
> Basic callout.

> [!warning] Custom Title
> Callout with a custom title.

> [!faq]- Collapsed by default
> Foldable callout (`-` starts collapsed, `+` starts expanded).

Common types: note, tip, info, warning, danger, success, failure, question, example, quote, bug, abstract, todo.

Tags
markdown
#tag            inline tag
#nested/tag     hierarchical tag

Letters, digits (not first char), _, -, /. Tags also go in frontmatter tags:.

Tasks
markdown
- [ ] Pending task
- [x] Completed task
Other syntax
markdown
==highlight==   **bold**   *italic*
Footnote[^1].          [^1]: Footnote text.       Inline footnote.^[Inline text.]
Visible %%hidden inline comment%% text.            $e^{i\pi}+1=0$  (inline math)
markdown
$$\frac{a}{b} = c$$         (block math, KaTeX)

```mermaid
graph TD
  A --> B
```

Editing rules

  • Prefer PATCH append over PUT when only adding content, so you don't clobber a note.
  • Read before you overwrite an existing note unless the user explicitly wants a fresh replace; preserve its frontmatter and formatting.
  • Paths are case-sensitive and notes must include the .md extension.
  • When you reference another note, link it ([[Other Note]]) instead of writing a bare name — it keeps the graph and backlinks intact.

Troubleshooting

  • 401 → key missing/invalid → re-run the credentials flow above.
  • 403 → the key lacks the required scope → ask the user to create a key with the needed scope (read/write/search).
  • 404 on a note → wrong path/casing, or it's in .trash.
  • 429 → rate limited → wait and retry.
  • Connection refused / TLS error → confirm the base URL and that the server is reachable.

© xnohat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/agent-skill/webobsidian of xnohat/webobsidian.

Open the folder on GitHubat commit c41967a

Compare with similar skills

Webobsidian next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Webobsidian compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Webobsidian this skillxnohat/webobsidian268—~2.1kAutomated safety check: PassMIT
Obsidian Layout AdjustmentAr9av/obsidian-wiki3.5k—~2.5kAutomated safety check: PassMIT
Conducty Contextrobertbarclayy/conducty176—~3.7kAutomated safety check: PassMIT
Compressiurykrieger/claude-bedrock1051 repos~9.9kAutomated safety check: WarnMIT
Obsidiansteipete/agent-scripts7.3k—~916Automated safety check: PassMIT
Obsidian Official CLIhashgraph-online/awesome-codex-plugins1.3k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Obsidian Layout Adjustment

    Ar9av/obsidian-wiki

    Adjust the user's Obsidian visual layout with CSS snippets. An agent skill from Ar9av/obsidian-wiki.

    3.5k GitHub stars~2.5k tokensUpdated yesterday
    Marketing & SEOAuto-check passed
  • Conducty Context

    robertbarclayy/conducty

    Ingest a project directory into the Obsidian vault as a linked context sub-graph — Architecture, Conventions, Invariants, Hotspots, Tests, Glossary, plus per-bounded-context module notes.

    176 GitHub stars~3.7k tokensUpdated 3 mo ago
    Marketing & SEOAuto-check passed
  • Compress

    iurykrieger/claude-bedrock

    Vault alignment engine. An agent skill from iurykrieger/claude-bedrock.

    105 GitHub starsUsed in 1 repo~9.9k tokens
    Marketing & SEOAuto-check: warnings
  • Obsidian

    steipete/agent-scripts

    Obsidian vault: search/read/write notes, backlinks, Bases, Canvas.

    7.3k GitHub stars~916 tokensUpdated 4 days ago
    Marketing & SEOAuto-check passed
  • Obsidian Official CLI

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when the user wants local Obsidian note or metadata work done primarily through documented official desktop obsidian CLI commands, with limited local vault filesystem support…

    1.3k GitHub stars~2.2k tokensUpdated today
    Marketing & SEOAuto-check passed
  • Links

    thoreinstein/gemini-obsidian

    A skill your agent uses when the user wants to explore connections between notes, see what links to or from a note, or says "links", "backlinks", "connections", or "graph".

    102 GitHub stars~232 tokensUpdated 2 mo ago
    Marketing & SEOAuto-check passed

Works with

Questions about Webobsidian

What does Webobsidian do?

Read, write, search, and manage notes in a WebObsidian vault through its Agent REST API (/api/v1). Webobsidian is an agent skill from xnohat/webobsidian. Read, write, search, and manage notes in a WebObsidian vault through its Agent REST API (/api/v1).

When should I use Webobsidian?

Webobsidian fits situations like: the user asks to find; delete notes in their WebObsidian / Obsidian vault; run a vault search.

How do I install Webobsidian in Claude Code?

Run `npx skills add xnohat/webobsidian --skill webobsidian -a claude-code`. Or copy the skill folder (docs/agent-skill/webobsidian in xnohat/webobsidian) into .claude/skills/webobsidian in your project. Claude Code loads it when a task matches its description.

How do I install Webobsidian in Codex?

Run `npx skills add xnohat/webobsidian --skill webobsidian -a codex`. Or copy the skill folder (docs/agent-skill/webobsidian in xnohat/webobsidian) into .agents/skills/webobsidian in your project. Codex loads it when a task matches its description.

Can I use Webobsidian in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xnohat/webobsidian --skill webobsidian -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/webobsidian, .gemini/skills/webobsidian, .github/skills/webobsidian and .opencode/skills/webobsidian in your project.

What does Webobsidian need to run?

Going by SKILL.md and its folder, Webobsidian needs the command-line tools its instructions call (curl and python3) and credentials named API_KEY. Our summary lists: Python 3; A credential in API_KEY.

Does Webobsidian access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Webobsidian safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Webobsidian use?

Webobsidian is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Webobsidian use?

About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Webobsidian?

Skills that share tags, products or a category with Webobsidian: Obsidian Layout Adjustment (Ar9av/obsidian-wiki, 3.5k stars), Conducty Context (robertbarclayy/conducty, 176 stars), Compress (iurykrieger/claude-bedrock, 105 stars) and Obsidian (steipete/agent-scripts, 7.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Webobsidian?

xnohat (a GitHub user) maintains it in xnohat/webobsidian, which has 268 GitHub stars. The repository was last updated on June 27, 2026.

Source: xnohat/webobsidian on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.