Everyone is connecting Obsidian to Claude via MCP. Nobody is asking what's actually in their vault.
API keys in old notes. Connection strings. Client names. Tokens saved "temporarily." All of it now accessible in a single AI conversation.
The risk ...
If you're building AI agents and trying to sell into enterprise, you've probably hit the wall: the 40-page security questionnaire that asks about logging, access control, data residency, and adversarial testing - none of which you thought about while...