- No secrets in git.
- No secrets in Obsidian.
- No broad mailbox/workspace scraping.
- No auto-send.
- No external mutation without explicit approval.
- Manual export or read-only scope first.
- One source at a time.
Raw source exports should stay local unless the client approves sharing.
Source notes should preserve:
- source name;
- date;
- original location or link;
- sensitivity;
- whether the content is approved for external use.
MCP config examples in this repo are examples only. Real MCP credentials must live outside git and outside the vault.