Generic markdown vault MCP with hybrid search
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
OPENAI_API_KEYAPI keyoptionalVOYAGE_API_KEYAPI keyoptionalVoyage AI API key for the voyage embedding provider. Bare (not MARKDOWN_VAULT_MCP_-prefixed), matching the OPENAI_API_KEY / OLLAMA_HOST convention. Setting it never auto-selects the provider; choose…
MARKDOWN_VAULT_MCP_GIT_TOKENAPI keyoptionalToken/password for HTTPS git auth; remotes must be HTTPS when set.
MARKDOWN_VAULT_MCP_GITHUB_WEBHOOK_SECRETAPI keyoptionalShared secret for the GitHub push-event webhook; when set, mounts POST /github-webhook on HTTP/SSE transports to trigger an immediate pull + reindex on push events.
MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SIGNING_TOKENAPI keyoptionalSigning token for the GitLab push-event webhook (GitLab 19.0+); when set, mounts POST /gitlab-webhook on HTTP/SSE transports to trigger an immediate pull + reindex on push events. GitLab generates…
MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SECRET_TOKENAPI keyoptionalSecret token for the GitLab push-event webhook, GitLab's plain-text form and the only one below 19.0; also mounts POST /gitlab-webhook. It proves nothing about the body and cannot expire, so prefer…
MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_API_KEYAPI keyoptionalAPI key for the OpenAI-compatible summarize endpoint; the bare OPENAI_API_KEY is honoured as a fallback. Unset works for keyless local endpoints (Ollama).
MARKDOWN_VAULT_MCP_BEARER_TOKENAPI keyoptionalSingle shared bearer token; enables bearer auth unless `bearer_tokens_file` is set, which takes precedence.
MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRETOAuth appoptionalOIDC client secret registered with the provider.
MARKDOWN_VAULT_MCP_OIDC_JWT_SIGNING_KEYAPI keyoptionalSigning key for issued tokens; used in oidc-proxy mode only. When unset, the key is derived deterministically from `oidc_client_secret`, so tokens survive a restart. Rotating that secret then…
MARKDOWN_VAULT_MCP_OIDC_VERIFY_ACCESS_TOKENAPI keyoptionalValidate the access token instead of the id token.
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge read 7 source files from the published package tarball and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.
Generic markdown vault MCP with hybrid search
Forge's dependency resolver reads npm metadata only, so this PyPI package has no resolved tree. That is a gap in coverage, not a clean bill of health.