markdown-vault-mcp

MCPcommunity
v5.0.0io.github.pvliesdonkUnknownUpdated 7d agoGitHub

Generic markdown vault MCP with hybrid search

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
34GitHub stars
14Forks
7d agoLast update
Reads these credentials
  • OPENAI_API_KEYAPI keyoptional
  • VOYAGE_API_KEYAPI keyoptional

    Voyage AI API key for the voyage embedding provider. Bare (not MARKDOWN_VAULT_MCP_-prefixed), matching the OPENAI_API_KEY / OLLAMA_HOST convention. Setting it never auto-selects the provider; choose…

  • MARKDOWN_VAULT_MCP_GIT_TOKENAPI keyoptional

    Token/password for HTTPS git auth; remotes must be HTTPS when set.

  • MARKDOWN_VAULT_MCP_GITHUB_WEBHOOK_SECRETAPI keyoptional

    Shared secret for the GitHub push-event webhook; when set, mounts POST /github-webhook on HTTP/SSE transports to trigger an immediate pull + reindex on push events.

  • MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SIGNING_TOKENAPI keyoptional

    Signing token for the GitLab push-event webhook (GitLab 19.0+); when set, mounts POST /gitlab-webhook on HTTP/SSE transports to trigger an immediate pull + reindex on push events. GitLab generates…

  • MARKDOWN_VAULT_MCP_GITLAB_WEBHOOK_SECRET_TOKENAPI keyoptional

    Secret token for the GitLab push-event webhook, GitLab's plain-text form and the only one below 19.0; also mounts POST /gitlab-webhook. It proves nothing about the body and cannot expire, so prefer…

  • MARKDOWN_VAULT_MCP_SUMMARIZE_OPENAI_API_KEYAPI keyoptional

    API key for the OpenAI-compatible summarize endpoint; the bare OPENAI_API_KEY is honoured as a fallback. Unset works for keyless local endpoints (Ollama).

  • MARKDOWN_VAULT_MCP_BEARER_TOKENAPI keyoptional

    Single shared bearer token; enables bearer auth unless `bearer_tokens_file` is set, which takes precedence.

  • MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRETOAuth appoptional

    OIDC client secret registered with the provider.

  • MARKDOWN_VAULT_MCP_OIDC_JWT_SIGNING_KEYAPI keyoptional

    Signing key for issued tokens; used in oidc-proxy mode only. When unset, the key is derived deterministically from `oidc_client_secret`, so tokens survive a restart. Rotating that secret then…

  • MARKDOWN_VAULT_MCP_OIDC_VERIFY_ACCESS_TOKENAPI keyoptional

    Validate the access token instead of the id token.

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
Authorio.github.pvliesdonk
LicenseUnknown
Version5.0.0
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: run `forge publish` from the repo to claim ownership
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface—
Security scan✓ CleanvHEAD · 1mo agoHow well does this scan work?
EvalsNone
IndexedJun 17, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

No tool declarations found in the source1mo ago

Forge read 7 source files from the published package tarball and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.

About

Generic markdown vault MCP with hybrid search

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

Forge's dependency resolver reads npm metadata only, so this PyPI package has no resolved tree. That is a gap in coverage, not a clean bill of health.

Topics

Related in documents & pdfs