mcp-markdown-vault (wirux/mcp-markdown-vault) is an MCP server listed on the M8ven Trust Index. M8ven has not graded it: we have no way to read this server ourselves. No publisher has claimed this listing.
Headless semantic MCP server for Obsidian, Logseq, Dendron, Foam, and any markdown folder. Features built-in hybrid semantic search, surgical AST editing, template scaffolding, zero-config local embeddings, and workflow tracking.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
wirux
Source: Glama · also listed on github_code
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
BODY_LIMIT_BYTES1mb Max JSON request body size for SSE POST /messages.HOST_BIND_ADDRESS127.0.0.1 Bind address for the SSE HTTP server.MCP_AUTH_TOKEN(unset) Bearer token for SSE transport auth. If set, all SSE endpoints require Authorization: Bearer <token>.MCP_TRANSPORT_TYPEsse PORT=3000 VAULT_PATH=/path/to/vault npx @wirux/mcp-markdown-vaultOLLAMA_DIMENSIONS768 Ollama embedding vector dimensionsOLLAMA_MODELnomic-embed-text Ollama embedding model nameOLLAMA_URLset? Ollama reachable? Provider usedVAULT_CONTEXT(deprecated) Deprecated and ignored. Use VAULT_CONTEXT_MODE instead.VAULT_CONTEXT_MODEVAULT_CONTEXT (deprecated) Deprecated and ignored. Use instead.VAULT_PATH/path/to/your/vault markdown-vault-mcpVECTOR_STORE_COLLECTIONmarkdown_vault Qdrant collection name when VECTOR_STORE_URL is set.VECTOR_STORE_RESETfalse Set to true to auto-delete a mismatched vector index on startup and rebuild from scratch.VECTOR_STORE_URL(unset) Set to use Qdrant (e.g. http://localhost:6333). If unset, local persisted flat store is used.PORTTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
5/5 tools missing one or more hints — vault (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); edit (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); view (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +2 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Shell command execution
2 child_process calls — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Dependency freshness
3/13 production deps abandoned (no release in 2+ years): remark-frontmatter@2023-11-20 (2.6y), remark-parse@2023-11-20 (2.6y), remark-stringify@2023-11-20 (2.6y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/wirux-mcp-markdown-vault-1utrtj)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check