Atlas / MCP servers / pvliesdonk / Markdown Vault

Markdown VaultBLOCK

mcp/pvliesdonk/markdown-vault

Generic markdown vault MCP with hybrid search

Verdict
BLOCK
Grade
F
Trust score
39 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/pvliesdonk/markdown-vault-mcp/actions/workflows/ci.yml) [](https://sonarcloud.io/summary/newcode?id=pvliesdonkmarkdown-vault-mcp) [](https://sonarcloud.io/summary/newcode?id=pvliesdonkmarkdown-vault-mcp) [](https://sonarcloud.io/summary/newcode?id=pvliesdonkmarkdown-vault-mcp) [](https://sonarcloud.io/summary/newcode?id=pvliesdonkmarkdown-vault-mcp) [](https://pypi.org/project/markdown-vault-mcp/) [](https://pypi.org/project/markdown-vault-mcp/) [](LICENSE) [](https://github.com/pvliesdonk/markdown-vault-mcp/pkgs/container/markdown-vault-mcp) [](https://pvliesdonk.github.io/markdown-vault-mcp/) [](https://pvliesdonk.github.io/markdown-vault-mcp/latest/llms.

Read from source at commit 0c61c82af626OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add markdown-vault-mcp --env OPENAI_API_KEY=${OPENAI_API_KEY} --env VOYAGE_API_KEY=${VOYAGE_API_KEY} --env MARKDOWN_VAULT_MCP_BEARER_TOKEN=${MARKDOWN_VAULT_MCP_BEARER_TOKEN} --env MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRET=${MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRET} -- uvx markdown-vault-mcp==5.1.0
claude-code (oci)
claude mcp add markdown-vault-mcp:v5.1.0 --env OPENAI_API_KEY=${OPENAI_API_KEY} --env VOYAGE_API_KEY=${VOYAGE_API_KEY} --env MARKDOWN_VAULT_MCP_BEARER_TOKEN=${MARKDOWN_VAULT_MCP_BEARER_TOKEN} --env MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRET=${MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRET} -- docker run -i --rm ghcr.io/pvliesdonk/markdown-vault-mcp:v5.1.0:None
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
_probereadreturn
summarizereadreturn
04

Trust audit

BLOCKgrade F · trust 39/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (4 observation(s))
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
src/markdown_vault_mcp/static/app.src.html:1601
return String(text || '').replace(/^?-{3,}[ \t]*\r?\n[\s\S]*?\r?\n-{3,}[ \t]*\r?\n?/, '');
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/applying-template-updates
.claude/skills/applying-template-updates
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/authoring-issues-prs
.claude/skills/authoring-issues-prs
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/config-contract
.claude/skills/config-contract
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/designing-tool-outcomes
.claude/skills/designing-tool-outcomes
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/logging-standard
.claude/skills/logging-standard
Why it matters. link not followed
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/gen_config_surface.py:254
module = importlib.import_module(f"{python_module}.config")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/gen_reference.py:885
server_mod = importlib.import_module(f"{module}.server")
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/gen_reference.py:886
cli_mod = importlib.import_module(f"{module}.cli")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:85
CMD python -c "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/health', timeout=2).close()"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/markdown_vault_mcp/static/spa/views/note.js:31
return String(text || '').replace(/^?-{3,}[ \t]*\r?\n[\s\S]*?\r?\n-{3,}[ \t]*\r?\n?/, '');
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_git.py:971
secret = "ghp_supersecret_token_xyz"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_git.py:1006
secret = "ghp_push_secret_abc123"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_git.py:1076
secret = "ghp_startup_token_999"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_webhooks.py:59
SECRET = "test-webhook-secret-xyz"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.copier-answers.yml
.copier-answers.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.copier-seeded-changes.md
.copier-seeded-changes.md
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.copier-template-drift.md
.copier-template-drift.md
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_docstrings.py:29
module = importlib.import_module(module_name)
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_prompts.py:306
assert "exec(" not in source
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_published_examples.py:100
exec(compile(code, where, "exec"), namespace)  # the published example is the test
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/conftest.py:115
seed = int(hashlib.md5(text.encode()).hexdigest(), 16) % 2**31
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/test_git.py:3554
blob_id = hashlib.sha1(header + body, usedforsecurity=False).hexdigest()

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 0c61c82af626full audit observations/trust-audit/mcp-server/pvliesdonk__markdown-vault.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-090c61c82af626BLOCKF39first audit
06

Questions

What is the Markdown Vault MCP server?

Generic markdown vault MCP with hybrid search

What tools does Markdown Vault expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Markdown Vault safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (39/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Markdown Vault need?

It reads GITHUB_TOKEN, MARKDOWN_VAULT_MCP_BEARER_TOKEN, MARKDOWN_VAULT_MCP_OIDC_CLIENT_SECRET, MARKDOWN_VAULT_MCP_OIDC_JWT_SIGNING_KEY, OPENAI_API_KEY and VOYAGE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Markdown Vault run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as markdown-vault-mcp.

How current is this page?

The grade is for one exact copy of the source (0c61c82af626), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement