A lightweight, self-hosted MCP server over a folder of markdown files. Exposes vault operations as MCP tools for note management, searching, tagging, and linking.
Vellum demonstrates solid tool design with 23 well-named, verb-prefixed tools (list_, read_, write_, search_, etc.). All tools have descriptions (avg ~100 chars, within baseline 34-392 range). Input schemas are present and typed for all tools. Tool annotations (readOnlyHint, destructiveHint, idempotentHint) are correctly applied. However, parameter descriptions are sparse, many lack detail on format, constraints, or valid values. Output schemas are not documented in the source. Error handling guidance is minimal. The curator and sharing tools are feature-gated but lack explicit permission declarations.
Add tags to a note's frontmatter.
Append markdown content to the end of a note.
Delete a note from the vault.
Find notes in the inbox that haven't been modified recently. Curator tool (requires VELLUM_CURATOR flag).
Find notes with no backlinks and no forward links (isolated notes). Curator tool (requires VELLUM_CURATOR flag).
Find notes without any tags. Curator tool (requires VELLUM_CURATOR flag).
Get backlinks (notes linking to this note) and forward links (notes this note links to).
Parameter descriptions lack format/constraint details. E.g., 'path' params don't specify vault-relative format, 'status' enum values aren't listed in descriptions, 'max_results' lacks min/max bounds. LLMs cannot infer constraints from names alone.
Output schemas are not documented in source code. Tool descriptions state what is returned (e.g., 'Returns the resolved path and content hash') but formal output schema definitions are absent. LLMs cannot plan downstream tool chains without knowing response structure.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 79 | 2025-06-18+ | v2 |
List markdown notes in the vault (optionally recursive).
List all tags in the vault with their note counts.
List tasks (notes with status frontmatter), optionally filtered by status and project.
Move a note to a new path. Directories are created as needed. Backlinks are kept resolving.
Replace a section of a note by heading text. The heading line is kept, only the section content changes.
Prepend markdown content to the beginning of a note.
Read a note: content, frontmatter, tags, links and the content hash used for conflict-safe edits.
Remove tags from a note's frontmatter.
Search notes by text query, tags, or both. Case-, diacritics- and typo-insensitive. Tags act as an AND-filter.
Set the status of a note (task). Valid statuses: backlog, in-progress, done.
Create a public share link for a note. Sharing must be enabled (VELLUM_SHARING=on).
Suggest wikilinks for a note based on content similarity to other notes. Curator tool (requires VELLUM_CURATOR flag).
Suggest vault locations for new content based on existing structure and content similarity. Curator tool (requires VELLUM_CURATOR flag).
Suggest tags for a note based on its content and existing tag usage. Curator tool (requires VELLUM_CURATOR flag).
Revoke a public share link for a note. Sharing must be enabled (VELLUM_SHARING=on).
Write a note to the vault. Without a path, it lands in the inbox with a slug name. Returns the resolved path and content hash.
Curator and sharing tools are feature-gated (VELLUM_CURATOR, VELLUM_SHARING flags) but lack explicit permission declarations in tool definitions. No scope metadata (e.g., 'read:vault', 'write:vault') to guide least-privilege agent configuration.
Error handling lacks recovery guidance. Tool descriptions do not explain what to do on failure (e.g., 'If path not found, try search_notes first'). No categorization of errors as retryable vs. user-fixable.
Destructive operations (delete_note, patch_note) lack confirmation/dry-run support. No pattern to prevent accidental data loss when agents make mistakes.