A secure MCP server providing filesystem tools scoped to a Personal vault, with built-in OAuth 2.1 authorization and JWT token validation.
Strong foundation with 13 well-named tools following verb_noun convention (read_file, write_file, search_content). All tools have descriptions (avg 150 chars, within 10-1024 baseline). Input schemas present with parameter descriptions. Key gaps: no output schemas documented, missing error recovery guidance, no pagination for search_content results, and destructive operations (delete_file) lack confirmation patterns. Tool composition is clean (single responsibility), but error messages lack actionable recovery hints.
Create a directory (and any missing parent directories) in the vault.
Delete a file or directory (recursively) from the vault. Disabled by default; enable with AllowDelete=true.
Return a recursive JSON tree of a directory's contents. Bounded by the server's max-results setting.
Edit a file by finding and replacing exact text. Each edit is a single find/replace pair; multiple edits are applied in order.
Return metadata for a file or directory: type, size, and created/modified timestamps (UTC).
Return the directories these tools are permitted to access. Everything is confined to the vault root.
Output schemas not documented. Tools return JSON or text but LLMs cannot infer field structure (e.g., directory_tree returns nested objects, search_content returns line numbers + snippets). LLMs must guess what fields exist, risking extraction errors.
search_content lacks pagination. No limit parameter or result count cap documented. Large vaults could return thousands of matches, exhausting context window. Baseline requires pagination for list-returning tools.
delete_file (destructive operation) has no confirmation or dry-run pattern. Agents can permanently delete vault contents without a safety gate. Baseline requires confirmation-request for irreversible operations.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 79 | 2026-07-28+ | v2 |
List the immediate contents of a directory. Each entry is prefixed with [DIR] or [FILE].
Move or rename a file or directory within the vault.
Read the full text contents of a file in the vault. The path is relative to the vault root.
Read several files at once. Each file's contents are returned prefixed by its path; an error on one file is reported inline and does not abort the rest.
Full-text search across the vault: return files containing the query string, with matching line numbers and a snippet. Case-insensitive. Ideal for finding notes by their content.
Recursively find files and folders whose name matches a glob pattern (case-insensitive), e.g. '*.md' or 'meeting-*'. Returns matching vault-relative paths.
Write text to a file in the vault, creating it if it does not exist. Overwrites the entire file.
Error messages lack recovery guidance. Code throws FileNotFoundException, DirectoryNotFoundException, InvalidOperationException but does not suggest next steps (e.g., 'File not found. Try search_files() to locate it'). Baseline requires actionable error responses.
edit_file requires exact oldText match ('Must occur exactly once in the file'). No guidance on how LLM should handle partial matches, whitespace variations, or multi-line text. Constraint is strict but underdocumented.