Vault RAG MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| VAULT_ROOT | Yes | The single allowlisted Markdown root | |
| VAULT_AUDIT_PATH | No | JSONL audit location (default: OS state directory) | |
| VAULT_INDEX_PATH | No | SQLite index location (default: OS cache directory) | |
| VAULT_MAX_RESULTS | No | Hard cap on search results | 10 |
| VAULT_EXCLUDE_DIRS | No | Directory names skipped recursively | .git,.obsidian,.trash,.venv,__pycache__,node_modules |
| VAULT_MAX_FILE_BYTES | No | Per-note indexing and read limit | 1000000 |
| VAULT_MAX_READ_CHARS | No | Maximum text returned by one read | 20000 |
| VAULT_EMBEDDING_MODEL | No | Local Sentence Transformers model | intfloat/multilingual-e5-small |
| VAULT_AUDIT_QUERY_TEXT | No | Store raw searches instead of hashes | false |
| VAULT_EMBEDDING_DEVICE | No | Torch device used for embeddings | cpu |
| VAULT_MODEL_LOCAL_FILES_ONLY | No | Refuse model-network access; enable after the model is cached | false |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| vault_statusA | Show index readiness and the server's read-only security boundary. |
| refresh_vault_indexB | Incrementally index changed Markdown notes. This never modifies source notes. |
| search_vaultA | Find semantically relevant passages with source paths and exact line ranges. |
| read_vault_noteA | Read a bounded line range from an allowlisted Markdown note. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool has a clearly distinct responsibility: status, indexing, search, and reading. There is no overlap or ambiguity between actions an agent could confuse.
Most tools follow a verb_noun pattern (refresh_vault_index, search_vault, read_vault_note). vault_status deviates slightly by using a noun phrase instead of a verb prefix, but the naming style is otherwise uniform and readable.
Four tools is a well-scoped size for a focused RAG-over-vault server. Each tool covers a necessary part of the workflow without redundancy or bloat.
For a read-only RAG server, the set covers the full lifecycle: checking index health, refreshing the index, searching semantically, and reading source passages. No obvious missing operations are needed to accomplish its stated purpose.