← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

Dimensionmcp-server-filesystemRestricted filesystem access for MCPFilesystem MCP ServerSecure local file read/write accessMCPVaultA safe MCP bridge to Obsidian vaults
FMRS46 / 100 · D84 / 100 · B60 / 100 · C
Reliability8 / 2017 / 209 / 20
Security and permissions8 / 2016 / 2013 / 20
Maintenance13 / 2016 / 2010 / 20
Documentation7 / 2017 / 2015 / 20
Setup experience10 / 2018 / 2013 / 20
Best for
  • MCP clients that need controlled local file access
  • Developers who want to explicitly constrain filesystem operations
  • Local assistants that need to work inside explicitly approved directories
  • Individuals and development teams that want path-based data boundaries
  • Users who want to access a local Obsidian vault through multiple MCP clients.
  • Note workflows that need to preserve raw formatting for unmodified frontmatter fields.
  • Knowledge-base users who need local file operations, search, and tag management.
Not for
  • Workflows that require access to unauthorized directories
  • Users seeking a server with documented tool names or broader capabilities
  • Highly sensitive environments that cannot allow model access to local file contents
  • Shared remote file-service use cases
  • Users without an Obsidian vault or local vault directory.
  • Users seeking a remote network service, cloud-hosted service, or non-MCP integration.
  • Users who do not want an AI assistant to access or modify vault content and structure.
Required permissions
  • The server needs file-operation access to the directories listed in allowed-directories
  • SSE and Streamable HTTP modes require use of the configured local port
  • Read access to every local directory listed in the configuration
  • Filesystem write access when write or move tools are enabled
  • Requires Node.js 18 or later.
  • Requires read access to the specified vault; writing, moving, and deleting also require the corresponding write permissions.
  • The server can access allowed `.md`, `.markdown`, `.txt`, `.base`, and `.canvas` files.
  • The AI assistant can see allowed file content, directory structure, and some file metadata.
Risks and side effects
  • An overly broad allowed-directories value may expand the scope of local files that can be exposed or modified
  • When using a local SSE or HTTP endpoint, port and access-scope configuration should be reviewed
  • The source does not specify individual filesystem tools, authentication, or authorization mechanisms
  • Sensitive files inside an allowed directory may enter model context
  • Write and move tools change real files; keep scopes narrow and maintain backups
  • The server provides full read/write access within its security boundaries, so incorrect instructions can modify or delete notes.
  • Vault content, structure, and file metadata may be exposed to AI conversations with access.
  • Permanent deletion may be unrecoverable; back up the vault before write operations.
  • Path filtering does not isolate content, so sensitive data in allowed files remains readable.
Supported clientsClaude Desktop, Cursor, Cline, WindsurfClaude Desktop, Claude Code, OpenCode, Goose Desktop, ChatGPT Desktop, IntelliJ IDEA 2025.1+, Cursor IDE, Windsurf IDE, Ontheia, Microsoft Copilot Studio, OpenAI Codex
Tools0614