← Back to directory
COMPARE UP TO 4 SERVERS

Compare MCP servers

Compare scores, permissions, risks, and fit in one decision-focused table.

DimensionAdeuSafe Word track changes for LLM editing.Filesystem MCP ServerSecure local file read/write accessVault Cortex MCP ServerStandalone MCP server for Obsidian vaults: hybrid search, notes & files, structured memory, tasks, OAuth 2.1.
FMRS55 / 100 · C84 / 100 · B79 / 100 · B
Reliability7 / 2017 / 2012 / 20
Security and permissions9 / 2016 / 2018 / 20
Maintenance12 / 2016 / 2015 / 20
Documentation13 / 2017 / 2019 / 20
Setup experience14 / 2018 / 2015 / 20
Best for
  • Legal-tech teams that need Word Track Changes and existing formatting preserved
  • AI-agent workflows operating on local DOCX files
  • Developers integrating document processing through the Python or TypeScript SDKs
  • Local assistants that need to work inside explicitly approved directories
  • Individuals and development teams that want path-based data boundaries
  • Serious Obsidian users who want AI agents reading and writing their vault
  • Users wanting self-hosted, plugin-free operation with no external APIs
  • Mobile/multi-device workflows accessing the vault remotely
  • Security-conscious users (OAuth 2.1, atomic writes, container hardening)
Not for
  • Simple DOCX generation from scratch
  • Plain-text editing where Word redlining and XML preservation are unnecessary
  • Users seeking Adeu Cloud email-fetching features without connecting to Adeu Cloud
  • Highly sensitive environments that cannot allow model access to local file contents
  • Shared remote file-service use cases
  • Users unwilling to run Docker or self-host a server
  • Non-Obsidian note tools (Notion, Logseq, etc.)
  • Scenarios requiring only a stdio local process without an HTTP server
  • Remote multi-device sync without an Obsidian Sync subscription (the remote image requires one)
Required permissions
  • Read access to user-selected DOCX files
  • Write access to save edited or finalized documents
  • Windows, Microsoft Word, and the Python backend for live Word integration
  • The selected LLM provider may process document text read by the agent
  • Read access to every local directory listed in the configuration
  • Filesystem write access when write or move tools are enabled
  • Read/write access to the Obsidian vault folder (bind mount /vault, rw)
  • Persistent /data volume (search index, OAuth token DB, logs)
  • MCP_AUTH_TOKEN as Bearer token (also the JWT signing key)
  • Obsidian Sync token for headless sync in remote mode
  • Local download of embedding/reranker models (~45MB total), no external API calls
Risks and side effects
  • Broad or ambiguous matches can produce unintended edits; the engine blocks ambiguous matches and invalid structural changes
  • AI-generated edits may still conflict with legal or business intent and require human review
  • Document contents are processed by the chosen LLM provider, so sensitive files require policy review
  • Finalization can change metadata and editing protection, so the target file should be confirmed first
  • Sensitive files inside an allowed directory may enter model context
  • Write and move tools change real files; keep scopes narrow and maintain backups
  • The server can read and write personal notes — guard MCP_AUTH_TOKEN carefully; leaking it exposes the whole vault
  • Writes to real note files; despite atomic writes and protected paths, misconfiguration can alter data
  • OAuth token DB lives on the /data volume; container compromise could expose valid sessions
  • Remote deployments expose a public port — set PUBLIC_URL and reverse proxy correctly
  • The remote image bundles proprietary obsidian-headless (not MIT-licensed); requires an active Obsidian Sync subscription
Supported clientsClaude Desktop, Gemini CLI, Claude Code, Cursor, Windsurf, VS Code CopilotClaude Desktop, Cursor, Cline, WindsurfClaude Code, Claude Desktop, claude.ai, Cursor, OpenCode, MCP Inspector
Tools3630