Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | Codebase MemoryMCP100 Selected | MCPVault for ObsidianMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | Community implementation io.github.DeusData · Publisher source ↗ | Community implementation BitBonsai · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 14, 2026 Package: Aug 14, 2026 | Repo: Aug 13, 2026 Package: Aug 9, 2026 |
| Popularity evidence | ||
| GitHub stars | 38,935 GitHub stars · checked 2026-08-14T18:46:26.000Z | 1,613 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| 30-day package downloads | 28,015 30-day package downloads · checked 2026-08-14T18:46:26.000Z | 64,139 30-day package downloads · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | No authentication or API key is documented for local stdio. CBM_ALLOWED_ROOT is an optional filesystem containment control; no containment is imposed when it is unset. | None at the local stdio layer. |
| Cost | The MIT-licensed native software lists no service fee. Local storage and package-manager costs are separate. | MCPVault is MIT licensed and free to run locally. MCP-host, model, backup, and storage costs remain. |
| Permissions | Indexes repositories, queries code and graphs, performs architecture and impact analysis, manages ADRs and watchers, deletes projects, and writes agent configuration, instruction, Skill, and hook files. | The server has filesystem read and write access within the supplied vault root, including note creation, overwrite or patch, frontmatter changes, moves, tags, and deletion. Operating-system permissions and the configured vault path are the primary boundary. |
| Data handling | The publisher says processing is local and code does not leave the machine. Indexes, embeddings, memories, SQLite data, and logs persist under the local CBM cache directory. | Vault content and metadata are read locally and returned to the MCP client and model. Changes are written directly to local files. MCPVault states that it does not receive, store, or transmit vault data, while the selected AI provider still processes content sent by the client. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Indexing can capture sensitive files, while persistent graph data and installer/configuration writes expand local exposure. Set CBM_ALLOWED_ROOT, protect the cache, and use explicit project paths. | A selected vault can contain a large body of private knowledge, and write tools can overwrite, move, or delete it. Use a dedicated vault, reliable backups or version control, an absolute path, a reviewed package version, and explicit approval for writes. |
| Evidence date | ||
| Editorial review | 2026-08-11 | 2026-07-24 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →