VibeDNA Vault

io.github.marstudio360v1.1.0更新于 Oct 6, 2026

Encrypted local vault for API keys. Your AI fetches keys on demand and scans code for leaks.

概览

AI 生成的概览

本地加密保险库,让 AI 按需获取 API 密钥,并扫描项目文件夹中泄露的密钥。

功能
把 API 密钥、令牌和密码集中存放在本机的一个加密文件中,密钥由主密码派生。助手可以搜索条目、读取某个字段、新增、编辑或删除条目、把条目导出为 .env 行,并使用常见服务的模板。它还能扫描文件夹中的明文密钥、跟踪轮换日期、记录使用日志,并备份加密文件。
适用场景
当你希望助手从本地存储中取用凭据,而不是把密钥粘贴到对话里,或需要检查项目文件夹中是否有明文密钥时,适合使用。
运行要求
作为本机本地进程运行(仅桌面端),可通过 .mcpb 包安装,或用 Python 及其依赖从源码安装。主密码从系统钥匙串读取;没有钥匙串的机器使用 VAULT_MASTER_PASSWORD。VAULT_HOME 指定加密保险库文件位置,VAULT_BACKUP_HOME 指定备份位置。除 check_for_update 外不发起网络请求。
安装前请注意
保险库保存真实凭据,助手可以读取、新增、编辑、删除条目并导出为 .env 行。没有密码重置:丢失主密码后文件将无法读取。主密码是机密(VAULT_MASTER_PASSWORD),不应泄露。check_for_update 会访问外部端点。泄露扫描结果和使用日志写在保险库文件旁边。

安装

在 SourceWeft 中

  1. 打开 控制台中的 VibeDNA Vault,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

VibeDNA Vault MCP

Encrypted local vault for API keys. Your AI fetches keys on demand and scans code for leaks.

Vault keeps every API key, token and password in one encrypted file on your machine (Fernet, with the key derived from your master password by scrypt). The master password is read from your system keyring, or from VAULT_MASTER_PASSWORD on machines with no keyring. Your AI searches the vault and fetches the exact key it needs when it needs it, so keys stop getting pasted into chats. It exports an entry as .env lines, tracks rotation dates, keeps a usage log, ships entry templates for common services, and scans a project folder for keys left in plain text, reporting file and line.

A desktop window (vault_ui.py) and a terminal CLI (vault_core.py) open the same vault with no AI involved. There is no password reset: lose the master password and the file stays unreadable.

Homepage: https://vibedna.ai/store/vault

Tools (17)

ToolWhat it does
credential_exists(name)Check whether an entry exists before asking the user for a key
get_credential(name, key)Return one field of one entry
list_credentials()Entry names, categories and field names. No values
search_credentials(term)Search by name, category or notes
add_credential(name, category, fields, notes)Add an entry (fields is a JSON object)
edit_credential(name, fields)Update fields; an empty value removes that field
delete_credential(name, confirm)Delete an entry (confirm must equal the name)
export_env(name)The entry's fields as KEY=value lines
add_with_template(service, name, fields, notes)Add an entry from a service template
list_templates()The available templates
scan_for_leaks(path)Scan a folder for plaintext keys: your vault's values plus known key patterns
leak_history()Recent leak-scan results
check_rotation_due(days)Entries not rotated in days
mark_rotated(name)Record a rotation
usage_log(name)Recent credential-access events
backup_vault()Copy the encrypted file to the backup folder
check_for_update()Compare this copy with the published version

Install

bash
git clone https://github.com/marstudio360/vibedna-vault-mcpcd vibedna-vault-mcppython -m venv .venv# Windows: .venv\Scripts\activate    mac/linux: source .venv/bin/activatepip install -r requirements.txtpython vault_core.py init

Store the master password in your system keyring once, so the MCP server can open the vault:

bash
python -c "import keyring; keyring.set_password('vibedna-vault','master', input('master password: '))"

Claude Code

bash
claude mcp add vault --scope user -- /absolute/path/to/vibedna-vault-mcp/.venv/bin/python /absolute/path/to/vibedna-vault-mcp/server.py

Or in a project's .mcp.json:

json
{  "mcpServers": {    "vault": {      "command": "/absolute/path/to/vibedna-vault-mcp/.venv/bin/python",      "args": ["/absolute/path/to/vibedna-vault-mcp/server.py"]    }  }}

On Windows the interpreter is .venv\Scripts\python.exe.

Cursor

Add the same mcpServers block to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (one project).

Claude Desktop

Add the same mcpServers block to claude_desktop_config.json (Settings > Developer > Edit Config), then restart Claude Desktop.

INSTALL.md is a step-by-step guide written so you can paste it into an AI chat and let the AI do the install. It also covers the desktop window and the CLI.

Configuration

VariableDefaultWhat it does
VAULT_HOME~/.vibedna-vaultFolder of the encrypted vault file (vault.enc)
VAULT_MASTER_PASSWORD(unset)Master password for machines with no system keyring
VAULT_BACKUP_HOME~/.vibedna-vault/backupsWhere backup_vault writes copies (the last 30 are kept)

The usage log and leak-scan results are written next to the vault file, in logs/.

Network

The vault, the window and the CLI make no network calls. check_for_update is the one tool that does: it asks https://vibedna.ai/api/mcp/latest for the published version number.

License

MIT, see LICENSE. Copyright (c) 2026 VibeDNA.

Support: [email protected]

来源:README.md,提交 7711932

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.1.0最新Oct 6, 2026