VibeDNA Vault

io.github.marstudio360v1.1.0更新於 Oct 6, 2026

Encrypted local vault for API keys. Your AI fetches keys on demand and scans code for leaks.

概覽

AI 產生的概覽

本機加密保險庫,讓 AI 隨需取得 API 金鑰,並掃描專案資料夾中外洩的金鑰。

功能
把 API 金鑰、權杖和密碼集中存放在本機的一個加密檔案中,金鑰由主密碼衍生。助理可以搜尋項目、讀取某個欄位、新增、編輯或刪除項目、把項目匯出成 .env 行,並使用常見服務的範本。它也能掃描資料夾中的明文金鑰、追蹤輪換日期、記錄使用日誌,並備份加密檔案。
適用情境
當你希望助理從本機儲存區取用憑證,而不是把金鑰貼到對話中,或需要檢查專案資料夾是否有明文金鑰時,適合使用。
執行需求
以本機本機程序執行(僅桌面端),可透過 .mcpb 套件安裝,或以 Python 及其相依套件從原始碼安裝。主密碼從系統鑰匙圈讀取;沒有鑰匙圈的機器使用 VAULT_MASTER_PASSWORD。VAULT_HOME 指定加密保險庫檔案位置,VAULT_BACKUP_HOME 指定備份位置。除 check_for_update 外不發出網路請求。
安裝前請注意
保險庫保存真實憑證,助理可以讀取、新增、編輯、刪除項目並匯出成 .env 行。沒有密碼重設:遺失主密碼後檔案將無法讀取。主密碼是機密(VAULT_MASTER_PASSWORD),不應外洩。check_for_update 會連線外部端點。外洩掃描結果和使用日誌寫在保險庫檔案旁。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 VibeDNA Vault,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

VibeDNA Vault MCP

Encrypted local vault for API keys. Your AI fetches keys on demand and scans code for leaks.

Vault keeps every API key, token and password in one encrypted file on your machine (Fernet, with the key derived from your master password by scrypt). The master password is read from your system keyring, or from VAULT_MASTER_PASSWORD on machines with no keyring. Your AI searches the vault and fetches the exact key it needs when it needs it, so keys stop getting pasted into chats. It exports an entry as .env lines, tracks rotation dates, keeps a usage log, ships entry templates for common services, and scans a project folder for keys left in plain text, reporting file and line.

A desktop window (vault_ui.py) and a terminal CLI (vault_core.py) open the same vault with no AI involved. There is no password reset: lose the master password and the file stays unreadable.

Homepage: https://vibedna.ai/store/vault

Tools (17)

ToolWhat it does
credential_exists(name)Check whether an entry exists before asking the user for a key
get_credential(name, key)Return one field of one entry
list_credentials()Entry names, categories and field names. No values
search_credentials(term)Search by name, category or notes
add_credential(name, category, fields, notes)Add an entry (fields is a JSON object)
edit_credential(name, fields)Update fields; an empty value removes that field
delete_credential(name, confirm)Delete an entry (confirm must equal the name)
export_env(name)The entry's fields as KEY=value lines
add_with_template(service, name, fields, notes)Add an entry from a service template
list_templates()The available templates
scan_for_leaks(path)Scan a folder for plaintext keys: your vault's values plus known key patterns
leak_history()Recent leak-scan results
check_rotation_due(days)Entries not rotated in days
mark_rotated(name)Record a rotation
usage_log(name)Recent credential-access events
backup_vault()Copy the encrypted file to the backup folder
check_for_update()Compare this copy with the published version

Install

bash
git clone https://github.com/marstudio360/vibedna-vault-mcpcd vibedna-vault-mcppython -m venv .venv# Windows: .venv\Scripts\activate    mac/linux: source .venv/bin/activatepip install -r requirements.txtpython vault_core.py init

Store the master password in your system keyring once, so the MCP server can open the vault:

bash
python -c "import keyring; keyring.set_password('vibedna-vault','master', input('master password: '))"

Claude Code

bash
claude mcp add vault --scope user -- /absolute/path/to/vibedna-vault-mcp/.venv/bin/python /absolute/path/to/vibedna-vault-mcp/server.py

Or in a project's .mcp.json:

json
{  "mcpServers": {    "vault": {      "command": "/absolute/path/to/vibedna-vault-mcp/.venv/bin/python",      "args": ["/absolute/path/to/vibedna-vault-mcp/server.py"]    }  }}

On Windows the interpreter is .venv\Scripts\python.exe.

Cursor

Add the same mcpServers block to ~/.cursor/mcp.json (all projects) or .cursor/mcp.json (one project).

Claude Desktop

Add the same mcpServers block to claude_desktop_config.json (Settings > Developer > Edit Config), then restart Claude Desktop.

INSTALL.md is a step-by-step guide written so you can paste it into an AI chat and let the AI do the install. It also covers the desktop window and the CLI.

Configuration

VariableDefaultWhat it does
VAULT_HOME~/.vibedna-vaultFolder of the encrypted vault file (vault.enc)
VAULT_MASTER_PASSWORD(unset)Master password for machines with no system keyring
VAULT_BACKUP_HOME~/.vibedna-vault/backupsWhere backup_vault writes copies (the last 30 are kept)

The usage log and leak-scan results are written next to the vault file, in logs/.

Network

The vault, the window and the CLI make no network calls. check_for_update is the one tool that does: it asks https://vibedna.ai/api/mcp/latest for the published version number.

License

MIT, see LICENSE. Copyright (c) 2026 VibeDNA.

Support: [email protected]

來源:README.md,提交 7711932

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.1.0最新Oct 6, 2026