Atlas / MCP servers / danieljustus / Symaira Vault

Symaira VaultBLOCK

mcp/danieljustus/symaira-vault

🔐 The password manager for terminal users and AI agents. Age-encrypted, keyring-cached, MCP-ready. Zero telemetry.

Verdict
BLOCK
Grade
F
Trust score
31 /100
Exposed tools
87 60r · 27w · 0d
Transport
stdio
License
Apache-2.0
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Accepted product direction — implementation pending: The independent symvault CLI/service and repository remain. Brain GUI/CLI become the normal integrated credential-management entrypoints. The separate management app remains transitional and is retired only after verified replacement, secure input/approval, data migration and rollback. This is not a removal of the credential service or a requirement to install Brain for CLI use. See PB-2026-09-09.

[](https://github.com/danieljustus/symaira-vault/actions/workflows/ci.yml) [](https://github.com/danieljustus/symaira-vault/releases/latest) [](https://opensource.org/licenses/Apache-2.0) [](https://pkg.go.dev/github.com/danieljustus/symaira-vault)

A modern, secure command-line password manager (symvault) written in Go. Uses age for encryption with built-in MCP server support for AI agent integration.

Status: pre-1.0 — the CLI surface and vault format are stabilizing under SemVer; see CHANGELOG.md for the release history.
Safety Notice: Symaira Vault manages sensitive secrets. Use at your own risk, keep tested backups of your vault, and verify recovery before relying on it for critical credentials.

Features

  • Modern Encryption: age (X25519 + ChaCha20-Poly1305)
  • TOTP Support: Store and generate TOTP codes
  • Clipboard Auto-Clear: Automatic clearing after timeout
  • Autotype: Cross-platform automatic password e
Read from source at commit 35b0e7f4323cOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add symvault-vscode --env FIXTURE_TOKEN=${FIXTURE_TOKEN} --env PUBLIC_FIXTURE_PASSWORD=${PUBLIC_FIXTURE_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "symvault-vscode": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "FIXTURE_TOKEN": "${FIXTURE_TOKEN}",
        "PUBLIC_FIXTURE_PASSWORD": "${PUBLIC_FIXTURE_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (87)

60 read · 27 write · 0 destructive.

ToolRiskDescription
add-credentialwriteGuided workflow to add a new credential to the Symaira Vault vault. Sensitive fields are collected via secure dialog so the agent never sees the value.
find-and-usereadFind an Symaira Vault entry by query and suggest the right consumption tool (copy_to_clipboard, autotype, execute_with_secret) based on the user
get_alias_lexemereadget returns an alias node value without resolving it
get_anchored_quoted_scalarreadget returns an anchored quoted scalar value
get_block_scalarreadget returns the value of a literal block scalar
get_bool_lexemereadget preserves YAML boolean spelling
get_colon_block_scalar_indentationreadget preserves colon-containing block scalar lines at their node indentation
get_complex_quote_commentreadget preserves a comment marker inside a quoted scalar
get_default_homereadget uses the default home config path
get_duplicate_anchor_namesreadget reports duplicate anchor names as a YAML error
get_duplicate_sibling_commentsreadget attaches comments to the selected duplicate-content sibling
get_flow_mappingreadget renders a flow mapping node
get_flow_sequencereadget renders a flow sequence node
get_folded_scalarreadget returns the value of a folded block scalar
get_json_before_commandreadget accepts a global JSON flag before the command
get_json_escape_controlsreadJSON get preserves literal escape text and Unicode separators while leaving HTML characters unescaped
get_json_unescapedreadJSON get output does not HTML escape scalar strings
get_malformedreadget rejects malformed YAML before lookup
get_mapping_comments_anchorsreadget preserves comments and anchors in a mapping node
get_mapping_nodereadget renders a nested block mapping node
get_missing_keyreadget reports the complete dotted path for a missing key
get_missing_key_sibling_scopereadget does not cross a sibling mapping while resolving a path
get_multidoc_firstreadget reads the first YAML document
get_multidoc_second_missingreadget does not read keys from a later YAML document
get_nested_block_scalar_chompingreadget preserves strip and keep chomping indicators in nested block scalars
get_nested_block_scalar_explicit_indentreadget preserves explicit indentation indicators in nested block scalars
get_nested_block_scalar_mappingreadget renders a mapping containing a block scalar
get_nested_block_scalar_relative_indentreadget preserves intentional relative indentation inside a block scalar
get_nested_scalarreadget follows dotted paths through mappings
get_nested_sequence_block_scalarsreadget preserves block scalars nested in a sequence
get_null_lexemereadget preserves YAML null spelling
get_output_jsonreadget honors the global JSON output format
get_quietreadquiet get reads and resolves a value without stdout
get_quoted_anchor_aliasreadget returns the name of an alias to a quoted anchor
get_quoted_colon_keyreadget resolves a quoted mapping key containing a colon
get_quoted_null_literal_mappingreadget preserves a quoted null-looking mapping scalar
get_scalar_anchor_textreadget does not treat anchor-like text inside a scalar as an anchor
get_scalar_lexemereadget preserves the source lexeme for scalar values
get_sequence_mapping_nodereadget renders a sequence containing mappings
lengthreadNew password length (default 32)
list_crlfreadlist preserves CRLF bytes
list_default_homereadlist uses ~/.symvault/config.yaml when no file is supplied
list_emptyreadlist preserves an empty config file
list_empty_file_falls_backreadan empty --file value uses the default home path
list_invalid_utf8readlist preserves invalid UTF-8 bytes
list_json_flagreadlist remains raw when JSON output is requested
list_json_global_before_commandreadlist accepts a global JSON flag before the command
list_malformedreadlist prints malformed YAML without parsing it
list_missing_homereada missing home directory is a general CLI error
list_missing_quietreadquiet list still reports a missing config file
list_output_global_before_commandreadlist accepts a global output flag before the command
list_quietreadquiet list reads the file and suppresses stdout
list_rawreadlist prints ordinary config bytes without parsing
pathreadVault entry path. If omitted, derive a slug from service_name.
queryreadSearch query
rotate-credentialreadRotate the password/token on an existing Symaira Vault entry by generating a new value, storing it, and reminding the user to update it server-side.
secret_fieldreadOptional single field to share instead of the whole entry
service_namereadFriendly name of the service, e.g.
set_boolean_valuewriteset parses a YAML boolean value
set_default_homewriteset uses the default home config path
set_empty_valuewriteset preserves an explicitly empty string value
set_existing_scalarwriteset replaces an existing scalar and preserves other fields
set_flow_mapping_valuewriteset emits a parsed mapping value using Go YAML encoding
set_flow_sequence_valuewriteset emits a parsed sequence value using Go YAML encoding
set_invalid_mcp_bindwriteset writes then reports a config validation error for an invalid known field
set_literal_clipwriteset preserves a clip-chomping literal scalar
set_literal_emptywriteset emits an empty string for an empty literal scalar
set_literal_explicit_indentwriteset preserves an explicit indentation indicator in a multiline string
set_literal_keepwriteset preserves a keep-chomping literal scalar
set_literal_relative_indentwriteset preserves intentional relative indentation in a multiline string
set_literal_stripwriteset preserves a strip-chomping literal scalar
set_literal_valuewriteset emits a multiline YAML string as a literal scalar
set_malformedwriteset rejects malformed YAML without changing the file
set_nested_newwriteset creates a missing nested mapping path
set_newline_literalwriteset preserves a literal string containing only a newline
set_newline_quotedwriteset preserves a quoted string containing only a newline
set_null_valuewriteset parses a YAML null value
set_number_valuewriteset parses and emits a YAML integer value
set_overwrites_scalar_parentwriteset replaces a scalar intermediate with a mapping
set_preserves_comments_anchorswriteset preserves comments and anchors around an edited value
set_quietwritequiet set writes the value without stdout
set_quoted_null_valuewriteset keeps a quoted null-looking value as a string
set_quoted_valuewriteset parses a quoted YAML string value
share-credentialwriteCreate a share grant for another agent and explain the human-approval flow.
taskreadWhat the user wants to do with the credential (login / curl / terraform / ...)
to_agentreadName of the receiving agent profile
ttlreadTime-to-live for the grant, default
04

Trust audit

BLOCKgrade F · trust 31/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (12 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALObfuscation / stealth · obf.decode_then_exec · CWE-506, CWE-94
scripts/rust-port/device_list_differential.py:97
b64decode( ... subprocess.
Why it matters. decodes a payload and executes it
CRITICALObfuscation / stealth · obf.decode_then_exec · CWE-506, CWE-94
scripts/rust-port/http_process_contract.py:256
b64decode( ... subprocess.
Why it matters. decodes a payload and executes it
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
internal/vault/entry_canary.go:98
"token":    "ghp_CANARY1234567890abcdefghijklmnopqrstuv",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/symvault-store/src/lib.rs:2008
"-----BEGIN RSA PRIVATE KEY-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/symvault-store/src/lib.rs:2009
"-----BEGIN EC PRIVATE KEY-----",
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/threat-model.md:32
| MITRE ATLAS | AML.T0057 LLM Jailbreak via Indirect Prompt Injection | §2, §3 |
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
internal/crypto/eff_large_wordlist.txt:3448
34654	jailbreak
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInventory / provenance · inv.binary · CWE-1104
assets/branding/symaira-vault.icns
symaira-vault.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
testdata/importer/onepux/sample.1pux
sample.1pux
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
fuzz/corpus/age_envelope/valid_age_b64:1
b64:YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBpeHhCQ0QybUVOdTBFZU1HQkZTcjB2aThlcFFkUG5FZzIrb1BmUEhqdFZvCnlNM1pVT0orWU5YZUZWTWROdnI5d3dSdDJyU29hb1gxSHcyKzIvT3lwZlEKLT4gWDI1NTE5IEZYNnBPTWpQR2VUOHRGQm9p
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
testdata/port/core/password-totp-contract.json:40
"reader_bytes": "AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8gISIjJCUmJygpKissLS4vMDEyMzQ1Njc4OTo7PD0+PwABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4fICEiIyQlJicoKSorLC0uLzAxMjM0NTY3ODk6Ozw9Pj8AAQIDBAUGBwg
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
testdata/port/mcp/execute-api-request.json:231
"text": "{\"body\":\"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
testdata/port/mcp/tools-audit-self.json:557
"audit_log_hex": "7b227473223a22323032362d30312d30325430333a30343a31315a222c22616374696f6e223a226f76657273697a6564222c2270617468223a22787878787878787878787878787878787878787878787878787878787878787878
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
testdata/port/mcp/tools-set-entry.json:461
"{\"jsonrpc\":\"2.0\",\"id\":12,\"method\":\"tools/call\",\"params\":{\"name\":\"set_entry_field\",\"arguments\":{\"path\":\"github\",\"field\":\"username\",\"value\":\"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/symvault-cli/src/session_commands.rs:353
parse_ttl_override("1μs").unwrap(),
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/symvault-core/src/config.rs:1042
|| rest[index..].starts_with("μs")
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/symvault-core/src/config.rs:1198
if !matches!(unit, "ns" | "us" | "μs" | "μs" | "ms" | "s" | "m" | "h") {
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/symvault-core/src/config.rs:2172
("1μs", 1_000_i64),
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
crates/symvault-core/src/config.rs:2224
assert_eq!(parse_duration_nanos("1μs"), Some(1_000));
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
internal/vault/entry_test.go:1552
"access_key": "AKIA1234567890ABCDEF",
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
internal/vault/types_test.go:104
{"AKIA0123456789ABCDEF", SecretTypeAPIKey},
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
internal/vault/types_test.go:192
{"value pattern wins over path", "minimax/api-key", "", "AKIA0123456789ABCDEF", "", SecretTypeAPIKey},
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
crates/symvault-cli/tests/auth_differential.rs:490
let token = "0123456789ABCDEF0123456789ABCDEF";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
crates/symvault-cli/tests/auth_differential.rs:550
let token = "0123456789ABCDEF0123456789ABCDEF";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
crates/symvault-cli/tests/cli_differential.rs:2461
let secret = "JBSWY3DPEHPK3PXPJBSWY3DPEHPK3PXP";

Gates applied: critical_finding, instruction_override, no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 35b0e7f4323cfull audit observations/trust-audit/mcp-server/danieljustus__symaira-vault.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0935b0e7f4323cBLOCKF31first audit
06

Questions

What is the Symaira Vault MCP server?

🔐 The password manager for terminal users and AI agents. Age-encrypted, keyring-cached, MCP-ready. Zero telemetry.

What tools does Symaira Vault expose?

87 in total: 60 read-only, 27 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Symaira Vault safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (31/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Symaira Vault need?

It reads FIXTURE_TOKEN and PUBLIC_FIXTURE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Symaira Vault run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as symvault-vscode at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (35b0e7f4323c), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement