Symaira VaultBLOCK
🔐 The password manager for terminal users and AI agents. Age-encrypted, keyring-cached, MCP-ready. Zero telemetry.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Accepted product direction — implementation pending: The independent symvault CLI/service and repository remain. Brain GUI/CLI become the normal integrated credential-management entrypoints. The separate management app remains transitional and is retired only after verified replacement, secure input/approval, data migration and rollback. This is not a removal of the credential service or a requirement to install Brain for CLI use. See PB-2026-09-09.
[](https://github.com/danieljustus/symaira-vault/actions/workflows/ci.yml) [](https://github.com/danieljustus/symaira-vault/releases/latest) [](https://opensource.org/licenses/Apache-2.0) [](https://pkg.go.dev/github.com/danieljustus/symaira-vault)
A modern, secure command-line password manager (symvault) written in Go. Uses age for encryption with built-in MCP server support for AI agent integration.
Status: pre-1.0 — the CLI surface and vault format are stabilizing under SemVer; see CHANGELOG.md for the release history.
Safety Notice: Symaira Vault manages sensitive secrets. Use at your own risk, keep tested backups of your vault, and verify recovery before relying on it for critical credentials.
Features
- Modern Encryption: age (X25519 + ChaCha20-Poly1305)
- TOTP Support: Store and generate TOTP codes
- Clipboard Auto-Clear: Automatic clearing after timeout
- Autotype: Cross-platform automatic password e
35b0e7f4323cOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add symvault-vscode --env FIXTURE_TOKEN=${FIXTURE_TOKEN} --env PUBLIC_FIXTURE_PASSWORD=${PUBLIC_FIXTURE_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"symvault-vscode": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"FIXTURE_TOKEN": "${FIXTURE_TOKEN}",
"PUBLIC_FIXTURE_PASSWORD": "${PUBLIC_FIXTURE_PASSWORD}"
}
}
}
}Exposed tools (87)
60 read · 27 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add-credential | write | Guided workflow to add a new credential to the Symaira Vault vault. Sensitive fields are collected via secure dialog so the agent never sees the value. |
find-and-use | read | Find an Symaira Vault entry by query and suggest the right consumption tool (copy_to_clipboard, autotype, execute_with_secret) based on the user |
get_alias_lexeme | read | get returns an alias node value without resolving it |
get_anchored_quoted_scalar | read | get returns an anchored quoted scalar value |
get_block_scalar | read | get returns the value of a literal block scalar |
get_bool_lexeme | read | get preserves YAML boolean spelling |
get_colon_block_scalar_indentation | read | get preserves colon-containing block scalar lines at their node indentation |
get_complex_quote_comment | read | get preserves a comment marker inside a quoted scalar |
get_default_home | read | get uses the default home config path |
get_duplicate_anchor_names | read | get reports duplicate anchor names as a YAML error |
get_duplicate_sibling_comments | read | get attaches comments to the selected duplicate-content sibling |
get_flow_mapping | read | get renders a flow mapping node |
get_flow_sequence | read | get renders a flow sequence node |
get_folded_scalar | read | get returns the value of a folded block scalar |
get_json_before_command | read | get accepts a global JSON flag before the command |
get_json_escape_controls | read | JSON get preserves literal escape text and Unicode separators while leaving HTML characters unescaped |
get_json_unescaped | read | JSON get output does not HTML escape scalar strings |
get_malformed | read | get rejects malformed YAML before lookup |
get_mapping_comments_anchors | read | get preserves comments and anchors in a mapping node |
get_mapping_node | read | get renders a nested block mapping node |
get_missing_key | read | get reports the complete dotted path for a missing key |
get_missing_key_sibling_scope | read | get does not cross a sibling mapping while resolving a path |
get_multidoc_first | read | get reads the first YAML document |
get_multidoc_second_missing | read | get does not read keys from a later YAML document |
get_nested_block_scalar_chomping | read | get preserves strip and keep chomping indicators in nested block scalars |
get_nested_block_scalar_explicit_indent | read | get preserves explicit indentation indicators in nested block scalars |
get_nested_block_scalar_mapping | read | get renders a mapping containing a block scalar |
get_nested_block_scalar_relative_indent | read | get preserves intentional relative indentation inside a block scalar |
get_nested_scalar | read | get follows dotted paths through mappings |
get_nested_sequence_block_scalars | read | get preserves block scalars nested in a sequence |
get_null_lexeme | read | get preserves YAML null spelling |
get_output_json | read | get honors the global JSON output format |
get_quiet | read | quiet get reads and resolves a value without stdout |
get_quoted_anchor_alias | read | get returns the name of an alias to a quoted anchor |
get_quoted_colon_key | read | get resolves a quoted mapping key containing a colon |
get_quoted_null_literal_mapping | read | get preserves a quoted null-looking mapping scalar |
get_scalar_anchor_text | read | get does not treat anchor-like text inside a scalar as an anchor |
get_scalar_lexeme | read | get preserves the source lexeme for scalar values |
get_sequence_mapping_node | read | get renders a sequence containing mappings |
length | read | New password length (default 32) |
list_crlf | read | list preserves CRLF bytes |
list_default_home | read | list uses ~/.symvault/config.yaml when no file is supplied |
list_empty | read | list preserves an empty config file |
list_empty_file_falls_back | read | an empty --file value uses the default home path |
list_invalid_utf8 | read | list preserves invalid UTF-8 bytes |
list_json_flag | read | list remains raw when JSON output is requested |
list_json_global_before_command | read | list accepts a global JSON flag before the command |
list_malformed | read | list prints malformed YAML without parsing it |
list_missing_home | read | a missing home directory is a general CLI error |
list_missing_quiet | read | quiet list still reports a missing config file |
list_output_global_before_command | read | list accepts a global output flag before the command |
list_quiet | read | quiet list reads the file and suppresses stdout |
list_raw | read | list prints ordinary config bytes without parsing |
path | read | Vault entry path. If omitted, derive a slug from service_name. |
query | read | Search query |
rotate-credential | read | Rotate the password/token on an existing Symaira Vault entry by generating a new value, storing it, and reminding the user to update it server-side. |
secret_field | read | Optional single field to share instead of the whole entry |
service_name | read | Friendly name of the service, e.g. |
set_boolean_value | write | set parses a YAML boolean value |
set_default_home | write | set uses the default home config path |
set_empty_value | write | set preserves an explicitly empty string value |
set_existing_scalar | write | set replaces an existing scalar and preserves other fields |
set_flow_mapping_value | write | set emits a parsed mapping value using Go YAML encoding |
set_flow_sequence_value | write | set emits a parsed sequence value using Go YAML encoding |
set_invalid_mcp_bind | write | set writes then reports a config validation error for an invalid known field |
set_literal_clip | write | set preserves a clip-chomping literal scalar |
set_literal_empty | write | set emits an empty string for an empty literal scalar |
set_literal_explicit_indent | write | set preserves an explicit indentation indicator in a multiline string |
set_literal_keep | write | set preserves a keep-chomping literal scalar |
set_literal_relative_indent | write | set preserves intentional relative indentation in a multiline string |
set_literal_strip | write | set preserves a strip-chomping literal scalar |
set_literal_value | write | set emits a multiline YAML string as a literal scalar |
set_malformed | write | set rejects malformed YAML without changing the file |
set_nested_new | write | set creates a missing nested mapping path |
set_newline_literal | write | set preserves a literal string containing only a newline |
set_newline_quoted | write | set preserves a quoted string containing only a newline |
set_null_value | write | set parses a YAML null value |
set_number_value | write | set parses and emits a YAML integer value |
set_overwrites_scalar_parent | write | set replaces a scalar intermediate with a mapping |
set_preserves_comments_anchors | write | set preserves comments and anchors around an edited value |
set_quiet | write | quiet set writes the value without stdout |
set_quoted_null_value | write | set keeps a quoted null-looking value as a string |
set_quoted_value | write | set parses a quoted YAML string value |
share-credential | write | Create a share grant for another agent and explain the human-approval flow. |
task | read | What the user wants to do with the credential (login / curl / terraform / ...) |
to_agent | read | Name of the receiving agent profile |
ttl | read | Time-to-live for the grant, default |
Trust audit
BLOCKgrade F · trust 31/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (12 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
b64decode( ... subprocess.
b64decode( ... subprocess.
"token": "ghp_CANARY1234567890abcdefghijklmnopqrstuv",
"-----BEGIN RSA PRIVATE KEY-----",
"-----BEGIN EC PRIVATE KEY-----",
| MITRE ATLAS | AML.T0057 LLM Jailbreak via Indirect Prompt Injection | §2, §3 |
34654 jailbreak
symaira-vault.icns
sample.1pux
b64:YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBpeHhCQ0QybUVOdTBFZU1HQkZTcjB2aThlcFFkUG5FZzIrb1BmUEhqdFZvCnlNM1pVT0orWU5YZUZWTWROdnI5d3dSdDJyU29hb1gxSHcyKzIvT3lwZlEKLT4gWDI1NTE5IEZYNnBPTWpQR2VUOHRGQm9p
"reader_bytes": "AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8gISIjJCUmJygpKissLS4vMDEyMzQ1Njc4OTo7PD0+PwABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4fICEiIyQlJicoKSorLC0uLzAxMjM0NTY3ODk6Ozw9Pj8AAQIDBAUGBwg
"text": "{\"body\":\"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"audit_log_hex": "7b227473223a22323032362d30312d30325430333a30343a31315a222c22616374696f6e223a226f76657273697a6564222c2270617468223a22787878787878787878787878787878787878787878787878787878787878787878
"{\"jsonrpc\":\"2.0\",\"id\":12,\"method\":\"tools/call\",\"params\":{\"name\":\"set_entry_field\",\"arguments\":{\"path\":\"github\",\"field\":\"username\",\"value\":\"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxparse_ttl_override("1μs").unwrap(),|| rest[index..].starts_with("μs")if !matches!(unit, "ns" | "us" | "μs" | "μs" | "ms" | "s" | "m" | "h") {("1μs", 1_000_i64),assert_eq!(parse_duration_nanos("1μs"), Some(1_000));"access_key": "AKIA1234567890ABCDEF",
{"AKIA0123456789ABCDEF", SecretTypeAPIKey},{"value pattern wins over path", "minimax/api-key", "", "AKIA0123456789ABCDEF", "", SecretTypeAPIKey},let token = "0123456789ABCDEF0123456789ABCDEF";
let token = "0123456789ABCDEF0123456789ABCDEF";
let secret = "JBSWY3DPEHPK3PXPJBSWY3DPEHPK3PXP";
Gates applied: critical_finding, instruction_override, no_behavioural_pass.
35b0e7f4323cfull audit observations/trust-audit/mcp-server/danieljustus__symaira-vault.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 35b0e7f4323c | BLOCK | F | 31 | first audit |
Questions
What is the Symaira Vault MCP server?
🔐 The password manager for terminal users and AI agents. Age-encrypted, keyring-cached, MCP-ready. Zero telemetry.
What tools does Symaira Vault expose?
87 in total: 60 read-only, 27 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Symaira Vault safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (31/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Symaira Vault need?
It reads FIXTURE_TOKEN and PUBLIC_FIXTURE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Symaira Vault run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as symvault-vscode at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (35b0e7f4323c), read on 2026-10-09. The repository is watched and re-audited when it changes.