Vault for LLMBLOCK
Local-first memory governance for AI agents: shared, reviewable, auditable memory via SQLite and MCP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 繁體中文 | 简体中文
Website · Founding 10 challenge · Live evidence · Reproduce independently · Methodology · Install
Vault is a local-first, backend-agnostic memory governance layer for AI agents.
Vault Agent Memory gives Codex, Claude Code, Hermes, OpenClaw, n8n, Coze, and other agents one governed memory vault to share. It is not trying to be another notes app or vector database. It helps agents decide what should be remembered, who can use it, whether it is still current, and how to roll it back when it is wrong.
Vault's product boundary is the governance contract, not a specific backend. The same candidate-first review model can run on local SQLite, a self-hosted central memory host, a Supabase cloud adapter, or a future managed Vault Cloud backend.
Vault works standalone, and it can also become the governed memory backend for other agent memory frameworks. You can use Vault by itself with CLI, MCP, Gateway, and local SQLite; or let frameworks such as Hermes, OpenClaw, Letta, mem0, Claude Code, and Codex connect through Vault APIs while Vault keeps the review, audit, lifecycle, and backend boundaries consistent.
The core multi-agent model is single-host sharing, multi-host governed sync: agents on one trusted machine can share the same local Vault, while agents on other machines or hosted runtimes can read approved memory and submit candidates. Only a trusted sync host promotes official memory, runs lifecycle jobs, and pushes reviewed read copies back out.
The Python package and existing install path remain vault-for-llm.
Vault is for pe
45c5ee362e22OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add vault-for-llm --env AGENTMEMORY_SECRET=${AGENTMEMORY_SECRET} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env COHERE_API_KEY=${COHERE_API_KEY} --env LETTA_API_KEY=${LETTA_API_KEY} -- uvx vault-for-llm{
"mcpServers": {
"vault-for-llm": {
"command": "uvx",
"args": [
"vault-for-llm"
],
"env": {
"AGENTMEMORY_SECRET": "${AGENTMEMORY_SECRET}",
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"COHERE_API_KEY": "${COHERE_API_KEY}",
"LETTA_API_KEY": "${LETTA_API_KEY}"
}
}
}
}Exposed tools (5)
4 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
vault_memory_propose | read | Propose a new memory candidate. Candidate-first only: do not promote unless a human operator explicitly asks. |
vault_obsidian_import | write | Import an existing Obsidian vault into Vault Agent Memory. Run dry_run first; only use apply+compile after user confirmation. |
vault_read_range | read | Read a bounded source range from Vault Agent Memory after vault_search returns an id/node/line range. Use this before citing evidence. |
vault_search | read | Search governed Vault Agent Memory project memory. Use before answering project-memory, decision, SOP, pitfall, or source-of-truth questions. |
vault_stats | read | Show Vault Agent Memory project memory status and counts. |
Trust audit
BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
exec(compile(raw, "<subject-v4-sibling>", "exec"), module.__dict__) # noqa: S102
exec(compile(raw, "<subject-v5-sibling>", "exec"), module.__dict__) # noqa: S102
exec(compile(raw, str(path), "exec"), module.__dict__) # noqa: S102 - fixed reviewed bytes
exec(compile(raw, str(path), "exec"), module.__dict__) # noqa: S102 - pinned bytes
exec(compile(raw, str(path), "exec"), module.__dict__) # noqa: S102 - pinned bytes
print(f"Auth: {'enabled' if token else 'disabled'}")print(f"Token: {token}")print(f"Auth: {'enabled' if token else 'disabled'}")("prompt_injection_reveal_secrets", re.compile(r"(?i)\b(?:reveal|print|dump|exfiltrate)\s+(?:the\s+)?(?:system\s+prompt|developer\s+message|api\s*key|token|secret)s?\b")),token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
result = scan_privacy("ghp_abcdefghijklmnopqrstuvwxyz0123456789")text = "My token: ghp_abcdefghijklmnopqrstuvwxyz0123456789"
assert "ghp_abcdefghijklmnopqrstuvwxyz0123456789" not in result
"-----BEGIN PRIVATE KEY-----",
"note -----BEGIN PRIVATE KEY----- suffix",
("ordinary", "-----BEGIN PRIVATE KEY-----", False),"prefix -----BEGIN PRIVATE KEY----- suffix",
"-----BEGIN PRIVATE KEY-----",
return __import__(name)
return hashlib.md5(key_json.encode("utf-8")).hexdigest()print(f" {status} '{token[:20]}' -> {result}")Gates applied: no_behavioural_pass.
45c5ee362e22full audit observations/trust-audit/mcp-server/zycaskevin__vault-for-llm.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 45c5ee362e22 | BLOCK | F | 49 | first audit |
Questions
What is the Vault for LLM MCP server?
Local-first memory governance for AI agents: shared, reviewable, auditable memory via SQLite and MCP.
What tools does Vault for LLM expose?
5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Vault for LLM safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (49/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Vault for LLM need?
It reads AGENTMEMORY_SECRET, ANTHROPIC_API_KEY, COHERE_API_KEY, LETTA_API_KEY, OLLAMA_API_KEY, OPENAI_API_KEY, SUPABASE_ANON_KEY, SUPABASE_KEY, SUPABASE_PUBLISHABLE_KEY, SUPABASE_SERVICE_KEY, SUPABASE_SERVICE_ROLE_KEY and VAULT_GATEWAY_TLS_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (45c5ee362e22), read on 2026-10-08. The repository is watched and re-audited when it changes.