Atlas / MCP servers / zycaskevin / Vault for LLM

Vault for LLMBLOCK

mcp/zycaskevin/vault-for-llm

Local-first memory governance for AI agents: shared, reviewable, auditable memory via SQLite and MCP.

Verdict
BLOCK
Grade
F
Trust score
49 /100
Exposed tools
5 4r · 1w · 0d
Transport
—
License
Apache-2.0
Stars
50
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 繁體中文 | 简体中文

Website · Founding 10 challenge · Live evidence · Reproduce independently · Methodology · Install

Vault is a local-first, backend-agnostic memory governance layer for AI agents.

Vault Agent Memory gives Codex, Claude Code, Hermes, OpenClaw, n8n, Coze, and other agents one governed memory vault to share. It is not trying to be another notes app or vector database. It helps agents decide what should be remembered, who can use it, whether it is still current, and how to roll it back when it is wrong.

Vault's product boundary is the governance contract, not a specific backend. The same candidate-first review model can run on local SQLite, a self-hosted central memory host, a Supabase cloud adapter, or a future managed Vault Cloud backend.

Vault works standalone, and it can also become the governed memory backend for other agent memory frameworks. You can use Vault by itself with CLI, MCP, Gateway, and local SQLite; or let frameworks such as Hermes, OpenClaw, Letta, mem0, Claude Code, and Codex connect through Vault APIs while Vault keeps the review, audit, lifecycle, and backend boundaries consistent.

The core multi-agent model is single-host sharing, multi-host governed sync: agents on one trusted machine can share the same local Vault, while agents on other machines or hosted runtimes can read approved memory and submit candidates. Only a trusted sync host promotes official memory, runs lifecycle jobs, and pushes reviewed read copies back out.

The Python package and existing install path remain vault-for-llm.

Vault is for pe

Read from source at commit 45c5ee362e22OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add vault-for-llm --env AGENTMEMORY_SECRET=${AGENTMEMORY_SECRET} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env COHERE_API_KEY=${COHERE_API_KEY} --env LETTA_API_KEY=${LETTA_API_KEY} -- uvx vault-for-llm
claude-desktop
{
  "mcpServers": {
    "vault-for-llm": {
      "command": "uvx",
      "args": [
        "vault-for-llm"
      ],
      "env": {
        "AGENTMEMORY_SECRET": "${AGENTMEMORY_SECRET}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "COHERE_API_KEY": "${COHERE_API_KEY}",
        "LETTA_API_KEY": "${LETTA_API_KEY}"
      }
    }
  }
}
03

Exposed tools (5)

4 read · 1 write · 0 destructive.

ToolRiskDescription
vault_memory_proposereadPropose a new memory candidate. Candidate-first only: do not promote unless a human operator explicitly asks.
vault_obsidian_importwriteImport an existing Obsidian vault into Vault Agent Memory. Run dry_run first; only use apply+compile after user confirmation.
vault_read_rangereadRead a bounded source range from Vault Agent Memory after vault_search returns an id/node/line range. Use this before citing evidence.
vault_searchreadSearch governed Vault Agent Memory project memory. Use before answering project-memory, decision, SOP, pitfall, or source-of-truth questions.
vault_statsreadShow Vault Agent Memory project memory status and counts.
04

Trust audit

BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (4 observation(s))
Shell
declared (5 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/run_subject_development_mission_v4.py:71
exec(compile(raw, "<subject-v4-sibling>", "exec"), module.__dict__)  # noqa: S102
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/run_subject_development_mission_v5.py:72
exec(compile(raw, "<subject-v5-sibling>", "exec"), module.__dict__)  # noqa: S102
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/run_subject_implementation_authorization.py:77
exec(compile(raw, str(path), "exec"), module.__dict__)  # noqa: S102 - fixed reviewed bytes
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/run_subject_task_authorization_v2.py:130
exec(compile(raw, str(path), "exec"), module.__dict__)  # noqa: S102 - pinned bytes
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/run_subject_task_authorization_v3.py:172
exec(compile(raw, str(path), "exec"), module.__dict__)  # noqa: S102 - pinned bytes
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
vault/gateway.py:794
print(f"Auth: {'enabled' if token else 'disabled'}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
vault/gateway.py:810
print(f"Token: {token}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
vault/gui_server.py:63
print(f"Auth: {'enabled' if token else 'disabled'}")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
vault/privacy.py:31
("prompt_injection_reveal_secrets", re.compile(r"(?i)\b(?:reveal|print|dump|exfiltrate)\s+(?:the\s+)?(?:system\s+prompt|developer\s+message|api\s*key|token|secret)s?\b")),
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_automation.py:1503
token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_automation.py:1603
token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_automation.py:2219
token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_automation.py:2345
token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_automation.py:2396
token = "ghp_FAKEFAKEFAKEFAKEFAKEFAKE"
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/test_privacy_extended.py:118
result = scan_privacy("ghp_abcdefghijklmnopqrstuvwxyz0123456789")
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/test_privacy_extended.py:160
text = "My token: ghp_abcdefghijklmnopqrstuvwxyz0123456789"
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/test_privacy_extended.py:163
assert "ghp_abcdefghijklmnopqrstuvwxyz0123456789" not in result
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_subject_authorization_bootstrap.py:250
"-----BEGIN PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_subject_authorization_bootstrap.py:268
"note -----BEGIN PRIVATE KEY----- suffix",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_subject_baseline_control.py:188
("ordinary", "-----BEGIN PRIVATE KEY-----", False),
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_subject_baseline_control.py:225
"prefix -----BEGIN PRIVATE KEY----- suffix",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_subject_progress.py:383
"-----BEGIN PRIVATE KEY-----",
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_search_extended.py:2637
return __import__(name)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
vault/search_cache.py:72
return hashlib.md5(key_json.encode("utf-8")).hexdigest()
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
security-audits/test_security_review.py:460
print(f"    {status} '{token[:20]}' -> {result}")

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 45c5ee362e22full audit observations/trust-audit/mcp-server/zycaskevin__vault-for-llm.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0845c5ee362e22BLOCKF49first audit
06

Questions

What is the Vault for LLM MCP server?

Local-first memory governance for AI agents: shared, reviewable, auditable memory via SQLite and MCP.

What tools does Vault for LLM expose?

5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Vault for LLM safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (49/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Vault for LLM need?

It reads AGENTMEMORY_SECRET, ANTHROPIC_API_KEY, COHERE_API_KEY, LETTA_API_KEY, OLLAMA_API_KEY, OPENAI_API_KEY, SUPABASE_ANON_KEY, SUPABASE_KEY, SUPABASE_PUBLISHABLE_KEY, SUPABASE_SERVICE_KEY, SUPABASE_SERVICE_ROLE_KEY and VAULT_GATEWAY_TLS_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (45c5ee362e22), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement