{"_id":"@botiverse/agent-vault","_rev":"11-8861fb8c0c53de6643aeee58784e094e","name":"@botiverse/agent-vault","dist-tags":{"latest":"0.4.0"},"versions":{"0.1.0":{"name":"@botiverse/agent-vault","version":"0.1.0","keywords":["agent","vault","secrets","cli","ai","security","redaction"],"license":"Apache-2.0","_id":"@botiverse/agent-vault@0.1.0","maintainers":[{"name":"richardchien","email":"stdrc@outlook.com"}],"homepage":"https://github.com/botiverse/agent-vault#readme","bugs":{"url":"https://github.com/botiverse/agent-vault/issues"},"bin":{"agent-vault":"dist/cli.js"},"dist":{"shasum":"532cc1ddd2aac1537e24cf45a3358da8a74c524e","tarball":"https://registry.npmjs.org/@botiverse/agent-vault/-/agent-vault-0.1.0.tgz","fileCount":16,"integrity":"sha512-dZFdvkcu8Y7yUiZ+N8mwgtelHkmvx74ED+eUJCCetJRa7LiL11YbZX4Fe1W01GuQK1fDbBNrYoBZaUVY71DhOA==","signatures":[{"sig":"MEUCIQCkDEnunoou0U2krFRaolRaeJKbEf65gpLbZoEEuspovQIgcWsr/sp5W3Km46pt7pIvv3ZLtAnGaoJ0GrbAEUI2zGM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":84905},"type":"module","engines":{"node":">=18"},"gitHead":"d4c681fc8f936199111d448ba40459fdc27249f2","scripts":{"dev":"tsx src/cli.ts","test":"vitest run","build":"tsc","start":"node dist/cli.js","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build"},"_npmUser":{"name":"richardchien","email":"stdrc@outlook.com"},"repository":{"url":"git+https://github.com/botiverse/agent-vault.git","type":"git"},"_npmVersion":"11.8.0","description":"Keep your secrets hidden from AI coding agents.","directories":{},"_nodeVersion":"24.13.1","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"^25.3.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/agent-vault_0.1.0_1771487062443_0.10400880020857173","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@botiverse/agent-vault","version":"0.1.3","keywords":["agent","vault","secrets","cli","ai","security","redaction"],"license":"Apache-2.0","_id":"@botiverse/agent-vault@0.1.3","maintainers":[{"name":"richardchien","email":"stdrc@outlook.com"}],"homepage":"https://github.com/botiverse/agent-vault#readme","bugs":{"url":"https://github.com/botiverse/agent-vault/issues"},"bin":{"agent-vault":"dist/cli.js"},"dist":{"shasum":"dbc056acc076e6234162f661f4e5b6d876e2427d","tarball":"https://registry.npmjs.org/@botiverse/agent-vault/-/agent-vault-0.1.3.tgz","fileCount":16,"integrity":"sha512-yeALruP056rmQGWW/HhIzH2wpFDEC5/AvBj57NNPaFwO20xKzsz5Y3fhlXdnyCFHJKpKM/4Qafz+IA83qL2g/Q==","signatures":[{"sig":"MEUCIQCkzS32KfjVmZYcq7ny3AXjz+Lisj13s8O08VyYdUmWfQIgW4Rj+Mhg2qtyF8oNQgF4ibC0drzqMbadXSfqjR8xr3o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@botiverse%2fagent-vault@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":84905},"type":"module","engines":{"node":">=18"},"gitHead":"ed37fa056bfed28469df44b30ac7c9a9e7d86b81","scripts":{"dev":"tsx src/cli.ts","test":"vitest run","build":"tsc","start":"node dist/cli.js","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1d1096ae-b538-4d69-a794-901c3f7fafc4"}},"repository":{"url":"git+https://github.com/botiverse/agent-vault.git","type":"git"},"_npmVersion":"11.6.2","description":"Keep your secrets hidden from AI coding agents.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"^25.3.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/agent-vault_0.1.3_1771488493239_0.4104789456061271","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@botiverse/agent-vault","version":"0.2.0","keywords":["agent","vault","secrets","cli","ai","security","redaction"],"license":"Apache-2.0","_id":"@botiverse/agent-vault@0.2.0","maintainers":[{"name":"richardchien","email":"stdrc@outlook.com"}],"homepage":"https://github.com/botiverse/agent-vault#readme","bugs":{"url":"https://github.com/botiverse/agent-vault/issues"},"bin":{"agent-vault":"dist/cli.js"},"dist":{"shasum":"e9c987141241a459651578215e2b128d54c53d2b","tarball":"https://registry.npmjs.org/@botiverse/agent-vault/-/agent-vault-0.2.0.tgz","fileCount":16,"integrity":"sha512-PQEaf6MsaJuh2h+T+xpnUoB5GcZj24yBwzslV34I9urbIg1G2TSg+RpgXeIBwzsb8dKSS9/7eT6SqzFCt62LEA==","signatures":[{"sig":"MEUCIFdXnsR2bKhoVqT3BhCP/DQLbn3IsRqWtw5eIbCcR3kCAiEA3W8yiJ30MpqyNUzEcoVgftHYJ3JhOJWJnd/Z2NXQbqE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@botiverse%2fagent-vault@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":84955},"type":"module","engines":{"node":">=18"},"gitHead":"62e775a94287ffdf8bf48ca178126366ab7058c0","scripts":{"dev":"tsx src/cli.ts","test":"vitest run","build":"tsc","start":"node dist/cli.js","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1d1096ae-b538-4d69-a794-901c3f7fafc4"}},"repository":{"url":"git+https://github.com/botiverse/agent-vault.git","type":"git"},"_npmVersion":"11.6.2","description":"Keep your secrets hidden from AI coding agents.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"^25.3.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/agent-vault_0.2.0_1771489193404_0.9112611016792482","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@botiverse/agent-vault","version":"0.2.1","keywords":["agent","vault","secrets","cli","ai","security","redaction"],"license":"Apache-2.0","_id":"@botiverse/agent-vault@0.2.1","maintainers":[{"name":"richardchien","email":"stdrc@outlook.com"}],"homepage":"https://github.com/botiverse/agent-vault#readme","bugs":{"url":"https://github.com/botiverse/agent-vault/issues"},"bin":{"agent-vault":"dist/cli.js"},"dist":{"shasum":"65fbc9a645a75130c72b47dc1901b464d3e9ef87","tarball":"https://registry.npmjs.org/@botiverse/agent-vault/-/agent-vault-0.2.1.tgz","fileCount":16,"integrity":"sha512-6Pt7ZOJPh+gr3khKjqNuhLXr7GrsLXv8aJRiMFgk48tfmO92UEyCiOwmkl/nZWv9IUtqCSaheKice8VjR20kog==","signatures":[{"sig":"MEUCIAqLhx14tRNu0h/Uj1uIgQg69gIcG2j7qDJY6PJMc2f2AiEA2JWdgJhHt0dH4lXv7Pir1JWxtL0xWiAIYgKIa5O1JNI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@botiverse%2fagent-vault@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":85348},"type":"module","engines":{"node":">=18"},"gitHead":"f03581c2059583863f51895c003c235358383a54","scripts":{"dev":"tsx src/cli.ts","test":"vitest run","build":"tsc","start":"node dist/cli.js","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1d1096ae-b538-4d69-a794-901c3f7fafc4"}},"repository":{"url":"git+https://github.com/botiverse/agent-vault.git","type":"git"},"_npmVersion":"11.6.2","description":"Keep your secrets hidden from AI agents.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"^25.3.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/agent-vault_0.2.1_1771497595843_0.03517719437213418","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"@botiverse/agent-vault","version":"0.2.2","keywords":["agent","vault","secrets","cli","ai","security","redaction"],"license":"Apache-2.0","_id":"@botiverse/agent-vault@0.2.2","maintainers":[{"name":"richardchien","email":"stdrc@outlook.com"}],"homepage":"https://github.com/botiverse/agent-vault#readme","bugs":{"url":"https://github.com/botiverse/agent-vault/issues"},"bin":{"agent-vault":"dist/cli.js"},"dist":{"shasum":"f42ccf7e8e05502276abe9163d1c60cd50a2ccfa","tarball":"https://registry.npmjs.org/@botiverse/agent-vault/-/agent-vault-0.2.2.tgz","fileCount":16,"integrity":"sha512-N6S3EQbZ2DsekCPRtKsrxMyFp0sSuufEHRHuBOSPRlz4QcPi/21+9cjrMVG9rmfoMiPGzTDoMYRGj+TGy36Xqw==","signatures":[{"sig":"MEQCIApeiacubm7nqPG8MfADTC5W6XTonXrtQreXr7sjgOgzAiA93xnhd4Eemxrf1kzQbveobjc325I6sjtoM8ehSLxF/A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@botiverse%2fagent-vault@0.2.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":85354},"type":"module","engines":{"node":">=18"},"gitHead":"2aa04e34fea11d8e53d60affafbc7e7a2ce733ad","scripts":{"dev":"tsx src/cli.ts","test":"vitest run","build":"tsc","start":"node dist/cli.js","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1d1096ae-b538-4d69-a794-901c3f7fafc4"}},"repository":{"url":"git+https://github.com/botiverse/agent-vault.git","type":"git"},"_npmVersion":"11.6.2","description":"Keep your secrets hidden from AI agents.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"^25.3.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/agent-vault_0.2.2_1771497854572_0.09350882932857907","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@botiverse/agent-vault","version":"0.3.0","keywords":["agent","vault","secrets","cli","ai","security","redaction"],"license":"Apache-2.0","_id":"@botiverse/agent-vault@0.3.0","maintainers":[{"name":"richardchien","email":"stdrc@outlook.com"}],"homepage":"https://github.com/botiverse/agent-vault#readme","bugs":{"url":"https://github.com/botiverse/agent-vault/issues"},"bin":{"agent-vault":"dist/cli.js"},"dist":{"shasum":"dc4aa7498c7db49970945d14432cee85cb8c9f1c","tarball":"https://registry.npmjs.org/@botiverse/agent-vault/-/agent-vault-0.3.0.tgz","fileCount":16,"integrity":"sha512-3IUwFAdbvV1q8wcvuzYxgPcRtCUlUXuSS+q1C12FjWRe+fRp1SQ1VPvA4P6a5ne+8zqpYYojm/D+Bgk4emhbXA==","signatures":[{"sig":"MEUCIQDhYnycou1QDxX3eZeweSVwsDy23T6LXzkCIo2kBbL/hAIgSHCbRu8HGWU2I2gotxspYZv/7pmSTjOGLJcGzG/n9ak=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@botiverse%2fagent-vault@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":90752},"type":"module","engines":{"node":">=18"},"gitHead":"687361b0c24a26ee1a8a927b4aa3fe98da286c44","scripts":{"dev":"tsx src/cli.ts","test":"vitest run","build":"tsc","start":"node dist/cli.js","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1d1096ae-b538-4d69-a794-901c3f7fafc4"}},"repository":{"url":"git+https://github.com/botiverse/agent-vault.git","type":"git"},"_npmVersion":"11.6.2","description":"Keep your secrets hidden from AI agents.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"^25.3.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/agent-vault_0.3.0_1771499400132_0.028933408731430577","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@botiverse/agent-vault","version":"0.4.0","keywords":["agent","vault","secrets","cli","ai","security","redaction"],"license":"Apache-2.0","_id":"@botiverse/agent-vault@0.4.0","maintainers":[{"name":"richardchien","email":"stdrc@outlook.com"}],"homepage":"https://github.com/botiverse/agent-vault#readme","bugs":{"url":"https://github.com/botiverse/agent-vault/issues"},"bin":{"agent-vault":"dist/cli.js"},"dist":{"shasum":"cde13bbd49ef02638a68cc12ced04dc21cfaef40","tarball":"https://registry.npmjs.org/@botiverse/agent-vault/-/agent-vault-0.4.0.tgz","fileCount":16,"integrity":"sha512-D/kVdUtMQwk1C/BcUWxQKvxs0Sjz+kgdmloAlKfRarpf95B6aIeocOYKd2P/NXXEhS18c3YKiV4v9v/2LeHDFA==","signatures":[{"sig":"MEUCICeQ58cfPcRf+Gv9jh2/nRqKqElVNODzvzu3Fj0OXdZsAiEAuCgE28FVKJXfsF8Tvcmnemub2lsOHhIq45zjEq7ez0I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@botiverse%2fagent-vault@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":96898},"type":"module","engines":{"node":">=18"},"gitHead":"8f0bacf22eaa82938e4a8158926b29d82e678321","scripts":{"dev":"tsx src/cli.ts","test":"vitest run","build":"tsc","start":"node dist/cli.js","test:coverage":"vitest run --coverage","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1d1096ae-b538-4d69-a794-901c3f7fafc4"}},"repository":{"url":"git+https://github.com/botiverse/agent-vault.git","type":"git"},"_npmVersion":"11.6.2","description":"Keep your secrets hidden from AI agents.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"commander":"^14.0.3"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","vitest":"^4.0.18","typescript":"^5.9.3","@types/node":"^25.3.0","@vitest/coverage-v8":"^4.0.18"},"_npmOperationalInternal":{"tmp":"tmp/agent-vault_0.4.0_1771507771276_0.853157335819356","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-02-19T07:44:22.346Z","modified":"2026-07-07T16:53:11.336Z","0.1.0":"2026-02-19T07:44:22.611Z","0.1.3":"2026-02-19T08:08:13.379Z","0.2.0":"2026-02-19T08:19:53.568Z","0.2.1":"2026-02-19T10:39:55.986Z","0.2.2":"2026-02-19T10:44:14.706Z","0.3.0":"2026-02-19T11:10:00.274Z","0.4.0":"2026-02-19T13:29:31.435Z"},"bugs":{"url":"https://github.com/botiverse/agent-vault/issues"},"license":"Apache-2.0","homepage":"https://github.com/botiverse/agent-vault#readme","keywords":["agent","vault","secrets","cli","ai","security","redaction"],"repository":{"url":"git+https://github.com/botiverse/agent-vault.git","type":"git"},"description":"Keep your secrets hidden from AI agents.","maintainers":[{"email":"zty0826@gmail.com","name":"tennyzhuang"},{"email":"stdrc@outlook.com","name":"richardchien"},{"email":"yezizp2012@gmail.com","name":"yezizp"},{"email":"lengthmin@gmail.com","name":"lengthmin"},{"email":"xxchan22f@gmail.com","name":"xxchan"}],"readme":"# agent-vault\n\nKeep your secrets hidden from AI agents.\n\nWhen AI agents help you set up services, secrets like API keys and tokens flow through LLM provider servers. **agent-vault** prevents this by acting as a secret-aware file I/O layer — agents see placeholders like `<agent-vault:api-key>`, never real values.\n\n```\n┌──────────────────────────────────────────────┐\n│  Agent sees:                                 │\n│    api_key: <agent-vault:openai-key>         │\n│    bot_token: <agent-vault:tg-bot-token>     │\n│    port: 3000                                │\n├──────────────────────────────────────────────┤\n│  agent-vault                                 │\n│    read:  real value → <agent-vault:key>     │\n│    write: <agent-vault:key> → real value     │\n├──────────────────────────────────────────────┤\n│  Actual file on disk:                        │\n│    api_key: sk-proj-abc123...                │\n│    bot_token: 7821345:AAF...                 │\n│    port: 3000                                │\n└──────────────────────────────────────────────┘\n```\n\n## Install\n\n```bash\nnpm install -g @botiverse/agent-vault\n```\n\n## Quick start\n\n```bash\n# 1. Store a secret (interactive, masked input)\nagent-vault set my-api-key\n\n# 2. Write a config file using placeholders\nagent-vault write config.yaml --content 'api_key: <agent-vault:my-api-key>\nport: 8080'\n\n# 3. Read it back — secrets are redacted\nagent-vault read config.yaml\n#      1  api_key: <agent-vault:my-api-key>\n#      2  port: 8080\n\n# 4. The actual file has real values\ncat config.yaml\n# api_key: sk-proj-abc123...\n# port: 8080\n```\n\n## How it works\n\nSecrets are stored in an encrypted local vault (`~/.agent-vault/`). When reading files, known secret values are replaced with `<agent-vault:key>` placeholders. When writing, placeholders are restored to real values. The agent never sees or transmits your secrets.\n\nHigh-entropy strings not in the vault (like API keys added manually) are automatically detected and redacted as `<agent-vault:UNVAULTED:sha256:XXXXXXXX>`.\n\n## Command reference\n\n### Safe commands\n\nThese commands never expose secret values. Both agents and humans can use them.\n\n#### `agent-vault read <file>`\n\nRead a file with all secrets replaced by `<agent-vault:key>` placeholders. Output format matches `cat -n` (line numbers, plain text).\n\n```bash\nagent-vault read .env\n#      1  TELEGRAM_BOT_TOKEN=<agent-vault:telegram-bot-token>\n#      2  OPENAI_API_KEY=<agent-vault:openai-key>\n#      3  PORT=3000\n```\n\n#### `agent-vault write <file>`\n\nWrite a file, replacing `<agent-vault:key>` placeholders with real secret values.\n\n```bash\n# Via --content flag\nagent-vault write config.yaml --content 'token: <agent-vault:my-token>\nport: 3000'\n\n# Via stdin / heredoc\nagent-vault write config.yaml <<'EOF'\ntoken: <agent-vault:my-token>\nport: 3000\nEOF\n```\n\nFails with a clear error if any referenced key is missing:\n\n```\n✗ Error: Secret \"my-token\" not found in vault\n  To add it, the user should run: agent-vault set my-token\n```\n\n#### `agent-vault has <key> [keys...]`\n\nCheck if one or more keys exist in the vault.\n\n```bash\nagent-vault has my-key           # prints true/false, exit code 0/1\n\nagent-vault has a b c --json     # {\"a\": true, \"b\": false, \"c\": true}\n```\n\n#### `agent-vault list`\n\nList all stored key names (never values).\n\n```bash\nagent-vault list                 # one key per line\nagent-vault list --json          # {\"keys\": [{\"key\": \"...\", \"desc\": \"...\"}]}\n```\n\n### Sensitive commands\n\nThese commands involve secret values or destructive operations. They **require an interactive terminal (TTY)** and refuse to run without one. Agents should never execute these — they should tell the user to run them.\n\n#### `agent-vault set <key>`\n\nStore a secret value. Prompts for masked input. Warns before overwriting an existing key.\n\n```bash\nagent-vault set telegram-bot-token\n# Enter value for \"telegram-bot-token\": ••••••••\n# ✓ Saved \"telegram-bot-token\"\n\nagent-vault set telegram-bot-token    # already exists\n# ⚠ \"telegram-bot-token\" already exists (46 chars, set 2025-01-15T14:30:00.000Z)\n# Overwrite? [y/N]\n\nagent-vault set api-key --desc \"OpenAI API key\"\nagent-vault set api-key --from-env OPENAI_API_KEY\necho \"value\" | agent-vault set api-key --stdin\n```\n\n#### `agent-vault get <key>`\n\nView secret metadata, or the actual value with `--reveal`.\n\n```bash\nagent-vault get my-key\n# Key:      my-key\n# Desc:     My API key\n# Set at:   2025-01-15T14:30:00.000Z\n# Length:   46 chars\n\nagent-vault get my-key --reveal\n# sk-proj-abc123...\n```\n\n`--reveal` additionally checks that stdout is a TTY — you cannot pipe secret values.\n\n#### `agent-vault rm <key>`\n\nRemove a secret from the vault. Asks for confirmation.\n\n```bash\nagent-vault rm old-key\n# Remove \"old-key\"? [y/N]\n```\n\n#### `agent-vault import <file>`\n\nBulk import secrets from a `.env` file. Shows a preview and asks for confirmation. Short/common values (like `localhost`, `3000`) are automatically skipped.\n\n```bash\nagent-vault import .env\n# Found 5 entries:\n#   TELEGRAM_BOT_TOKEN → telegram-bot-token\n#   OPENAI_API_KEY     → openai-key\n#   PORT               → (skip: too short)\n# Import 2 secrets? [Y/n]\n```\n\n#### `agent-vault init`\n\nInitialize the vault at `~/.agent-vault/`. Automatically called on first `set` if no vault exists.\n\n```bash\nagent-vault init\n```\n\n#### `agent-vault scan <file>`\n\nAudit a file for vaulted and potentially unvaulted secrets.\n\n```bash\nagent-vault scan config.yaml\n# Vaulted (2):\n#   line 1: matches \"telegram-bot-token\"\n#   line 2: matches \"openai-key\"\n# Unvaulted suspects (0):\n#   (none)\n```\n\n## Agent integration\n\n### Skill installation\n\n```bash\nnpx skills add botiverse/agent-vault\n```\n\nThe skill teaches agents:\n\n- Use `agent-vault read` instead of the Read tool for secret-bearing files\n- Use `agent-vault write` instead of the Write tool\n- Never execute `set`, `get`, `rm`, `import` — tell the user to run them\n- Use `<agent-vault:key-name>` placeholders in all config content\n\n### How agents work with agent-vault\n\n```\nUser:  \"Help me set up a Telegram bot\"\n\nAgent: Let me check if you have the bot token stored.\n       → executes: agent-vault has telegram-bot-token\n       → false\n\nAgent: I need your Telegram bot token. Please run this in your terminal:\n\n           agent-vault set telegram-bot-token\n\n       You can get the token from @BotFather on Telegram.\n\nUser:  (runs the command, enters token)\nUser:  \"Done\"\n\nAgent: → executes: agent-vault write config.yaml --content '...<agent-vault:telegram-bot-token>...'\n       → ✓ Written config.yaml (1 secret restored)\n\nAgent: Config created. Your bot token is securely stored and I never saw it.\n```\n\n## Vault storage\n\nAll secrets are stored in a single global vault at `~/.agent-vault/`:\n\n```\n~/.agent-vault/\n├── vault.json      # AES-256-GCM encrypted secrets (per-value encryption)\n└── vault.key       # 256-bit master encryption key (0600 permissions)\n```\n\nLiving in the home directory means secrets are shared across all projects and are never at risk of being committed to version control.\n\n## Security\n\n- **Secret values never appear in safe command output** — enforced by code, not convention\n- **TTY requirement on sensitive commands** — prevents agents from calling `set` / `get --reveal` even through prompt injection\n- **High-entropy detection** — unvaulted secrets in files are automatically redacted on read\n- **Vault outside project tree** — lives in `~/.agent-vault/`, never at risk of git commit\n- **Encrypted at rest** — AES-256-GCM with per-value encryption\n- **0600 permissions** — vault files are owner-readable only\n\n## License\n\nApache-2.0\n","readmeFilename":"README.md"}