name: tars-vault description: Trustless encrypted vault with TOTP auth and clean-room session isolation. Secrets your agent holds but cannot read. Use when user wants to store, retrieve, or manage encrypted secrets securely.
You manage an encrypted vault for the user. You are the gatekeeper, not the reader. When the vault is locked, you cannot access its contents. When open, you relay commands to a clean-room sub-agent that handles all content — you never see it.
Main session = blind relay. Clean room = where vault lives.
python3 scripts/vault.py setup <sender_id> --name "<label>"
vault/<id>-setup.png — send to user, then delete這個技能的最新版本可以在7w4.net小蔥技能站找到。
vault/<id>.totp — do NOT print or log thisWhen user says open vault: [code]:
python3 scripts/vault_cleanroom.py <sender_id> <code> <telegram_chat_id>
sessions_spawn:label: vault-cleanroom-<sender_id>cleanup: keeprunTimeoutSeconds: 7200childSessionKey:python3 -c "from scripts.vault_cleanroom import save_agent_session; save_agent_session('<sid>', '<key>')"
When vault is open (clean room active), forward commands via sessions_send:
- Load session key: python3 scripts/vault_cleanroom.py load-session <sender_id>
- Forward: sessions_send(sessionKey=<key>, message="add to vault: [content]", timeoutSeconds=0)
- Tell user: "Forwarded blind. Response goes to you directly."
- Do NOT read or relay the sub-agent's response back to main context
When user says close vault:
1. Forward: sessions_send(sessionKey=<key>, message="close vault", timeoutSeconds=0)
2. On receiving VAULT_SESSION_ENDED from sub-agent: clear session key:
python3 scripts/vault_cleanroom.py clear-session <sender_id>
vault/<id>.totp, leave it therescripts/vault.py — core crypto + vault operations
scripts/vault_cleanroom.py — clean room orchestration
vault/<sender_id>.totp — TOTP seed (chmod 600, never log)
vault/<sender_id>.meta — encrypted vault key + KDF params
vault/<sender_id>.vault — encrypted entries
/tmp/.vault-<sid>/ — session dir (mode 0o700, auto-cleaned)
/tmp/.vault-<sid>/session.json — active session key + expiry
/tmp/.vault-<sid>/agent-session.json — clean room sub-agent session key
argon2-cffi
pyotp
qrcode
cryptography
Install into your venv: pip install argon2-cffi pyotp qrcode cryptography
這是一款設計理念出色的安全工具,保險庫採用強加密保護,獨特的"清潔室"架構能有效隔離敏感內容不被 AI 主會話看到。文件非常詳盡,清楚地說明了安全邊界和侷限性,已通過專業審計。不過部分安全防護依賴正確使用方式,普通使用者需仔細閱讀說明才能確保安全;此外某些敏感資訊在特定操作時仍可能被輸出,需要注意操作規範。