Agent skill

Vault User

by mvschwarz in mvschwarz/openrig

A skill your agent uses when checking the health of this rig's HashiCorp Vault or writing, reading, listing, deleting or explaining its secrets.

Apache-2.0Auto-check passedAgent Workflows

Install Vault User

skills CLI
$ npx skills add mvschwarz/openrig --skill vault-user -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mvschwarz/openrig vault-user --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mvschwarz/openrig.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/daemon/specs/agents/apps/vault-specialist/skills/vault-user .claude/skills/vault-user && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vault-user
GitHub stars
5.9k
Used in
1 other repo
Token cost
~451 tokens
SKILL.md length
144 words
Files
1
Skills in repo
49
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when checking the health of this rig's HashiCorp Vault or writing, reading, listing, deleting or explaining its secrets.

  • Checking the health of this rigs HashiCorp Vault
  • SKILL.md covers Connection, Health Check, Secret Operations and Explaining Secrets, plus 1 more section
  • Calls curl and jq
  • Explaining its secrets

What it does

Vault User is an agent skill from mvschwarz/openrig. Use when checking the health of this rig's HashiCorp Vault or writing, reading, listing, deleting or explaining its secrets.

Its SKILL.md is about 450 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. It works with HashiCorp Vault. The repository describes itself as: Build your own network of agents from Claude Code, Codex and Pi: persistent teams with roles, shared context and owned work. The licence is Apache-2.0.

When your agent uses it

  • Checking the health of this rigs HashiCorp Vault
  • Explaining its secrets

Example prompts

  • “/vault-user”

What it can do on your machine

Read from SKILL.md and the folder at commit 1f69831. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vault User loads about 451 tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 144 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~451

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mvschwarz/openrig at commit 1f69831, republished under its Apache-2.0 licence (© mvschwarz). 144 words, ~451 tokens.

Download SKILL.mdSave it as .claude/skills/vault-user/SKILL.md (or your agent's skills folder).
name
vault-user
description
Use when checking the health of this rig's HashiCorp Vault or writing, reading, listing, deleting or explaining its secrets.

Vault User

You have access to a HashiCorp Vault instance managed by this rig's environment.

Connection

  • Address: http://127.0.0.1:8200
  • Token: openrig-dev-token
  • Auth header: X-Vault-Token: openrig-dev-token

Always set the token before making API calls. For curl, use -H "X-Vault-Token: openrig-dev-token".

Health Check

bash
curl -s http://127.0.0.1:8200/v1/sys/health | jq .

A healthy response has "initialized": true and "sealed": false.

Secret Operations

Write a secret
bash
curl -s -X POST http://127.0.0.1:8200/v1/secret/data/<path> \
  -H "X-Vault-Token: openrig-dev-token" \
  -d '{"data": {"key": "value"}}' | jq .
Read a secret
bash
curl -s http://127.0.0.1:8200/v1/secret/data/<path> \
  -H "X-Vault-Token: openrig-dev-token" | jq .

The secret value is in .data.data.

List secrets
bash
curl -s -X LIST http://127.0.0.1:8200/v1/secret/metadata/ \
  -H "X-Vault-Token: openrig-dev-token" | jq .

List a subdirectory by appending the path: .../secret/metadata/<prefix>/.

Delete a secret
bash
curl -s -X DELETE http://127.0.0.1:8200/v1/secret/data/<path> \
  -H "X-Vault-Token: openrig-dev-token"

Explaining Secrets

When asked to explain the current secret structure, list all paths and summarize what each contains. Use the list endpoint recursively if needed.

Important Notes

  • This is Vault dev mode — all data is in-memory and lost on restart
  • The KV secrets engine is mounted at secret/ by default in dev mode
  • Use the rig env status command to verify Vault health through OpenRig before direct probing

© mvschwarz, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/daemon/specs/agents/apps/vault-specialist/skills/vault-user of mvschwarz/openrig.

Open the folder on GitHubat commit 1f69831

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in mvschwarz/openrig, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Vault User next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vault User compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vault User this skillmvschwarz/openrig5.9k1 repos~451Automated safety check: PassApache-2.0
Hashicorp VaultBagelHole/DevOps-Security-Agent-Skills1.1k—~2kAutomated safety check: PassMIT
Secrets Managementdavila7/claude-code-templates32k12 repos~2kAutomated safety check: PassMIT
Secrets Vault Manageralirezarezvani/claude-skills28k1 repos~3.6kAutomated safety check: NotesMIT
Ak Dev New Secret Provideryaalalabs/agent-kernel191—~2.6kAutomated safety check: PassApache-2.0
Implementing Secrets Management With Vaultmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    32k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Secrets Vault Manager

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…

    28k GitHub starsUsed in 1 repo~3.6k tokens
    DevOps & CloudAuto-check: notes
  • Ak Dev New Secret Provider

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm).

    191 GitHub stars~2.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Implementing Secrets Management With Vault

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Managing Secrets

    ancoleman/ai-design-components

    Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes.

    526 GitHub stars~2.9k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed

More from mvschwarz/openrig

All 49 skills in this repo
  • OpenRig Upgrade Procedure

    mvschwarz/openrig

    Walks an agent through upgrading the OpenRig CLI and daemon one observed step at a time, keeping live seats alive and reconciling managed plugin files.

    5.9k GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Agent Refocusing

    mvschwarz/openrig

    Re-grounds a long-running agent in the current product outcome by running a path-based trace to the root of its topology and work trees.

    5.9k GitHub stars~864 tokensUpdated today
    Auto-check passed
  • OpenRig Software Factory

    mvschwarz/openrig

    Helps set up a continuing agent software team for a real repository with OpenRig, choosing between manual work, queue handoffs and an explicit Workflow.

    5.9k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Loads one section of a Markdown file by its path#h2-slug address with a bundled resolver script, for use outside OpenRig's context library.

    5.9k GitHub starsUsed in 1 repo~341 tokens
    Auto-check passed
  • Separates a stable agent seat's identity from its changing occupant, and records honest, two-part provenance whenever one occupant replaces another.

    5.9k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Cross Host Rig Commands

    mvschwarz/openrig

    A skill your agent uses when addressing a registered remote OpenRig host, choosing its transport, or interpreting a cross-host result.

    5.9k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed

Works with

Categories

Questions about Vault User

What does Vault User do?

A skill your agent uses when checking the health of this rig's HashiCorp Vault or writing, reading, listing, deleting or explaining its secrets. Vault User is an agent skill from mvschwarz/openrig. Use when checking the health of this rig's HashiCorp Vault or writing, reading, listing, deleting or explaining its secrets.

When should I use Vault User?

Vault User fits situations like: checking the health of this rigs HashiCorp Vault; explaining its secrets.

How do I install Vault User in Claude Code?

Run `npx skills add mvschwarz/openrig --skill vault-user -a claude-code`. Or copy the skill folder (packages/daemon/specs/agents/apps/vault-specialist/skills/vault-user in mvschwarz/openrig) into .claude/skills/vault-user in your project. Claude Code loads it when a task matches its description.

How do I install Vault User in Codex?

Run `npx skills add mvschwarz/openrig --skill vault-user -a codex`. Or copy the skill folder (packages/daemon/specs/agents/apps/vault-specialist/skills/vault-user in mvschwarz/openrig) into .agents/skills/vault-user in your project. Codex loads it when a task matches its description.

Can I use Vault User in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mvschwarz/openrig --skill vault-user -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vault-user, .gemini/skills/vault-user, .github/skills/vault-user and .opencode/skills/vault-user in your project.

What does Vault User need to run?

Going by SKILL.md and its folder, Vault User needs the command-line tools its instructions call (curl and jq).

Does Vault User access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Vault User safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vault User use?

Vault User is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vault User use?

About 451 tokens (SKILL.md is roughly 1.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vault User?

Skills that share tags, products or a category with Vault User: Hashicorp Vault (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars), Secrets Management (davila7/claude-code-templates, 32k stars), Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars) and Ak Dev New Secret Provider (yaalalabs/agent-kernel, 191 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vault User?

mvschwarz (a GitHub user) maintains it in mvschwarz/openrig, which has 5,854 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 8, 2026.

Source: mvschwarz/openrig on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.