Ranking|Claude Code Mods

ModsCode / Claude Code Mods / Ranking / vault

vault

Credential vault for Claude Code: macOS Keychain secrets, per-directory grants, injected env, redacted output, pane with import/export

Code you can checkTerminal + desktopPaneBandStatus lineBoxButtonText
writes files, runs programs, draws

What it does

  • Draws a band above the prompt, a pane, the status line
  • Adds /vault, /vault:vault
  • Watches mcp__vault__vault_list, mcp__vault__vault_exec, Bash calls and can refuse them
  • Hooks session.append, session.start
  • Keeps its own state between turns

Good points

  • No network calls
  • Written in TypeScript
  • Has a desktop-specific branch
  • Handles errors

Code to start from

A starter ModsCode writes from the drawing it read, and the mod's own lines that draw, where there are any.

Starter (register.tsx)

register.tsx
import type { Register } from 'claude-code'

// Drawn like vault by yocloud-code (pane, band, status), as ModsCode read it from the mod's code:
// https://modscode.com/claude-mods/mods/yocloud-code-vault/
// Written by ModsCode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
  // the band above the prompt; what else goes there is drawn under it
  on('ui.render', { component: 'AbovePrompt' }, async ($, e, next) => {
    const { Box, Button, Text } = $.ui.resolve(e)
    const granted = '…'
    return (
      <Box flexDirection="column">
        <Box>
          <Button label="🔐 Vault" />
          <Text dimColor>
            {` 当前目录已授权 ${granted} 个凭证`}
          </Text>
        </Box>
        {await next(e)}
      </Box>
    )
  })

  // the pane: open it with $.ui.open({ id: 'my-pane', title: "🔐 Vault" })
  on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
    const { Box, Text, Button } = $.ui.resolve(e)
    const crumbs = '…'
    const tilde = '…'
    const dirCount = '…'
    const notice = '…'
    const n = '…'
    const type = '…'
    const label = '…'
    const description = '…'
    const ms = '…'
    const ago = '…'
    const count = '…'
    const MODE_LABEL = '…'
    const type2 = '…'
    const description2 = '…'
    const type3 = '…'
    const description3 = '…'
    return (
      <Box flexDirection="column">
        <Box flexDirection="column" borderStyle="round" borderColor="cyan" paddingX={1}>
          <Box justifyContent="space-between" flexWrap="wrap">
            <Box gap={1}>
              <Text bold color="cyan">
                🔐 Vault
              </Text>
              <Text dimColor>
                ›
              </Text>
              <Text bold>
                {crumbs}
              </Text>
            </Box>
            <Text dimColor wrap="truncate-start">
              {tilde}
            </Text>
          </Box>
          <Box gap={2} flexWrap="wrap">
            <Text bold>
              {"● "}
            </Text>
            <Text dimColor>
              {`授权对目录及子目录长期有效 · 共 ${dirCount} 个目录有授权`}
            </Text>
          </Box>
        </Box>
        <Box paddingX={1} marginTop={1}>
          <Text>
            {notice}
          </Text>
        </Box>
        <Box flexDirection="column" borderStyle="round" borderColor="cyan" paddingX={1} marginTop={1}>
          <Box gap={2} flexDirection="column" justifyContent="space-between">
            <Box flexDirection="column" flexGrow={1}>
              <Box gap={1} alignItems="center">
                <Text>
                  🧩
                </Text>
                <Button plain label={`${n}`} />
                <Text dimColor>
                  {type}
                  {` · ${label}`}
                </Text>
              </Box>
              <Text dimColor wrap="truncate-end">
                —
              </Text>
              <Text wrap="truncate-end">
                {description}
              </Text>
              <Text color="green" wrap="truncate-end">
                {`✔ 连接正常 · ${ms}ms · ${ago}`}
              </Text>
              <Text dimColor>
                {`最近使用 ${ago} · 共 ${count} 次`}
              </Text>
            </Box>
            <Box flexDirection="column" alignItems="flex-start" flexShrink={0}>
              <Box gap={2}>
                <Text bold>
                  {"● "}
                </Text>
                <Text bold>
                  {"● "}
                </Text>
              </Box>
              <Box gap={1}>
                <Button label="测试中…" />
                <Button label="编辑" />
                <Button label="先设置密文" variant="primary" />
              </Box>
            </Box>
          </Box>
          <Box gap={1} alignItems="center" flexWrap="wrap" marginTop={1}>
            <Box width={10} flexShrink={0}>
              <Text dimColor>
                当前目录
              </Text>
            </Box>
            <Button label={`${MODE_LABEL}`} variant="primary" />
            <Button label={`${MODE_LABEL}`} variant="primary" />
            <Button label={`${MODE_LABEL}`} variant="primary" />
            <Text dimColor wrap="truncate-start">
              {`继承自 ${tilde}`}
            </Text>
            <Text color="yellow">
              只读不会拦截 SSH 上执行的命令,建议在服务器上用受限账号
            </Text>
          </Box>
        </Box>
        <Box flexDirection="column" borderStyle="round" borderColor="cyan" paddingX={1} marginTop={1}>
          <Box gap={2} flexDirection="column" justifyContent="space-between">
            <Box flexDirection="column" flexGrow={1}>
              <Box gap={1} alignItems="center">
                <Text>
                  🧩
                </Text>
                <Button plain label={`${n}`} />
                <Text dimColor>
                  {type2}
                  {` · ${label}`}
                </Text>
              </Box>
              <Text dimColor wrap="truncate-end">
                —
              </Text>
              <Text wrap="truncate-end">
                {description2}
              </Text>
              <Text color="green" wrap="truncate-end">
                {`✔ 连接正常 · ${ms}ms · ${ago}`}
              </Text>
              <Text dimColor>
                {`最近使用 ${ago} · 共 ${count} 次`}
              </Text>
            </Box>
            <Box flexDirection="column" alignItems="flex-start" flexShrink={0}>
              <Box gap={2}>
                <Text bold>
                  {"● "}
                </Text>
                <Text bold>
                  {"● "}
                </Text>
              </Box>
              <Box gap={1}>
                <Button label="测试中…" />
                <Button label="编辑" />
                <Button label="先设置密文" variant="primary" />
              </Box>
            </Box>
          </Box>
          <Box gap={1} alignItems="center" flexWrap="wrap" marginTop={1}>
            <Box width={10} flexShrink={0}>
              <Text dimColor>
                当前目录
              </Text>
            </Box>
            <Button label={`${MODE_LABEL}`} variant="primary" />
            <Button label={`${MODE_LABEL}`} variant="primary" />
            <Button label={`${MODE_LABEL}`} variant="primary" />
            <Text dimColor wrap="truncate-start">
              {`继承自 ${tilde}`}
            </Text>
            <Text color="yellow">
              只读不会拦截 SSH 上执行的命令,建议在服务器上用受限账号
            </Text>
          </Box>
        </Box>
        <Box flexDirection="column" borderStyle="round" borderColor="cyan" paddingX={1} marginTop={1}>
          <Box gap={2} flexDirection="column" justifyContent="space-between">
            <Box flexDirection="column" flexGrow={1}>
              <Box gap={1} alignItems="center">
                <Text>
                  🧩
                </Text>
                <Button plain label={`${n}`} />
                <Text dimColor>
                  {type3}
                  {` · ${label}`}
                </Text>
              </Box>
              <Text dimColor wrap="truncate-end">
                —
              </Text>
              <Text wrap="truncate-end">
                {description3}
              </Text>
              <Text color="green" wrap="truncate-end">
                {`✔ 连接正常 · ${ms}ms · ${ago}`}
              </Text>
              <Text dimColor>
                {`最近使用 ${ago} · 共 ${count} 次`}
              </Text>
            </Box>
            <Box flexDirection="column" alignItems="flex-start" flexShrink={0}>
              <Box gap={2}>
                <Text bold>
                  {"● "}
                </Text>
                <Text bold>
                  {"● "}
                </Text>
              </Box>
              <Box gap={1}>
                <Button label="测试中…" />
                <Button label="编辑" />
                <Button label="先设置密文" variant="primary" />
              </Box>
            </Box>
          </Box>
          <Box gap={1} alignItems="center" flexWrap="wrap" marginTop={1}>
            <Box width={10} flexShrink={0}>
              <Text dimColor>
                当前目录
              </Text>
            </Box>
            <Button label={`${MODE_LABEL}`} variant="primary" />
            <Button label={`${MODE_LABEL}`} variant="primary" />
            <Button label={`${MODE_LABEL}`} variant="primary" />
            <Text dimColor wrap="truncate-start">
              {`继承自 ${tilde}`}
            </Text>
            <Text color="yellow">
              只读不会拦截 SSH 上执行的命令,建议在服务器上用受限账号
            </Text>
          </Box>
        </Box>
        <Box gap={1} flexWrap="wrap" marginTop={1} />
      </Box>
    )
  })

  on('session.start', async ($, e, next) => {
    const names = '…'
    await $.ui.status(`🔐 vault: ${names}`)
    return next(e)
  })
}

The mod's own code

Its licence text was not found at the commit read, so only the places in the source are linked.

How to build this: Pane (panel), Deny a tool call

What its code calls

runs programswrites filesenv varstool callsremembers

What its code shows

Read from the source at commit 21af55e6a8bf on 2026-10-11. The first group decides whether a mod is listed; the rest is for you to weigh. A later commit is not read until the next crawl.

Decides the listing: code you can check
Entry readEvery module hooks/hooks.json names was read.hooks/register.tsx
ParsesEvery file parses as TypeScript or JavaScript.7 files parsed
All its code is in the modEvery import is a file of the mod or the engine's own module; no packages, no require.all its code is in the mod
ReadableNo minified lines, no eval or new Function, no import of a computed path, no encoded blobs.no minified code, no eval, no encoded blobs
Calls in the openNetwork and programs are reached as $.http.fetch and $.process.run in place, never passed around.every call outside goes through $ in the open
For you to weigh before installing
Where it drawsThe terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.draws in the terminal and the desktop app, the same in both
Install lineWhether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.its repository's .claude-plugin/marketplace.json does not list it: no marketplace line to give; the page shows how to try the commit read
Programs on WindowsWhether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).hooks/register.tsx:46 /usr/bin/security (not on Windows); hooks/register.tsx:73 /usr/bin/security (not on Windows); hooks/register.tsx:79 /usr/bin/security (not on Windows); hooks/register.tsx:91 /usr/bin/security (not on Windows); hooks/register.tsx:101 /usr/bin/security (not on Windows)
NetworkWhether every fetch names its https host in the code.no network
ProgramsWhether every program it starts is named in the code and is not a shell, an interpreter or a network tool.hooks/register.tsx:146 a program named at run time; hooks/register.tsx:295 /bin/sh (a shell or interpreter); hooks/register.tsx:340 /bin/sh (a shell or interpreter); hooks/register.tsx:447 /bin/bash (a shell or interpreter); hooks/register.tsx:579 /bin/sh (a shell or interpreter)
Reads and sendsWhether it both reads something of yours (files, environment variables, the transcript, settings) and reaches outside (the network, an MCP server, another session, telemetry).reads environment variables, files, but reaches nothing outside
Keys in the sourceWhether the source holds what looks like an API key or a private key.no keys in the source
LicenceAn open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets ModsCode show its code; otherwise the code is linked.no licence
Settings hooksHooks declared in hooks/hooks.json or plugin.json beside the module: a command (a shell when it has no args), an HTTP request, an MCP tool or a model prompt at an event. They run outside $.no settings hooks: its function hooks alone
Servers it shipsMCP servers (a program, or a URL; a headersHelper is a shell command; a .mcpb bundle is unpacked at run time), LSP servers, monitors (a shell command for the whole session) and bin/ (on the PATH of the Bash tool).ships no MCP or LSP server, no monitor, no bin/
Skills, commands, agentsWhat its Markdown declares beyond text: allowed-tools granted for the turn, hooks added when a skill is invoked, a command run before Claude reads the skill.1 command: text only
Tools and MCPWhether every tool it calls through $.tool.call and $.mcp.call is named in the code, and none is a shell (Bash through the tool runs a shell without $.process).calls no tool, MCP server or command
Asks of the modelCompletions it runs ($.model.complete, fork, classify), subagents it spawns, prompts it submits as you, and the tools, commands and agents it adds.adds tool vault_list, adds tool vault_exec, adds command vault
Events it hooksBy what a hook there can do: gates (refuse a tool call, a prompt, a setting, another plugin), shapes (what the model reads: the system prompt, tool descriptions, each request), reads (your input, the events of the settings hooks, every event with *), and the rest.gates: tool.call (mcp__vault__vault_list, mcp__vault__vault_exec, Bash), session.append, command.run (vault, vault:vault) · also: session.start, ui.render (AbovePrompt, Pane) · timers: clock.after, clock.every
Reads, by nameThe environment variables and files it names, and whether it reads the transcript, settings.json, the prompt box or the mouse selection.env: HOME; files: …/revision, a path computed at run time
Writes, by nameThe files and environment variables it names, and whether it changes settings, the prompt box, the clipboard, the conversation (a row the model reads) or another session.files: …/revision; the clipboard

This is a reading of the code text, not a security review: it does not run the mod, and it cannot see what a program the mod starts does. The check before installing is yours. How mods are chosen

Install it

Check it yourself before you install it. Mods run unsandboxed, with your permissions, and ModsCode does not vouch for what this code does. Read its code (or run claude plugin validate . in its folder), weigh what it reaches, and install the commit you read.

Its repository's .claude-plugin/marketplace.json does not list it, so there is no marketplace line to give.

Try the commit ModsCode read

No marketplace needed. In a terminal, clone the repository, check out the commit read, validate the mod, and load it for one session:

git clone https://github.com/yocloud-code/claude-vault
git -C claude-vault checkout 21af55e6a8bf5c5bafb1a68b766c6818dda49096
claude plugin validate claude-vault
claude --plugin-dir claude-vault

The validate line lists the events the mod hooks and what it asks Claude Code to do, without running it. The last line loads the mod for this session only and writes nothing to your settings. If the author has rewritten history, the commit may no longer exist.

Ask Claude about it

With the ModsCode connector added, Claude can read this mod's code and what it reaches, and build on them. Ask it like this:

Read the ModsCode mod "yocloud-code-vault" with its code and make me one like it

Search them from Claude: the MCP connector

Similar mods

Badge for your README

If this is your mod, paste this into your README. It links to this page.

README.md
[![ModsCode](https://modscode.com/badge/yocloud-code-vault.svg)](https://modscode.com/claude-mods/mods/yocloud-code-vault/)