vault
Credential vault for Claude Code: macOS Keychain secrets, per-directory grants, injected env, redacted output, pane with import/export
What it does
- Draws a pane, the status line
- Adds /vault, /vault:vault
- Watches mcp__vault__vault_list, mcp__vault__vault_exec, Bash calls and can refuse them
- Hooks session.append, session.start
- Keeps its own state between turns
Good points
- No network calls
- Written in TypeScript
- Handles errors
Code to start from
Two kinds: a starter modscode writes from the design above, and the lines of the mod's own code that draw it.
Starter (register.tsx)
import type { Register } from 'claude-code'
// Drawn like vault by yocloud-code (pane, status), as modscode read it from the mod's code:
// https://modscode.com/gallery/yocloud-code-vault/
// Written by modscode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
// the pane: open it with $.ui.open({ id: 'my-pane', title: "🔐 Vault" })
on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
const { Box, Text, Button } = $.ui.resolve(e)
const crumbs = '…'
const tilde = '…'
const dirCount = '…'
const notice = '…'
const n = '…'
const type = '…'
const label = '…'
const description = '…'
const ms = '…'
const ago = '…'
const count = '…'
const MODE_LABEL = '…'
const type2 = '…'
const description2 = '…'
const type3 = '…'
const description3 = '…'
return (
<Box flexDirection="column">
<Box flexDirection="column" borderStyle="round" borderColor="cyan" paddingX={1}>
<Box justifyContent="space-between" flexWrap="wrap">
<Box gap={1}>
<Text bold color="cyan">
🔐 Vault
</Text>
<Text dimColor>
›
</Text>
<Text bold>
{crumbs}
</Text>
</Box>
<Text dimColor wrap="truncate-start">
{tilde}
</Text>
</Box>
<Box gap={2} flexWrap="wrap">
<Text bold>
{"● "}
</Text>
<Text dimColor>
{`授权对目录及子目录长期有效 · 共 ${dirCount} 个目录有授权`}
</Text>
</Box>
</Box>
<Box paddingX={1} marginTop={1}>
<Text>
{notice}
</Text>
</Box>
<Box flexDirection="column" borderStyle="round" borderColor="cyan" paddingX={1} marginTop={1}>
<Box gap={2} flexDirection="column" justifyContent="space-between">
<Box flexDirection="column" flexGrow={1}>
<Box gap={1} alignItems="center">
<Text>
🧩
</Text>
<Button plain label={`${n}`} />
<Text dimColor>
{type}
{` · ${label}`}
</Text>
</Box>
<Text dimColor wrap="truncate-end">
—
</Text>
<Text wrap="truncate-end">
{description}
</Text>
<Text color="green" wrap="truncate-end">
{`✔ 连接正常 · ${ms}ms · ${ago}`}
</Text>
<Text dimColor>
{`最近使用 ${ago} · 共 ${count} 次`}
</Text>
</Box>
<Box flexDirection="column" alignItems="flex-start" flexShrink={0}>
<Box gap={2}>
<Text bold>
{"● "}
</Text>
<Text bold>
{"● "}
</Text>
</Box>
<Box gap={1}>
<Button label="测试中…" />
<Button label="编辑" />
<Button label="先设置密文" variant="primary" />
</Box>
</Box>
</Box>
<Box gap={1} alignItems="center" flexWrap="wrap" marginTop={1}>
<Box width={10} flexShrink={0}>
<Text dimColor>
当前目录
</Text>
</Box>
<Button label={`${MODE_LABEL}`} variant="primary" />
<Button label={`${MODE_LABEL}`} variant="primary" />
<Button label={`${MODE_LABEL}`} variant="primary" />
<Text dimColor wrap="truncate-start">
{`继承自 ${tilde}`}
</Text>
<Text color="yellow">
只读不会拦截 SSH 上执行的命令,建议在服务器上用受限账号
</Text>
</Box>
</Box>
<Box flexDirection="column" borderStyle="round" borderColor="cyan" paddingX={1} marginTop={1}>
<Box gap={2} flexDirection="column" justifyContent="space-between">
<Box flexDirection="column" flexGrow={1}>
<Box gap={1} alignItems="center">
<Text>
🧩
</Text>
<Button plain label={`${n}`} />
<Text dimColor>
{type2}
{` · ${label}`}
</Text>
</Box>
<Text dimColor wrap="truncate-end">
—
</Text>
<Text wrap="truncate-end">
{description2}
</Text>
<Text color="green" wrap="truncate-end">
{`✔ 连接正常 · ${ms}ms · ${ago}`}
</Text>
<Text dimColor>
{`最近使用 ${ago} · 共 ${count} 次`}
</Text>
</Box>
<Box flexDirection="column" alignItems="flex-start" flexShrink={0}>
<Box gap={2}>
<Text bold>
{"● "}
</Text>
<Text bold>
{"● "}
</Text>
</Box>
<Box gap={1}>
<Button label="测试中…" />
<Button label="编辑" />
<Button label="先设置密文" variant="primary" />
</Box>
</Box>
</Box>
<Box gap={1} alignItems="center" flexWrap="wrap" marginTop={1}>
<Box width={10} flexShrink={0}>
<Text dimColor>
当前目录
</Text>
</Box>
<Button label={`${MODE_LABEL}`} variant="primary" />
<Button label={`${MODE_LABEL}`} variant="primary" />
<Button label={`${MODE_LABEL}`} variant="primary" />
<Text dimColor wrap="truncate-start">
{`继承自 ${tilde}`}
</Text>
<Text color="yellow">
只读不会拦截 SSH 上执行的命令,建议在服务器上用受限账号
</Text>
</Box>
</Box>
<Box flexDirection="column" borderStyle="round" borderColor="cyan" paddingX={1} marginTop={1}>
<Box gap={2} flexDirection="column" justifyContent="space-between">
<Box flexDirection="column" flexGrow={1}>
<Box gap={1} alignItems="center">
<Text>
🧩
</Text>
<Button plain label={`${n}`} />
<Text dimColor>
{type3}
{` · ${label}`}
</Text>
</Box>
<Text dimColor wrap="truncate-end">
—
</Text>
<Text wrap="truncate-end">
{description3}
</Text>
<Text color="green" wrap="truncate-end">
{`✔ 连接正常 · ${ms}ms · ${ago}`}
</Text>
<Text dimColor>
{`最近使用 ${ago} · 共 ${count} 次`}
</Text>
</Box>
<Box flexDirection="column" alignItems="flex-start" flexShrink={0}>
<Box gap={2}>
<Text bold>
{"● "}
</Text>
<Text bold>
{"● "}
</Text>
</Box>
<Box gap={1}>
<Button label="测试中…" />
<Button label="编辑" />
<Button label="先设置密文" variant="primary" />
</Box>
</Box>
</Box>
<Box gap={1} alignItems="center" flexWrap="wrap" marginTop={1}>
<Box width={10} flexShrink={0}>
<Text dimColor>
当前目录
</Text>
</Box>
<Button label={`${MODE_LABEL}`} variant="primary" />
<Button label={`${MODE_LABEL}`} variant="primary" />
<Button label={`${MODE_LABEL}`} variant="primary" />
<Text dimColor wrap="truncate-start">
{`继承自 ${tilde}`}
</Text>
<Text color="yellow">
只读不会拦截 SSH 上执行的命令,建议在服务器上用受限账号
</Text>
</Box>
</Box>
<Box gap={1} flexWrap="wrap" marginTop={1} />
</Box>
)
})
on('session.start', async ($, e, next) => {
const names = '…'
await $.ui.status(`🔐 vault: ${names}`)
return next(e)
})
}
The mod's own code
Its licence text was not found at the commit read, so only the places in the source are linked.
What its code calls
runs programswrites filesenv varstool callsremembers
The design, read from code
Drawn from the mod's source at the commit read, not from a run: a list is drawn three times, a condition takes its first branch that draws in the desktop app, and a value only the run time knows is shown as a made-up sample (dotted underline) or left out. Colours and type are this site's.
What its code shows
Read from the source at commit b19b9473db21 on 2026-10-06. The first group decides whether a mod is listed; the rest is for you to weigh. A later commit is not read until the next crawl.
| Decides the listing: code you can check | |
|---|---|
| Entry read | Every module hooks/hooks.json names was read.hooks/register.tsx |
| Parses | Every file parses as TypeScript or JavaScript.7 files parsed |
| All its code is in the mod | Every import is a file of the mod or the engine's own module; no packages, no require.all its code is in the mod |
| Readable | No minified lines, no eval or new Function, no import of a computed path, no encoded blobs.no minified code, no eval, no encoded blobs |
| Calls in the open | Network and programs are reached as $.http.fetch and $.process.run in place, never passed around.every call outside goes through $ in the open |
| For you to weigh before installing | |
| Where it draws | The terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.draws in the terminal and the desktop app, the same in both |
| Install line | Whether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.its repository's .claude-plugin/marketplace.json does not list it: no install line to give |
| Programs on Windows | Whether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).hooks/register.tsx:46 /usr/bin/security (not on Windows); hooks/register.tsx:73 /usr/bin/security (not on Windows); hooks/register.tsx:79 /usr/bin/security (not on Windows); hooks/register.tsx:91 /usr/bin/security (not on Windows); hooks/register.tsx:101 /usr/bin/security (not on Windows) |
| Network | Whether every fetch names its https host in the code.no network |
| Programs | Whether every program it starts is named in the code and is not a shell, an interpreter or a network tool.hooks/register.tsx:146 a program named at run time; hooks/register.tsx:295 /bin/sh (a shell or interpreter); hooks/register.tsx:340 /bin/sh (a shell or interpreter); hooks/register.tsx:447 /bin/bash (a shell or interpreter); hooks/register.tsx:579 /bin/sh (a shell or interpreter) |
| Reads and sends | Whether it both reads files or environment variables and reaches the network.reaches no network |
| Keys in the source | Whether the source holds what looks like an API key or a private key.no keys in the source |
| Licence | An open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets modscode show its code; otherwise the code is linked.no licence |
This is a reading of the code text, not a security review: it does not run the mod, and it cannot see what a program the mod starts does. The check before installing is yours. How mods are chosen
Install it
Check it yourself before you install it. Mods run unsandboxed, with your permissions, and modscode does not vouch for what this code does. Read the code below (or run claude plugin validate . in its folder), weigh what it reaches, and install the commit you read.
Its repository's .claude-plugin/marketplace.json does not list it, so there is no install line to give. Read it as code, or follow its author's README.
Ask Claude about it
With the modscode connector added, Claude can read this design, what its code reaches and its code, and build on them. Ask it like this:
Read the modscode design "yocloud-code-vault" with its code and make me a pane like itSearch them from Claude: the MCP connector
Similar designs
-
What it does
- Draws a pane
- Hooks session.end, session.start, ui.close
- Starts processes
-
Ask Claude…2h 10m · █████░░░✓ build ✓ build ✓ buildJavaKotlin3 Python■ ok 3 ■ ok 3 ■ ok 3 Razor proven 3 Razor proven 3 Razor proven 3Phases ──────── 3/3build Pythonbuild Pythonbuild Python… 3 more phasesLua ──────── 3/Kotlin■ the whole upgrade Ruby■ build build Ruby■ build build Ruby■ build build Ruby … 3 moreNext ──────── PythonRuby (by hand)Podsclick a button, or ctrl+x tab then Tab, EnterAttention ──────── 3! Scala ! Scala ! Scala … 3 moreSession ──────── okJava
-
What it does
- Draws a band above the prompt
- Adds /seo-spend, /seo-doctor, /seo-cockpit
- Watches Agent calls and can refuse them
- Hooks agent.spawn, classic.SessionStart, prompt.submit, session.compact and 3 more
-
Open a file first: /crit-tui file <path>Reopen this one in the crit browser view.Ask Claude…
-
Ask Claude…TodayOct 63 left · Mar overdueRemCTL: Sep✓ All done for today.● build3● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● build3● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● build3● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓Updated 14:32UndoRefresh
-
Ask Claude…TO graph› Fix login › Fix login › Fix loginScopeThis featureWhole projectHide done stepsReconnect