Repository navigation
Add EnigmAgent MCP — Local Secrets Vault cursor rules #268
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
Show all changes
5 commits
Select commit
Hold shift + click to select a range
23117ee
Add EnigmAgent MCP secrets-vault cursor rules
Agnuxo1 1a0593f
Fix CodeRabbit review comments on PR #268
Agnuxo1 0510710
fix: address CodeRabbit review on PR #268
Agnuxo1 c03c9da
Fix CodeRabbit review round 2 on PR #268
Agnuxo1 3265750
Fix CodeRabbit review round 3 on PR #268
Agnuxo1 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
95 changes: 95 additions & 0 deletions
95
rules/enigmagent-mcp-secrets-cursorrules-prompt-file/.cursorrules
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,95 @@ | ||
| # EnigmAgent — Local Encrypted Secrets Vault Rules | ||
|
|
||
| You have access to the **enigmagent-mcp** Model Context Protocol server, which provides a local encrypted vault on the user's machine. Vault data is encrypted with AES-256-GCM using an Argon2id-derived key, and never leaves the local filesystem. | ||
|
|
||
| ## Hard Rules | ||
|
|
||
| 1. **Never paste secrets into chat or files.** API keys, access tokens, recovery phrases, passwords, private keys, signing keys, JWTs, OAuth refresh tokens, database connection strings with credentials, and any value the user labels "secret", "private", or "sensitive" must go through the vault — never inlined, never echoed back, never written into source files. | ||
|
|
||
| 2. **Never log, print, or summarize a vault value back to the user.** When you retrieve a secret, use it for the immediate operation only. If you need to confirm the operation succeeded, say "retrieved" — do not display the value. | ||
|
|
||
| 3. **Detect-and-redirect.** If the user pastes a credential into the conversation, refuse to commit it. Suggest moving it into the vault first: | ||
| > "I noticed an API key in your message. Let's store it in EnigmAgent instead — that way it stays encrypted on your machine and out of chat history. Should I save it as `<key-name>`?" | ||
|
|
||
| 4. **No environment-variable substitution from chat.** Never write `process.env.X = "<actual-value>"` or shell-export a literal secret. Always reference it indirectly: read from the vault at runtime, or load through `dotenv` from a gitignored `.env`. | ||
|
|
||
| 5. **`.gitignore` discipline — repository level.** Before any commit, verify the project's `.gitignore` lists at minimum: `.env`, `.env.local`, `*.pem`, `*.key`, `id_rsa`. Add them if missing. | ||
|
|
||
| 6. **System-level secrets directory — separate concern.** The vault file itself (default `~/.enigmagent/`) lives outside the repository. It is **not** a candidate for the project `.gitignore` because the directory is never inside the repo to begin with. Protect it via the user's global gitignore (`git config --global core.excludesfile`) or by simply keeping the path outside any tracked working tree. If you ever see `~/.enigmagent/` proposed as an entry in a project `.gitignore`, that's a hint the user has misplaced their vault — flag it. | ||
|
|
||
| ## Workflow Patterns | ||
|
|
||
| ### Storing a new secret | ||
| When the user says "save this key" / "remember this credential" / "store this token": | ||
| 1. Ask for a stable name (kebab-case): `openai-prod-key`, `stripe-test-secret`, etc. | ||
| 2. Call the EnigmAgent MCP `set` tool with `{ name, value }`. | ||
| 3. Confirm with name only: "Saved as `openai-prod-key`." | ||
|
|
||
| ### Reading a secret in code | ||
| When generating code that needs a credential: | ||
| - Prefer reading from `process.env` / `os.environ` populated via dotenv at startup. | ||
| - For agent workflows, call the EnigmAgent `get` tool inline rather than embedding the value. | ||
| - Never cache the retrieved value in a file the user has not explicitly asked you to write. | ||
|
|
||
| ### Listing or rotating | ||
| - The `list` tool returns names only — safe to display. | ||
| - For rotation, call `set` with the same name and the new value. Suggest deleting the old credential at the source provider. | ||
|
|
||
| ## Detection Heuristics | ||
|
|
||
| The patterns below are **best-effort triggers, not exhaustive rules** — apply judgment beyond the listed examples and err on the side of pausing when uncertain. | ||
|
|
||
| Treat any of the following as a "this should be in the vault" signal: | ||
|
|
||
| - **Common API key shapes** (unanchored substring matches — intentionally broad): | ||
| - OpenAI: `sk-[A-Za-z0-9]{20,}` · Anthropic: `sk-ant-[A-Za-z0-9-]{20,}` | ||
| - GitHub classic PAT: `ghp_[A-Za-z0-9]{36,}` · Fine-grained PAT: `github_pat_[A-Za-z0-9_]{80,}` | ||
| - Slack bot/user: `xox[bpas]-[A-Za-z0-9-]+` (includes `xoxa-`, `xoxs-`) | ||
| - Stripe live key/restricted: `sk_live_[A-Za-z0-9]{20,}` / `rk_live_[A-Za-z0-9]{20,}` | ||
| - Google API key: `AIza[0-9A-Za-z_-]{35}` | ||
| - AWS access key: `AKIA[0-9A-Z]{16}` | ||
| - **JWT tokens** — strings starting with `eyJ` that decode to a JSON header | ||
| - **12 or 24 word phrases** that look like BIP-39 mnemonics | ||
| - **PEM blocks** — `-----BEGIN ... PRIVATE KEY-----` or `-----BEGIN CERTIFICATE-----` | ||
| - **Credential connection strings** — pattern `://[^\s:]+:[^\s@]+@` (catches `postgres://user:pass@host`, `mongodb://user:pass@host`, etc.) | ||
| - **Explicit labels** — anything the user prefixes with `"secret:"`, `"do not commit:"`, or `"private:"` | ||
|
|
||
| When detected: stop, suggest vault storage, do not write the literal into any file. | ||
|
|
||
| ## Setup | ||
|
|
||
| If the vault is not yet initialized for the project, run once: | ||
|
|
||
| ```bash | ||
| npx enigmagent-mcp init | ||
| ``` | ||
|
|
||
| To use it as an MCP server in Claude Code or Cursor, add the following to `~/.cursor/mcp.json` (or `.mcp.json` in your project root). **The `--vault` argument is required** — replace the path with the absolute path to your encrypted vault file: | ||
|
|
||
| ```jsonc | ||
| // ~/.cursor/mcp.json or .mcp.json | ||
| { | ||
| "mcpServers": { | ||
| "enigmagent": { | ||
| "command": "npx", | ||
| "args": ["-y", "enigmagent-mcp", "--vault", "/absolute/path/to/my.vault.json"] | ||
| } | ||
| } | ||
| } | ||
| ``` | ||
|
|
||
| **Important:** `~` and `%USERPROFILE%` are **not** expanded when the MCP host spawns the process — the string is passed verbatim as `argv` and Node.js `fs` does not perform tilde or environment-variable expansion. Always supply a real absolute path. Cross-platform examples: | ||
|
|
||
| ```jsonc | ||
| // macOS / Linux — replace /Users/<you> with your actual home directory | ||
| { "mcpServers": { "enigmagent": { "command": "npx", "args": ["-y", "enigmagent-mcp", "--vault", "/Users/<you>/.enigmagent/vault.json"] } } } | ||
|
|
||
| // Windows — double backslashes required for valid JSON | ||
| { "mcpServers": { "enigmagent": { "command": "npx", "args": ["-y", "enigmagent-mcp", "--vault", "C:\\Users\\<you>\\.enigmagent\\vault.json"] } } } | ||
| ``` | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
|
|
||
| Alternatively, set the **`ENIGMAGENT_VAULT`** environment variable in the MCP host's env block to avoid hard-coding the path in the config file. | ||
|
|
||
| Repository: https://github.com/Agnuxo1/enigmagent-mcp | ||
| npm: https://www.npmjs.com/package/enigmagent-mcp | ||
| License: MIT | ||
33 changes: 33 additions & 0 deletions
33
rules/enigmagent-mcp-secrets-cursorrules-prompt-file/README.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,33 @@ | ||
| # EnigmAgent MCP — Local Secrets Vault .cursorrules prompt file | ||
|
|
||
| Author: [Francisco Angulo de Lafuente](https://github.com/Agnuxo1) | ||
|
|
||
| ## What you can build | ||
|
|
||
| A coding workflow where Cursor / Claude Code never sees a literal secret in chat. The rules teach the agent to: | ||
|
|
||
| 1. Detect API keys, tokens, mnemonics, and PEM blocks in user input | ||
| 2. Redirect them into a local encrypted vault via the **enigmagent-mcp** Model Context Protocol server | ||
| 3. Generate code that reads credentials at runtime instead of inlining them | ||
| 4. Enforce `.gitignore` discipline before any commit | ||
|
|
||
| ## Benefits | ||
|
|
||
| - **Zero cloud, zero telemetry** — vault file is AES-256-GCM encrypted with an Argon2id-derived key, stored under `~/.enigmagent/` | ||
| - **Audit-friendly** — secrets never appear in chat logs, prompt history, or generated source | ||
| - **Drop-in MCP** — works in Cursor, Claude Code, and any MCP-compatible host with `npx enigmagent-mcp` | ||
|
|
||
| ## Synopsis | ||
|
|
||
| Developers shipping Cursor or Claude-Code workflows for personal scripts, agent systems, or production apps benefit by keeping API keys, OAuth tokens, recovery phrases, and signing keys out of chat context entirely — the agent learns to route every credential through the encrypted vault and to refuse pasting them back. | ||
|
|
||
| ## Overview of .cursorrules prompt | ||
|
|
||
| The `.cursorrules` file establishes hard rules ("never paste a secret into chat", "never echo a vault value back", "verify gitignore before committing"), workflow patterns for storing / reading / rotating credentials through the EnigmAgent MCP tools (`set`, `get`, `list`), and detection heuristics that recognize common credential formats (`sk-...`, `ghp_...`, AWS access keys, BIP-39 mnemonics, PEM blocks, connection strings with embedded passwords). When triggered, the agent stops and offers to move the value into the vault rather than committing it. | ||
|
|
||
| ## Links | ||
|
|
||
| - Repository: https://github.com/Agnuxo1/enigmagent-mcp | ||
| - npm: https://www.npmjs.com/package/enigmagent-mcp | ||
| - Glama: https://glama.ai/mcp/servers/Agnuxo1/enigmagent-mcp (security A) | ||
| - License: MIT |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.