Skip to content
Closed
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -277,6 +277,7 @@ By creating a `.cursorrules` file in your project's root directory, you can leve
- [Unity (C#)](./rules/unity-cursor-ai-c-cursorrules-prompt-file/.cursorrules) - Cursor rules for Unity development with C# integration.
- [Web App Optimization](./rules/web-app-optimization-cursorrules-prompt-file/.cursorrules) - Cursor rules for web app development with optimization integration.
- [Code Pair Interviews](./rules/code-pair-interviews/.cursorrules) - Cursor rules for code pair interviews development with integration.
- [EnigmAgent MCP — Local Secrets Vault](./rules/enigmagent-mcp-secrets-cursorrules-prompt-file/.cursorrules) - Cursor rules that teach the agent to route every credential through a local AES-256-GCM encrypted vault (enigmagent-mcp) instead of pasting secrets into chat or source files.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated

### Documentation

Expand Down
72 changes: 72 additions & 0 deletions rules/enigmagent-mcp-secrets-cursorrules-prompt-file/.cursorrules
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
# EnigmAgent — Local Encrypted Secrets Vault Rules

You have access to the **enigmagent-mcp** Model Context Protocol server, which provides a local encrypted vault on the user's machine. Vault data is encrypted with AES-256-GCM using an Argon2id-derived key, and never leaves the local filesystem.

## Hard Rules

1. **Never paste secrets into chat or files.** API keys, access tokens, recovery phrases, passwords, private keys, signing keys, JWTs, OAuth refresh tokens, database connection strings with credentials, and any value the user labels "secret", "private", or "sensitive" must go through the vault — never inlined, never echoed back, never written into source files.

2. **Never log, print, or summarize a vault value back to the user.** When you retrieve a secret, use it for the immediate operation only. If you need to confirm the operation succeeded, say "retrieved" — do not display the value.

3. **Detect-and-redirect.** If the user pastes a credential into the conversation, refuse to commit it. Suggest moving it into the vault first:
> "I noticed an API key in your message. Let's store it in EnigmAgent instead — that way it stays encrypted on your machine and out of chat history. Should I save it as `<key-name>`?"

4. **No environment-variable substitution from chat.** Never write `process.env.X = "<actual-value>"` or shell-export a literal secret. Always reference it indirectly: read from the vault at runtime, or load through `dotenv` from a gitignored `.env`.

5. **`.gitignore` discipline.** Before any commit, verify `.env`, `.env.local`, `*.pem`, `*.key`, `id_rsa`, and `~/.enigmagent/` are gitignored. Add them if missing.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated

## Workflow Patterns

### Storing a new secret
When the user says "save this key" / "remember this credential" / "store this token":
1. Ask for a stable name (kebab-case): `openai-prod-key`, `stripe-test-secret`, etc.
2. Call the EnigmAgent MCP `set` tool with `{ name, value }`.
3. Confirm with name only: "Saved as `openai-prod-key`."

### Reading a secret in code
When generating code that needs a credential:
- Prefer reading from `process.env` / `os.environ` populated via dotenv at startup.
- For agent workflows, call the EnigmAgent `get` tool inline rather than embedding the value.
- Never cache the retrieved value in a file the user has not explicitly asked you to write.

### Listing or rotating
- The `list` tool returns names only — safe to display.
- For rotation, call `set` with the same name and the new value. Suggest deleting the old credential at the source provider.

## Detection Heuristics

Treat any of the following as a "this should be in the vault" trigger:

- Strings matching `sk-[A-Za-z0-9]{20,}`, `ghp_[A-Za-z0-9]{36,}`, `xox[bp]-[A-Za-z0-9-]+`, `AIza[0-9A-Za-z_-]{35}`, `AKIA[0-9A-Z]{16}`
- 12 or 24 word phrases that look like BIP-39 mnemonics
- PEM blocks (`-----BEGIN ... PRIVATE KEY-----`)
- Connection strings with `:password@`
- Anything the user prefixes with "secret:", "do not commit:", or "private:"

When detected: stop, suggest vault storage, do not write the literal into any file.

## Setup

If the vault is not yet initialized for the project, run once:

```bash
npx enigmagent-mcp init
```

To use it as an MCP server in Claude Code or Cursor:

```jsonc
// ~/.cursor/mcp.json or .mcp.json
{
"mcpServers": {
"enigmagent": {
"command": "npx",
"args": ["-y", "enigmagent-mcp"]
}
}
}
```
Comment thread
coderabbitai[bot] marked this conversation as resolved.

Repository: https://github.com/Agnuxo1/enigmagent-mcp
npm: https://www.npmjs.com/package/enigmagent-mcp
License: MIT
33 changes: 33 additions & 0 deletions rules/enigmagent-mcp-secrets-cursorrules-prompt-file/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# EnigmAgent MCP — Local Secrets Vault .cursorrules prompt file

Author: [Francisco Angulo de Lafuente](https://github.com/Agnuxo1)

## What you can build

A coding workflow where Cursor / Claude Code never sees a literal secret in chat. The rules teach the agent to:

1. Detect API keys, tokens, mnemonics, and PEM blocks in user input
2. Redirect them into a local encrypted vault via the **enigmagent-mcp** Model Context Protocol server
3. Generate code that reads credentials at runtime instead of inlining them
4. Enforce `.gitignore` discipline before any commit

## Benefits

- **Zero cloud, zero telemetry** — vault file is AES-256-GCM encrypted with an Argon2id-derived key, stored under `~/.enigmagent/`
- **Audit-friendly** — secrets never appear in chat logs, prompt history, or generated source
- **Drop-in MCP** — works in Cursor, Claude Code, and any MCP-compatible host with `npx enigmagent-mcp`

## Synopsis

Developers shipping Cursor or Claude-Code workflows for personal scripts, agent systems, or production apps benefit by keeping API keys, OAuth tokens, recovery phrases, and signing keys out of chat context entirely — the agent learns to route every credential through the encrypted vault and to refuse pasting them back.

## Overview of .cursorrules prompt

The `.cursorrules` file establishes hard rules ("never paste a secret into chat", "never echo a vault value back", "verify gitignore before committing"), workflow patterns for storing / reading / rotating credentials through the EnigmAgent MCP tools (`set`, `get`, `list`), and detection heuristics that recognize common credential formats (`sk-...`, `ghp_...`, AWS access keys, BIP-39 mnemonics, PEM blocks, connection strings with embedded passwords). When triggered, the agent stops and offers to move the value into the vault rather than committing it.

## Links

- Repository: https://github.com/Agnuxo1/enigmagent-mcp
- npm: https://www.npmjs.com/package/enigmagent-mcp
- Glama: https://glama.ai/mcp/servers/Agnuxo1/enigmagent-mcp (security A)
- License: MIT