跳到主要内容
知仓学习社ZHICANG

vault

>-

执行命令严重 0 · 高危 2glebis/claude-skills

它会碰到什么

扫了多少2 个文本文件,17 KB
它会碰到什么执行命令
命中总数2 处
命中统计严重 0 · 高 2 · 中 0 · 低 0
逐条看命中(2 条严重或高危)
  • scripts/vault.py:57exec-spawn
    res = subprocess.run(
  • scripts/vault.py:262exec-spawn
    subprocess.run(["age-keygen", "-o", key_path], check=True)

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

confide:vault — the THREE LOCKS for storing RED data

Operationalizes the defense-in-depth storage posture in

confide/docs/THREE-LOCKS.md: real (RED) transcripts rest behind **three independent

locks**, so compromising one does not expose a client. To read a real transcript an

attacker needs the device password AND the encrypted-store password AND the

age key — three separate secrets, ideally held in different places.

| Lock | What | Protects against |

|---|---|---|

| 1 — Device | FileVault full-disk encryption + strong login password + short auto-lock | a lost/stolen/USB-booted machine |

| 2 — Store | RED in a dedicated ENCRYPTED store (encrypted APFS volume / AES-256 .dmg), NOT in Documents and NEVER in iCloud/Dropbox | other apps, other users, silent cloud sync |

| 3 — Per-file | each RED file sops/age-encrypted at rest, age key stored SEPARATELY; processing in a no-network VM/container | files individually sealed; key not beside the data |

NON-DESTRUCTIVE — read before running

  • --check (the default) runs only read-only probes: fdesetup status,

shutil.which(sops/age), and os.path.exists(...). It never moves, deletes, or

encrypts data and never runs fdesetup enable, hdiutil, age-keygen, or rm.

  • It reports each lock ✓/✗ and prints the exact command to fix every ✗ — for the user

to review and run themselves.

  • --init-age generates an age key only with that explicit flag, and never

overwrites an existing key.

  • --init-store PATH only prints the encrypted-store creation command; it does not

execute disk-image creation. Refuses cloud-synced paths.

  • Never move, encrypt, or delete the user's RED data on their behalf without explicit

confirmation. There is no destructive default.

Run it

# default = read-only status check + checklist with fix commands
python3 skills/vault/scripts/vault.py --check
python3 skills/vault/scripts/vault.py --json            # structured status dict

# point at your own RED store to verify it's not cloud-synced
python3 skills/vault/scripts/vault.py --store-path ~/CONFIDE-RED.dmg

# optional, GUARDED helpers (explicit flags only)
python3 skills/vault/scripts/vault.py --init-age        # make an age key (never overwrites)
python3 skills/vault/scripts/vault.py --init-store ~/CONFIDE-RED.dmg   # prints the hdiutil command

lock_status() is importable and returns:

{
  "device":  {"filevault": bool},
  "store":   {"present": bool, "path": str|None, "cloud_synced": bool, "safe": bool},
  "perfile": {"sops": bool, "age": bool, "key": bool, "key_path": str|None}
}

How to help the user

  1. Run --check and read back the ✓/✗ checklist.
  2. For each ✗, show the printed fix command (e.g. sudo fdesetup enable,

age-keygen -o ~/.config/confide/age.key,

hdiutil create -encryption AES-256 … ~/CONFIDE-RED.dmg) and let the user run it.

  1. Confirm the RED store is not inside iCloud/Dropbox (store.safe).
  2. Show the sops/age encrypt+decrypt recipe (printed in the checklist) so RED stays

ciphertext at rest and is decrypted only in-memory inside the isolated pipeline

(confide/docs/ISOLATION.md). Only GREEN (redacted) output ever leaves the machine.

See confide/docs/THREE-LOCKS.md (the model + checklist) and confide/docs/ISOLATION.md

(red/green flow, no-network VM/container).

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。