rdmbair13m5-changelog-20260904-1942-fleet-credential-vault-and-agent-hooks
rdmbair13m5-changelog-20260904-1942-fleet-credential-vault-and-agent-hooks
Implemented the fleet-wide credential vault engine
(cred_vault.py), universal agent hooks
(agent_cred_hook.py), and access audit logging
(~/.secrets/access_log.json). Deployed and verified across
all six fleet Macs for Claude Code, Codex, and Antigravity.
[2026-09-04 19:42:00 EDT · rdmbair13m5]
Scope
- Fleet-wide:
rdmsm4x,rdmbair13m5,rdmbair15m5,rdmpw3265m,rdmpw3275m,jdmbair13m5. - Agent harnesses: Claude Code, Codex, Antigravity
(
agy).
What was built and deployed
cred_vault.py(CLI:vault/cred_vault):- Secure credential storage:
~/.secrets/global.env(permissions0600, directory0700). - Audit ledger:
~/.secrets/access_log.json(permissions0600). - Automatic regex extraction of vendor API keys (OpenAI, Anthropic,
Google Gemini, GitHub, GitLab, Slack, Stripe, AWS, Hugging Face),
database URIs with passwords, and assignment statements
(
export VAR=...,password: ...,apiKey: ...). vault get <KEY>: Emits secret to stdout while logging access event (service, target API, email/user, timestamp, caller, incrementing use count).vault set <KEY> <VALUE>: Atomically updates.env/global.envwith dated backup.vault scan: Filters pasted text, extracts credentials, saves them to the vault, masks secrets in the text, and generates guidance for the agent.vault list: Formatted table showing service names, key names, masked previews (****), users, last accessed timestamp, caller, and use counts without revealing raw secrets.vault exec -- <COMMAND>: Runs commands with vault secrets loaded directly into child process environment.
- Secure credential storage:
agent_cred_hook.py:- Universal hook intercepting
UserPromptSubmit(Claude Code & Codex),PreToolUse(Claude Code & Antigravity), andPreInvocation(Antigravity). - Automatically intercepts pasted credentials before they enter transcripts or command lines.
- Stores extracted credentials into
~/.secrets/global.envimmediately. - Injects clean agent context instructing the model on how to access
the credential via
source ~/.secrets/global.envor$(vault get <KEY>). - Redacts raw secrets from prompt strings and command executions.
- Universal hook intercepting
Fleet Deployment & Configuration (
deploy_cred_hooks.zsh):- Deployed scripts to
~/scripts/and symlinks to~/bin/on all 6 hosts. - Configured
~/.claude/settings.jsonon all 6 hosts (preservingpermissions.defaultMode=bypassPermissions). - Configured
~/.codex/hooks.jsonon all 6 hosts. - Configured
~/.gemini/antigravity-cli/hooks.jsonon all 6 hosts. - Canonical source committed to
rdmsm4x:~/dev/fleet/ops/credential-vault/as45e9fe3and pushed tofleetandbackupremotes. - Ticket
FEAT-20260904-12opened and resolved with verification evidence.
- Deployed scripts to
Verification evidence
- Local host
rdmbair13m5:vault listtested, syntheticghp_...prompt scan tested and verified, access log updated, hook registration verified. - Hub host
rdmsm4x:vault listverified against 13 existing fleet credentials;vault get CLOUDFLARE_EMAILexecuted and logged toaccess_log.jsonwith calleragent@rdmsm4x. - Fleet deployment: 6/6 hosts configured and verified via
deploy_cred_hooks.zsh.
How to undo
- Remove hook entries from
~/.claude/settings.json,~/.codex/hooks.json, and~/.gemini/antigravity-cli/hooks.json. - Remove
~/bin/vault,~/bin/cred_vault,~/scripts/cred_vault.py,~/scripts/agent_cred_hook.py.