skills/skills.volces.com/headless-vault-cli

headless-vault-cli

Installation
SKILL.md

Headless Vault CLI

Access Markdown notes on your personal computer from this VPS-hosted bot via SSH tunnel.

Terminology: "Local machine" = your personal computer (macOS or Linux) where your notes live. This skill runs on the VPS and connects to your machine via a reverse SSH tunnel.

Prerequisites

This is an instruction-only skill. Before using it, the user must complete a one-time setup on their local machine:

  1. Install vaultctl on the local machine (see setup instructions)
  2. Configure SSH forced-command on the local machine's ~/.ssh/authorized_keys to restrict the VPS key to only run vaultctl (see Security Model below)
  3. Start a reverse SSH tunnel from the local machine to the VPS, exposing localhost:2222
  4. Set the environment variable VAULT_SSH_USER to the local machine's username

Security Model

This skill connects to the local machine over a pre-configured reverse SSH tunnel. Access is restricted by design:

Installs
2
First Seen
Apr 19, 2026
headless-vault-cli from skills.volces.com