headless-vault-cli
Installation
SKILL.md
Headless Vault CLI
Access Markdown notes on your personal computer from this VPS-hosted bot via SSH tunnel.
Terminology: "Local machine" = your personal computer (macOS or Linux) where your notes live. This skill runs on the VPS and connects to your machine via a reverse SSH tunnel.
Prerequisites
This is an instruction-only skill. Before using it, the user must complete a one-time setup on their local machine:
- Install vaultctl on the local machine (see setup instructions)
- Configure SSH forced-command on the local machine's
~/.ssh/authorized_keysto restrict the VPS key to only runvaultctl(see Security Model below) - Start a reverse SSH tunnel from the local machine to the VPS, exposing
localhost:2222 - Set the environment variable
VAULT_SSH_USERto the local machine's username
Security Model
This skill connects to the local machine over a pre-configured reverse SSH tunnel. Access is restricted by design: