trackmcp
Back to directory
Agnuxo1

EnigmAgent

View on GitHub

EnigmAgent — 6-layer encrypted vault for AI agents (AES-256 + ChaCha20 + Blowfish + Fernet + 3DES + RSA). P2P sync via Gun.js. Zero cloud. Part of P2PCLAW.

4 stars PythonOthers Updated Jun 22, 2026
aes-256-gcmai-agentsargon2idencryptionmcpmodel-context-protocolsecrets-managementsecurityvaultcredentialsllm-securitynodejsprivacytypescript

Documentation

EnigmAgent

npm version
npm downloads
License: MIT
Crypto
Glama MCP
GitHub stars
OpenCLAW-P2P
n8n-nodes-enigmagent
langchain-enigmagent
llama-index-tools-enigmagent
crewai-tools-enigmagent

> Last week I asked Claude to push a fix to a private GitHub repo. To do that, Claude needed my personal access token. I had three options, and all three were terrible: paste the token into the chat (and into the provider's logs forever), give the agent a long-lived token it could reuse on its own at 3 a.m., or give up and do it by hand.

EnigmAgent is option four.

Your AI agent types `{{GITHUB_TOKEN}}`. The placeholder leaves the model and travels through the conversation, the logs, the context window — and only at the moment your tool actually needs the credential does EnigmAgent intercept the call, decrypt the real token locally with AES-256-GCM, and inject it. The plaintext exists for one event-loop tick. The model never sees it. The provider never sees it. Your terminal scrollback never sees it.

bash
npx enigmagent-mcp --vault ./my.vault.json

That's the entire install for Claude Desktop, Cursor, Continue.dev, Cline, Open WebUI, AnythingLLM, and LM Studio. A separate browser extension covers everything that lives in a tab.

> ⭐ Star this repo if you've ever pasted a token you regretted.


30-second Claude Desktop setup

Add this to `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS) or `%APPDATA%\Claude\claude_desktop_config.json` (Windows):

json
{
  "mcpServers": {
    "enigmagent": {
      "command": "npx",
      "args": ["-y", "enigmagent-mcp", "--vault", "/absolute/path/to/my.vault.json"]
    }
  }
}

Restart Claude Desktop. Two new tools appear: `enigmagent_resolve` and `enigmagent_list`. Now ask Claude:

> *"List my vault entries, then call my GitHub API with `{{GITHUB_TOKEN}}` in the Authorization header."*

The real token never enters the conversation. Same pattern works for Cursor and Continue.dev below.


The problem (in detail)

When you use an AI agent — Claude, ChatGPT, Cursor, a browser automation tool — to do something that requires credentials, you face an impossible choice:

OptionWhat happens
Paste the secret in the chatIt ends up in AI provider logs, context window, possibly training data
Give the agent a long-lived tokenThe agent can act with full permissions, in any future session
Don't use agents for sensitive tasksYou lose most of the value

EnigmAgent is option D. The agent only ever types `{{GITHUB_TOKEN}}`. The real value never appears in the conversation, in logs, or in the agent's memory.


How it works

code
┌─────────────────┐   types {{GITHUB_TOKEN}}   ┌────────────────────┐
│   LLM / Agent   │ ──────────────────────────▶ │  Tool call / Form  │
│  (any provider) │                             │  (github.com / …)  │
└─────────────────┘                             └─────────┬──────────┘
                                                          │ submit / call (intercepted)
                                                          ▼
                                              ┌───────────────────────┐
                                              │      EnigmAgent       │
                                              │  detects placeholder, │
                                              │  checks domain match, │
                                              │  decrypts → ghp_xxx   │
                                              └───────────┬───────────┘
                                                          │ real value
                                                          ▼
                                              ┌───────────────────────┐
                                              │  Request reissued     │
                                              │  with real credential │
                                              └───────────────────────┘

The plaintext value exists in memory for approximately one event-loop tick. It is never written to the clipboard, never logged, and never visible to any other tab, script, or LLM context.


Install paths

bash
npx enigmagent-mcp --vault ./my.vault.json     # MCP stdio for Claude/Cursor/etc.
npx enigmagent-mcp --mode rest --port 3737     # local REST API for custom integrations

Set `ENIGMAGENT_USER` + `ENIGMAGENT_PASS` env vars to skip the interactive unlock prompt (CI/headless mode).

Browser extension (for credentials inside web forms)

Chrome / Edge / Brave

1. Download the latest release ZIP and unzip it.

2. Go to `chrome://extensions` and enable Developer mode (top-right toggle).

3. Click Load unpacked and select the `extension/` folder.

Firefox

1. Go to `about:debugging#/runtime/this-firefox`.

2. Click Load Temporary Add-on…

3. Select `extension/manifest.json`.

> Signed releases for Chrome Web Store, Firefox AMO, Edge Add-ons, and Opera are in progress.


Per-client config

Claude Desktop

See 30-second setup above.

Cursor

Add to `~/.cursor/mcp.json`:

json
{
  "mcpServers": {
    "enigmagent": {
      "command": "npx",
      "args": ["-y", "enigmagent-mcp", "--vault", "/abs/path/my.vault.json"]
    }
  }
}

Continue.dev

In `~/.continue/config.yaml`:

yaml
mcpServers:
  - name: enigmagent
    command: npx
    args: ["-y", "enigmagent-mcp", "--vault", "/abs/path/my.vault.json"]

Cline (VS Code)

Edit `cline_mcp_settings.json`:

json
{
  "mcpServers": {
    "enigmagent": {
      "command": "npx",
      "args": ["-y", "enigmagent-mcp", "--vault", "/abs/path/my.vault.json"]
    }
  }
}

Open WebUI

Use `mcpo` as the bridge:

bash
mcpo --port 8000 -- npx enigmagent-mcp --vault /abs/path/my.vault.json

Real use cases

Browser-based agents

Tell your agent: *"When you need to authenticate on GitHub, type `{{GITHUB_TOKEN}}` and submit. Do not ask me for the real value."*

The agent types the placeholder. EnigmAgent intercepts, resolves on the bound domain, injects, re-submits. A small badge shows: ✓ submitted with real values.

Document injection (`{{DOC:filename}}`)

Upload a Markdown file as a document secret. Reference it as `{{DOC:system-prompt.md}}` in any text field on its bound domain. Your agent can embed your full system prompt without it appearing in the chat.

Personal data placeholders

code
add NIF @agenciatributaria.gob.es 12345678A
add IBAN @banca.example.com ES9121000418450200051332

Any custom name works. Domain binding is enforced everywhere.


Placeholder syntax reference

SyntaxResolves to
`{{GITHUB_TOKEN}}`Secret named `GITHUB_TOKEN`, only on its bound domain
`{{LOGIN:github.com}}`First secret bound to `github.com`
`{{DOC:report.md}}`Contents of stored document `DOC_report.md`
`{{NIF}}`Personal-data placeholder — any custom name works

Name grammar: `[A-Za-z0-9_:\-.@]+` — case-insensitive.


Security model

LayerImplementation
Password-to-key derivationArgon2id (m=64 MiB, t=3, p=1) — `@noble/hashes@1.4.0`, bundled, reproducible
Secret encryptionAES-256-GCM, 96-bit nonce per entry
Key materialLives in process memory only — never written to disk
Username bindingUsername mixed into Argon2id context: same password + different user = different key
Domain enforcementEvery secret pinned to a domain; resolver refuses mismatched origins
Delivery to siteNative `value` setter + `input`/`change` events — never clipboard, never console
Vault storageEncrypted file on disk, plaintext never persisted

Full threat model: docs/THREAT_MODEL.md. What it does NOT protect against:

  • A compromised process on your machine reading the unlocked session memory
  • A malicious MCP server you've connected to with permission to call `enigmagent_resolve`
  • Side-channels (timing, swap, core dumps) — out of scope for v0.x

EnigmAgent vs. 1Password / Bitwarden / `.env`

1Password / Bitwarden`.env` filesEnigmAgent
Target userHumans logging inDevs avoiding hardcoded secretsAI agents acting on behalf of humans
Core problemFilling logins for humansKeeping secrets out of source controlKeeping secrets out of AI context windows and logs
At restEncrypted (cloud)PlaintextEncrypted (local file)
Visible to LLM contextYes (when human pastes)Yes (when agent cats `.env`)Never
Domain bindingPer-item URL hintNoneEnforced
Cloud syncYesN/ANo — local-only by design

Use 1Password or Bitwarden for your own logins. Use `.env` for your local-dev shorthand. Use EnigmAgent for the credentials your AI agents need to act on your behalf.


Why I built this

EnigmAgent is part of the OpenCLAW / P2PCLAW ecosystem of privacy-preserving local AI tooling — a multi-agent scientific research network where dozens of LLM agents coordinate, evaluate each other, and publish papers. Every one of those agents needs credentials. None of them should have them.

That's the entire problem statement. The vault is just the smallest viable solution.

Francisco Angulo de Lafuente


Repository layout

code
EnigmAgent/
├── extension/              Chrome/Firefox extension (MV3)
├── platforms/firefox-ext/  Firefox manifest variant
├── build-tool/             Reproducible build (esbuild + icon generator)
├── docs/                   ARCHITECTURE.md, THREAT_MODEL.md
│   └── papers/             Background research papers (PDF)
├── examples/               Placeholder schemas
├── tests/                  Smoke tests + crypto round-trip
├── glama.json              Glama MCP server manifest
├── smithery.yaml           Smithery server descriptor
├── PRIVACY.md
├── SECURITY.md             Responsible disclosure
└── README.md

The Node/MCP server source is in the sister repo: Agnuxo1/enigmagent-mcp.


Reproducing the extension build

bash
cd build-tool
npm ci
npx esbuild argon2-entry.js \
  --bundle --minify --format=iife --target=es2020 \
  --outfile=../extension/lib/argon2id.js
python make-icons.py

`package.json` and `package-lock.json` pin `@noble/hashes@1.4.0`. The output is byte-reproducible — verify with `sha256sum extension/lib/argon2id.js`.


Why not just use `.env` files? (Comparison)

ApproachSecret in prompt?Secret in logs?Per-domain binding?Works in CI?
`.env` / environment vars✅ No (but agent can read them)✅ No❌ Global✅ Yes
Paste into chat❌ Yes — permanent❌ Yes — permanent
1Password CLI✅ No✅ No❌ All vault✅ Yes
Doppler / HashiCorp Vault✅ No✅ No❌ Global namespace✅ Yes
EnigmAgentNoNoPer-secret✅ Yes

EnigmAgent is the only option that combines local-first encryption, per-secret domain binding, and zero plaintext in context. The vault file never leaves your machine.


License

MIT — see LICENSE.

Built by

**Francisco Angulo de Lafuente** — independent researcher & developer. 35+ years in software. Also building P2PCLAW (decentralized science network), BenchClaw (agent evaluation), and PaperClaw (autonomous research publishing).

If this tool is useful to you:

  • Star the repo — it's how the AI ecosystem discovers tools
  • 🐛 Open an issue — every real use case sharpens the threat model
  • 📣 Tell one person who still pastes API keys into Claude

🧩 P2PCLAW Ecosystem

This project is part of P2PCLAW — a distributed AI research network with production-grade benchmarking, agent tooling, and model distribution.

ComponentRoleLink
OpenCLAW-P2PCore protocol · Lean 4 proofs · Papersgithub.com/Agnuxo1/OpenCLAW-P2P
BenchClaw17-judge agent benchmarkinggithub.com/Agnuxo1/benchclaw
EnigmAgentLocal encrypted vault for credentialsgithub.com/Agnuxo1/EnigmAgent
AgentBootBare-metal OS installergithub.com/Agnuxo1/AgentBoot
CAJAL4B research LLM for papershuggingface.co/Agnuxo/CAJAL-4B-P2PCLAW

🌐 Main website: https://www.p2pclaw.com/

📄 Paper: arXiv:2604.19792


💝 Support

If this tool is useful to you:

  • Star the repo — it's how the ecosystem discovers tools
  • 🐛 Open an issue — every real use case sharpens the project
  • 💰 Sponsor: github.com/sponsors/Agnuxo1

Built by Francisco Angulo de Lafuente — independent researcher with 35+ years in software.

Frequently asked questions

What is EnigmAgent?

EnigmAgent is EnigmAgent — 6-layer encrypted vault for AI agents (AES-256 + ChaCha20 + Blowfish + Fernet + 3DES + RSA). P2P sync via Gun.js. Zero cloud. Part of P2PCLAW.

How do I install EnigmAgent?

Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

Is EnigmAgent open source?

Yes — it is hosted on GitHub at https://github.com/Agnuxo1/EnigmAgent and has 4 stars.

Related MCP tools

KnockOutEZwigolo

The go-to web for your AI coding agent — local-first search, fetch, crawl & research over MCP. No API keys, no cloud, $0/query. Public beta.

4,906 TypeScript
mcpagentai+17
OpenOSINTOpenOSINT

AI-powered OSINT agent with interactive REPL, MCP server, and CLI. 19 tools. Works with Claude, GPT-4, or local models. For authorized security research only.

1,523 Python
ai-agentanthropicclaude+16
mukul975cve-mcp-server

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.

1,383 Python
cisa-kevclaude-aicve+15
pipeboard-cometa-ads-mcp

Meta Ads (Facebook/Instagram) MCP server for Claude, ChatGPT, Perplexity & Cursor — the Meta node of Pipeboard’s 5-platform family (+ Google, TikTok, Snap, Reddit). Hosted remote MCP, badged Meta Business Partner, free plan — no self-hosting required.

1,233 Python
advertisingai-agentschatgpt+7
riponcmprojectmem

Open-source coding agent memory. Records issues, attempts, fixes and decisions, then warns your agent before it repeats an approach that already failed. Native MCP server for Claude Code, Cursor, Antigravity and Codex. 100% local, no cloud, no telemetry. MIT.

796 Python
ai-agentsai-memoryai-tools+17
luckyPipewrenchpipelock

Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.

833 Go
ai-agentsai-securitydlp+17

Run your own MCP server? See who uses it and what to fix.

Measure it with TrackMCP