No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by hashicorp · MCP Server · ★ 58
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is vault-mcp-server safe to install? View the security audit →
Vault MCP Server The Vault MCP Server is a Model Context Protocol (MCP) server implementation that provides integration with HashiCorp Vault for managing secrets and mounts. This server uses both stdio and StreamableHTTP transports for MCP communication, making it compatible with Claude for Desktop and other MCP clients. Security Note: At this stage, the MCP server is intended for local use only. If using the StreamableHTTP transport, always configure the MCPALLOWEDORIGINS environment variable to restrict access to trusted origins only. This helps prevent DNS rebinding attacks and other cross-origin vulnerabilities. Security Note: Depending on the query, the MCP server may expose certain Vault data, including Vault secrets, to the MCP client and LLM. Do not use the MCP server with untrusted MCP clients or LLMs. Legal Note: Your use of a third party MCP Client/LLM is subject solely to the terms of use for such MCP/LLM, and IBM is not responsible for the performance of such third party tools.
| Stars | 58 |
| Forks | 25 |
| Language | Go |
| Category | MCP Server |
| License | MPL-2.0 |
| Quality Score | 65.2067484316969/100 |
| Open Issues | 21 |
| Last Updated | 2026-08-20 |
| Created | 2025-06-19 |
| Platforms | go, mcp |
| Est. Tokens | ~18k |
Explore other popular mcp server tools:
vault-mcp-server is an open-source mcp server by hashicorp with 58 GitHub stars.
vault-mcp-server is primarily written in Go. It covers topics such as doormat-managed.
You can find installation instructions and usage details in the vault-mcp-server GitHub repository at github.com/hashicorp/vault-mcp-server. The project has 58 stars and 25 forks, indicating an active community.
vault-mcp-server is released under the MPL-2.0 license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: