2026-03-26 06:06:51 +00:00
<!-- last - reviewed: 043bf0f0217aef3f319b844f1a1277acd6327a1c -->
2026-03-21 12:44:23 +00:00
# Vault Agent
2026-03-26 00:05:34 +00:00
**Role**: Three-pipeline gate — action safety classification, resource procurement, and human-action drafting.
2026-03-21 18:49:31 +00:00
**Pipeline A — Action Gating (*.json)**: Actions enter a pending queue and are
classified by Claude via `vault-agent.sh` , which can auto-approve (call
`vault-fire.sh` directly), auto-reject (call `vault-reject.sh` ), or escalate
2026-03-22 06:08:58 +00:00
to a human by writing `PHASE:escalate` to a phase file and sending a Matrix
message — using the same unified escalation path as dev/action agents.
2026-03-21 18:49:31 +00:00
**Pipeline B — Procurement (*.md)**: The planner files resource requests as
markdown files in `vault/pending/` . `vault-poll.sh` notifies the human via
Matrix. The human fulfills the request (creates accounts, provisions infra,
adds secrets to `.env` ) and moves the file to `vault/approved/` .
`vault-fire.sh` then extracts the proposed entry and appends it to
`RESOURCES.md` .
2026-03-21 12:44:23 +00:00
2026-03-26 00:05:34 +00:00
**Pipeline C — Rent-a-Human (outreach drafts)**: Any agent can dispatch the
`run-rent-a-human` formula (via an `action` issue) when a task requires a human
touch — posting on Reddit, commenting on HN, signing up for a service, etc.
Claude drafts copy-paste-ready content to `vault/outreach/{platform}/drafts/`
and notifies the human via Matrix for one-click execution. No vault approval
needed — the human reviews and publishes directly.
2026-03-21 12:44:23 +00:00
**Trigger**: `vault-poll.sh` runs every 30 min via cron.
**Key files**:
2026-03-21 18:49:31 +00:00
- `vault/vault-poll.sh` — Processes pending items: retry approved, auto-reject after 48h timeout, invoke vault-agent for JSON actions, notify human for procurement requests
- `vault/vault-agent.sh` — Classifies and routes pending JSON actions via `claude -p` : auto-approve, auto-reject, or escalate to human
2026-03-21 12:44:23 +00:00
- `vault/PROMPT.md` — System prompt for the vault agent's Claude invocation
2026-03-21 18:49:31 +00:00
- `vault/vault-fire.sh` — Executes an approved action (JSON) or writes RESOURCES.md entry (procurement MD)
- `vault/vault-reject.sh` — Marks a JSON action as rejected
2026-03-26 00:05:34 +00:00
- `formulas/run-rent-a-human.toml` — Formula for human-action drafts: Claude researches target platform norms, drafts copy-paste content, writes to `vault/outreach/{platform}/drafts/` , notifies human via Matrix
2026-03-21 18:49:31 +00:00
**Procurement flow**:
1. Planner drops `vault/pending/<name>.md` with what/why/proposed RESOURCES.md entry
2. `vault-poll.sh` notifies human via Matrix
3. Human fulfills: creates account, adds secrets to `.env` , moves file to `vault/approved/`
4. `vault-fire.sh` extracts proposed entry, appends to RESOURCES.md, moves to `vault/fired/`
5. Next planner run reads RESOURCES.md → new capability available → unblocks prerequisite tree
2026-03-21 12:44:23 +00:00
**Environment variables consumed**:
- All from `lib/env.sh`
- `MATRIX_TOKEN` , `MATRIX_ROOM_ID` , `MATRIX_HOMESERVER` — Escalation channel