Claim this agent
agentCLAWHUBUnverified

ResearchVault

Local-first research orchestration engine. Manages state, synthesis, and optional background services (MCP/Watchdog).

OpenClaw

Rank

62

Safety

84

Downloads

5.4k

Updated

Oct 9, 2026

Version

3.0.5

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 5.4K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
5.4K downloadsadoption · observed Oct 9, 2026
Latest release
3.0.5release · observed Feb 16, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17bn1wpkp680gff3pyzyw2v1s84c3ne:researchvault
  1. Install using `clawhub skill install s17bn1wpkp680gff3pyzyw2v1s84c3ne:researchvault` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/lraivisto/researchvault before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/snapshot"

Documentation

CLAWHUB

160,000 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: researchvault
description: "Local-first research orchestration engine. Manages state, synthesis, and optional background services (MCP/Watchdog)."
homepage: https://github.com/lraivisto/ResearchVault
disable-model-invocation: true
user-invocable: true
metadata:
  openclaw:
    emoji: "🦞"
    requires:
      python: ">=3.13"
      env:
        RESEARCHVAULT_DB:
          description: "Optional: Custom path to the SQLite database file."
          required: false
        BRAVE_API_KEY:
          description: "Optional: Brave Search API key."
          required: false
        SERPER_API_KEY:
          description: "Optional: Serper API key."
          required: false
        SEARXNG_BASE_URL:
          description: "Optional: SearXNG base URL."
          required: false
        RESEARCHVAULT_PORTAL_TOKEN:
          description: "Optional: static portal token. If unset, start_portal.sh sources/generates .portal_auth and exports this env var."
          required: false
        RESEARCHVAULT_PORTAL_ALLOWED_DB_ROOTS:
          description: "Optional: comma-separated absolute DB roots. Default: ~/.researchvault,/tmp."
          required: false
        RESEARCHVAULT_PORTAL_STATE_DIR:
          description: "Optional: portal state directory (default ~/.researchvault/portal)."
          required: false
        RESEARCHVAULT_PORTAL_HOST:
          description: "Optional: backend bind host."
          required: false
        RESEARCHVAULT_PORTAL_PORT:
          description: "Optional: backend bind port."
          required: false
        RESEARCHVAULT_PORTAL_FRONTEND_HOST:
          description: "Optional: frontend bind host."
          required: false
        RESEARCHVAULT_PORTAL_FRONTEND_PORT:
          description: "Optional: frontend bind port."
          required: false
        RESEARCHVAULT_PORTAL_CORS_ORIGINS:
          description: "Optional: comma-separated CORS origins for backend."
          required: false
        RESEARCHVAULT_PORTAL_RELOAD:
          description: "Optional: set to 'true' for backend auto-reload."
          required: false
        RESEARCHVAULT_PORTAL_COOKIE_SECURE:
          description: "Optional: set to 'true' to mark auth cookie Secure."
          required: false
        RESEARCHVAULT_PORTAL_PID_DIR:
          description: "Optional: start_portal.sh PID/log directory."
          required: false
        RESEARCHVAULT_PORTAL_SHOW_TOKEN:
          description: "Optional: set to '1' to print tokenized portal URLs."
          required: false
        RESEARCHVAULT_SEARCH_PROVIDERS:
          description: "Optional: search provider order override."
          required: false
        RESEARCHVAULT_WATCHDOG_INGEST_TOP:
          description: "Optional: watchdog ingest top-k override."
          required: false
        RESEARCHVAULT_VERIFY_INGEST_TOP:
          description: "Optional: verify ingest top-k override."
          required: false
        RESEARCHVAULT_MCP_TRANSPORT:
          description: "Optional: MCP server trans

README.md

# ResearchVault 🦞

**The local-first orchestration engine for high-velocity AI research.**

ResearchVault is a local-first state manager and orchestration framework for long-running investigations. It lets you persist projects, findings, evidence, and automation state into a local SQLite "Vault".

Vault is built CLI-first to close the loop between planning, ingestion, verification, and synthesis.

## 🛡️ Security & Privacy

ResearchVault is designed with a **Local-First, Privacy-First** posture:

*   **Local Persistence**: All research data stays on your machine in a local SQLite database (~/.researchvault/research_vault.db). No telemetry or auto-sync.
*   **SSRF Protection**: Strict internal network blocking by default. The tool resolves DNS and blocks private/local/link-local IPs (RFC1918, 127.0.0.1, 169.254.169.254, etc.).
*   **Network Transparency**: Outbound connections are limited to user-requested scuttling or Brave Search API (if configured).
*   **Zero Auto-Start**: No background processes or servers start during installation. Services must be explicitly invoked from `scripts/services/`.
*   **Restricted Model Invocation**: The `disable-model-invocation: true` flag prevents the AI from autonomously triggering side-effects without a direct user prompt.

## 🚀 Installation

### Standard (Recommended)
```bash
python3 -m venv .venv
source .venv/bin/activate
pip install -e .
```

## 🌐 Portal (v3)

Run the portal manually (nothing auto-starts in the background):

```bash
./start_portal.sh
```

- Backend binds to `127.0.0.1:8000`
- Frontend binds to `127.0.0.1:5173`
- Backend auth strictly uses `RESEARCHVAULT_PORTAL_TOKEN`.
- `./start_portal.sh` loads token from `.portal_auth` (or generates it) and exports `RESEARCHVAULT_PORTAL_TOKEN` before launching the backend.
- Use either host for login:
  - `http://127.0.0.1:5173/#token=<token>`
  - `http://localhost:5173/#token=<token>`
- Tokenized URLs are hidden in terminal output by default; read `.portal_auth` (chmod 600) to paste the token manually, or set `RESEARCHVAULT_PORTAL_SHOW_TOKEN=1` to print tokenized URLs.
- Allowed DB roots are constrained by `RESEARCHVAULT_PORTAL_ALLOWED_DB_ROOTS` (default `~/.researchvault,/tmp`).
- OpenClaw workspace DB discovery and selection are disabled in Portal mode (paths under `~/.openclaw/workspace` are rejected).
- Search provider secrets are env-only (read-only in Portal): configure `BRAVE_API_KEY`, `SERPER_API_KEY`, and/or `SEARXNG_BASE_URL` in the backend process environment.
- Provider secrets are never injected by Portal into vault subprocesses.

Process controls:

```bash
./start_portal.sh --status
./start_portal.sh --stop
```

Ingest SSRF behavior matches CLI defaults:
- Private/local/link-local targets are blocked by default.
- Portal checkbox **Allow private networks** maps to CLI `--allow-private-networks`.

## 🛠️ Key Workflows

### 1. Project Management
```bash
python scripts/vault.py init --id "ai-research" --name "AI Research" --objective "Mon

_meta.json

{
  "ownerId": "kn74ffp19fwws5d0f9mr856weh80a5n5",
  "slug": "researchvault",
  "version": "3.0.5",
  "publishedAt": 1771245500096
}

CHANGELOG.md

# Changelog

## [3.0.5] - 2026-02-16

### Security
- Manifest coherence hardening: removed the frontmatter install action from `SKILL.md`, leaving installation as explicit documentation-only shell steps.
- Removed Portal OpenClaw workspace DB behavior: paths under `~/.openclaw/workspace` are denylisted and cannot be discovered or selected, even when custom DB roots are configured.
- Removed Portal provider secret injection behavior: Portal no longer forwards provider secrets into vault subprocess environments.
- Updated portal diagnostics/frontend/docs to match the stricter defaults and removed stale OpenClaw/injection status surfaces.
- Added/updated regression tests covering OpenClaw path denylisting and no-secret-injection subprocess behavior.

## [3.0.4] - 2026-02-16

### Security
- Registry manifest transparency: moved install/env metadata to `metadata.openclaw.install` and `metadata.openclaw.requires.env` so ClawHub-visible fields match behavior.
- DB root enforcement hardened: removed `RESEARCHVAULT_PORTAL_ALLOW_ANY_DB` bypass and introduced `RESEARCHVAULT_PORTAL_ALLOWED_DB_ROOTS` as the only DB root policy input.
- OpenClaw DB scope tightened with explicit gating under allowed DB roots.
- Secrets handling hardened: portal secret persistence/write APIs are disabled; provider secrets are env-only.
- Portal auth consistency: backend remains strict on `RESEARCHVAULT_PORTAL_TOKEN`; `start_portal.sh` now always initializes/exports the token from `.portal_auth` and avoids printing tokenized URLs unless explicitly requested.
- Added regression tests for DB root enforcement, token strictness, and env-only secret behavior.

## [2.6.2] - 2026-02-10

### Security
- **SSRF Hardening**: Implemented strict DNS resolution and IP verification in `scuttle`. Blocks private, local, and link-local addresses by default.
- **Service Isolation**: Moved background services (MCP, Watchdog) to `scripts/services/` to reduce default capability surface.
- **Transparency**: Added `SECURITY.md` and updated `SKILL.md` manifest to explicitly declare optional environment variables.
- **Model Gating**: Explicitly set `disable-model-invocation: true` at the registry manifest level to prevent autonomous AI side-effects.

### Added
- `--allow-private-networks` flag for `vault scuttle` to allow fetching from local addresses when explicitly requested by user.
- Comprehensive provenance info: `LICENSE`, `CONTRIBUTING.md`, and project `homepage`.

### Fixed
- Registry metadata mismatch: standardized frontmatter keys for ClawHub compatibility.
- Removed `uv` requirement from primary installation path.

CONTRIBUTING.md

# Contributing to ResearchVault

Welcome! We appreciate your help in making ResearchVault better.

## How to Contribute

1.  **Report Bugs**: Open an issue on GitHub.
2.  **Suggest Features**: Open an issue to discuss.
3.  **Submit Pull Requests**:
    *   Fork the repository.
    *   Create a feature branch.
    *   Ensure all tests pass (`pytest`).
    *   Submit a PR with a clear description of changes.

## Security Considerations

Since this tool handles web ingestion, please prioritize SSRF safety and data scrubbing in your contributions.
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/lraivisto/skills/researchvault",
      "sourceUrl": "https://clawhub.ai/lraivisto/skills/researchvault",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T04:00:47.039Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T04:00:47.039Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "5.4K downloads",
      "href": "https://clawhub.ai/lraivisto/researchvault",
      "sourceUrl": "https://clawhub.ai/lraivisto/researchvault",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T04:00:47.039Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "3.0.5",
      "href": "https://clawhub.ai/lraivisto/researchvault",
      "sourceUrl": "https://clawhub.ai/lraivisto/researchvault",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-16T12:38:20.096Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 3.0.5",
      "description": "Removed install action mismatch, removed OpenClaw DB access from portal, and removed subprocess secret injection behavior.",
      "href": "https://clawhub.ai/lraivisto/researchvault",
      "sourceUrl": "https://clawhub.ai/lraivisto/researchvault",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-16T12:38:20.096Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to ResearchVault and adjacent AI workflows.