ResearchVault
Local-first research orchestration engine. Manages state, synthesis, and optional background services (MCP/Watchdog).
Rank
62
Safety
84
Downloads
5.4k
Updated
Oct 9, 2026
Version
3.0.5
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 5.4K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 5.4K downloadsadoption · observed Oct 9, 2026
- Latest release
- 3.0.5release · observed Feb 16, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17bn1wpkp680gff3pyzyw2v1s84c3ne:researchvault- Install using `clawhub skill install s17bn1wpkp680gff3pyzyw2v1s84c3ne:researchvault` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/lraivisto/researchvault before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/snapshot"
Documentation
CLAWHUB
160,000 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: researchvault
description: "Local-first research orchestration engine. Manages state, synthesis, and optional background services (MCP/Watchdog)."
homepage: https://github.com/lraivisto/ResearchVault
disable-model-invocation: true
user-invocable: true
metadata:
openclaw:
emoji: "🦞"
requires:
python: ">=3.13"
env:
RESEARCHVAULT_DB:
description: "Optional: Custom path to the SQLite database file."
required: false
BRAVE_API_KEY:
description: "Optional: Brave Search API key."
required: false
SERPER_API_KEY:
description: "Optional: Serper API key."
required: false
SEARXNG_BASE_URL:
description: "Optional: SearXNG base URL."
required: false
RESEARCHVAULT_PORTAL_TOKEN:
description: "Optional: static portal token. If unset, start_portal.sh sources/generates .portal_auth and exports this env var."
required: false
RESEARCHVAULT_PORTAL_ALLOWED_DB_ROOTS:
description: "Optional: comma-separated absolute DB roots. Default: ~/.researchvault,/tmp."
required: false
RESEARCHVAULT_PORTAL_STATE_DIR:
description: "Optional: portal state directory (default ~/.researchvault/portal)."
required: false
RESEARCHVAULT_PORTAL_HOST:
description: "Optional: backend bind host."
required: false
RESEARCHVAULT_PORTAL_PORT:
description: "Optional: backend bind port."
required: false
RESEARCHVAULT_PORTAL_FRONTEND_HOST:
description: "Optional: frontend bind host."
required: false
RESEARCHVAULT_PORTAL_FRONTEND_PORT:
description: "Optional: frontend bind port."
required: false
RESEARCHVAULT_PORTAL_CORS_ORIGINS:
description: "Optional: comma-separated CORS origins for backend."
required: false
RESEARCHVAULT_PORTAL_RELOAD:
description: "Optional: set to 'true' for backend auto-reload."
required: false
RESEARCHVAULT_PORTAL_COOKIE_SECURE:
description: "Optional: set to 'true' to mark auth cookie Secure."
required: false
RESEARCHVAULT_PORTAL_PID_DIR:
description: "Optional: start_portal.sh PID/log directory."
required: false
RESEARCHVAULT_PORTAL_SHOW_TOKEN:
description: "Optional: set to '1' to print tokenized portal URLs."
required: false
RESEARCHVAULT_SEARCH_PROVIDERS:
description: "Optional: search provider order override."
required: false
RESEARCHVAULT_WATCHDOG_INGEST_TOP:
description: "Optional: watchdog ingest top-k override."
required: false
RESEARCHVAULT_VERIFY_INGEST_TOP:
description: "Optional: verify ingest top-k override."
required: false
RESEARCHVAULT_MCP_TRANSPORT:
description: "Optional: MCP server transREADME.md
# ResearchVault 🦞 **The local-first orchestration engine for high-velocity AI research.** ResearchVault is a local-first state manager and orchestration framework for long-running investigations. It lets you persist projects, findings, evidence, and automation state into a local SQLite "Vault". Vault is built CLI-first to close the loop between planning, ingestion, verification, and synthesis. ## 🛡️ Security & Privacy ResearchVault is designed with a **Local-First, Privacy-First** posture: * **Local Persistence**: All research data stays on your machine in a local SQLite database (~/.researchvault/research_vault.db). No telemetry or auto-sync. * **SSRF Protection**: Strict internal network blocking by default. The tool resolves DNS and blocks private/local/link-local IPs (RFC1918, 127.0.0.1, 169.254.169.254, etc.). * **Network Transparency**: Outbound connections are limited to user-requested scuttling or Brave Search API (if configured). * **Zero Auto-Start**: No background processes or servers start during installation. Services must be explicitly invoked from `scripts/services/`. * **Restricted Model Invocation**: The `disable-model-invocation: true` flag prevents the AI from autonomously triggering side-effects without a direct user prompt. ## 🚀 Installation ### Standard (Recommended) ```bash python3 -m venv .venv source .venv/bin/activate pip install -e . ``` ## 🌐 Portal (v3) Run the portal manually (nothing auto-starts in the background): ```bash ./start_portal.sh ``` - Backend binds to `127.0.0.1:8000` - Frontend binds to `127.0.0.1:5173` - Backend auth strictly uses `RESEARCHVAULT_PORTAL_TOKEN`. - `./start_portal.sh` loads token from `.portal_auth` (or generates it) and exports `RESEARCHVAULT_PORTAL_TOKEN` before launching the backend. - Use either host for login: - `http://127.0.0.1:5173/#token=<token>` - `http://localhost:5173/#token=<token>` - Tokenized URLs are hidden in terminal output by default; read `.portal_auth` (chmod 600) to paste the token manually, or set `RESEARCHVAULT_PORTAL_SHOW_TOKEN=1` to print tokenized URLs. - Allowed DB roots are constrained by `RESEARCHVAULT_PORTAL_ALLOWED_DB_ROOTS` (default `~/.researchvault,/tmp`). - OpenClaw workspace DB discovery and selection are disabled in Portal mode (paths under `~/.openclaw/workspace` are rejected). - Search provider secrets are env-only (read-only in Portal): configure `BRAVE_API_KEY`, `SERPER_API_KEY`, and/or `SEARXNG_BASE_URL` in the backend process environment. - Provider secrets are never injected by Portal into vault subprocesses. Process controls: ```bash ./start_portal.sh --status ./start_portal.sh --stop ``` Ingest SSRF behavior matches CLI defaults: - Private/local/link-local targets are blocked by default. - Portal checkbox **Allow private networks** maps to CLI `--allow-private-networks`. ## 🛠️ Key Workflows ### 1. Project Management ```bash python scripts/vault.py init --id "ai-research" --name "AI Research" --objective "Mon
_meta.json
{
"ownerId": "kn74ffp19fwws5d0f9mr856weh80a5n5",
"slug": "researchvault",
"version": "3.0.5",
"publishedAt": 1771245500096
}CHANGELOG.md
# Changelog ## [3.0.5] - 2026-02-16 ### Security - Manifest coherence hardening: removed the frontmatter install action from `SKILL.md`, leaving installation as explicit documentation-only shell steps. - Removed Portal OpenClaw workspace DB behavior: paths under `~/.openclaw/workspace` are denylisted and cannot be discovered or selected, even when custom DB roots are configured. - Removed Portal provider secret injection behavior: Portal no longer forwards provider secrets into vault subprocess environments. - Updated portal diagnostics/frontend/docs to match the stricter defaults and removed stale OpenClaw/injection status surfaces. - Added/updated regression tests covering OpenClaw path denylisting and no-secret-injection subprocess behavior. ## [3.0.4] - 2026-02-16 ### Security - Registry manifest transparency: moved install/env metadata to `metadata.openclaw.install` and `metadata.openclaw.requires.env` so ClawHub-visible fields match behavior. - DB root enforcement hardened: removed `RESEARCHVAULT_PORTAL_ALLOW_ANY_DB` bypass and introduced `RESEARCHVAULT_PORTAL_ALLOWED_DB_ROOTS` as the only DB root policy input. - OpenClaw DB scope tightened with explicit gating under allowed DB roots. - Secrets handling hardened: portal secret persistence/write APIs are disabled; provider secrets are env-only. - Portal auth consistency: backend remains strict on `RESEARCHVAULT_PORTAL_TOKEN`; `start_portal.sh` now always initializes/exports the token from `.portal_auth` and avoids printing tokenized URLs unless explicitly requested. - Added regression tests for DB root enforcement, token strictness, and env-only secret behavior. ## [2.6.2] - 2026-02-10 ### Security - **SSRF Hardening**: Implemented strict DNS resolution and IP verification in `scuttle`. Blocks private, local, and link-local addresses by default. - **Service Isolation**: Moved background services (MCP, Watchdog) to `scripts/services/` to reduce default capability surface. - **Transparency**: Added `SECURITY.md` and updated `SKILL.md` manifest to explicitly declare optional environment variables. - **Model Gating**: Explicitly set `disable-model-invocation: true` at the registry manifest level to prevent autonomous AI side-effects. ### Added - `--allow-private-networks` flag for `vault scuttle` to allow fetching from local addresses when explicitly requested by user. - Comprehensive provenance info: `LICENSE`, `CONTRIBUTING.md`, and project `homepage`. ### Fixed - Registry metadata mismatch: standardized frontmatter keys for ClawHub compatibility. - Removed `uv` requirement from primary installation path.
CONTRIBUTING.md
# Contributing to ResearchVault
Welcome! We appreciate your help in making ResearchVault better.
## How to Contribute
1. **Report Bugs**: Open an issue on GitHub.
2. **Suggest Features**: Open an issue to discuss.
3. **Submit Pull Requests**:
* Fork the repository.
* Create a feature branch.
* Ensure all tests pass (`pytest`).
* Submit a PR with a clear description of changes.
## Security Considerations
Since this tool handles web ingestion, please prioritize SSRF safety and data scrubbing in your contributions.activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/lraivisto/skills/researchvault",
"sourceUrl": "https://clawhub.ai/lraivisto/skills/researchvault",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T04:00:47.039Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T04:00:47.039Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "5.4K downloads",
"href": "https://clawhub.ai/lraivisto/researchvault",
"sourceUrl": "https://clawhub.ai/lraivisto/researchvault",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T04:00:47.039Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "3.0.5",
"href": "https://clawhub.ai/lraivisto/researchvault",
"sourceUrl": "https://clawhub.ai/lraivisto/researchvault",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-16T12:38:20.096Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-lraivisto-researchvault/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 3.0.5",
"description": "Removed install action mismatch, removed OpenClaw DB access from portal, and removed subprocess secret injection behavior.",
"href": "https://clawhub.ai/lraivisto/researchvault",
"sourceUrl": "https://clawhub.ai/lraivisto/researchvault",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-02-16T12:38:20.096Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
