# Wundervault

> Zero-knowledge MCP secrets vault for AI agents: secrets injected at runtime, never seen by the model

## Facts
- Page: https://tashan.sh/capability/pkg-wundervault-mcp-server
- tashan id: pkg:@wundervault/mcp-server
- Source: https://github.com/wundervault/wundervault-mcp
- npm: https://www.npmjs.com/package/@wundervault/mcp-server
- Type: npm
- Category: other
- tashan score: 50.0 / 100
- Adoption: 28.0
- Upkeep: 67.0
- Freshness: 82.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- npm downloads: 92/week
- License: AGPL-3.0-or-later
- Official: no

## Install

```sh
claude mcp add wundervault-mcp-server -- npx -y @wundervault/mcp-server
```

## Security audit
- Known advisories: 0
- Install-time script: `chmod +x dist/agent.js dist/index.js 2>/dev/null || true`
- Build provenance: not attested

Permissions are read from DECLARED dependencies only. Nothing is executed, so an empty result means "nothing declared", never "nothing possible".

---
Measured 2026-09-12 by tashan (https://tashan.sh) from public evidence. Scorer s5.
