# OpenCLI Agent Pack: Vault

Use this when an AI agent needs to work with `vault`.

## What this CLI is for
The official CLI from HashiCorp. Secrets, identity, and pki from the terminal. Supports structured output — good for scripts and agents.

Best for: secrets, identity, and pki from the terminal.

## Agent readiness
Great for agents (75/100)
- Structured output is available for parsing.
- Supports non-interactive/scripted use.
- Works well in CI or repeatable automation.

## Install
```sh
brew tap hashicorp/tap && brew install hashicorp/tap/vault
```

## Verify before real work
```sh
vault --help
```
Expected signal: vault responds locally; authenticate before real work.

## Safe starting commands
```sh
vault --help
```

```sh
vault server -dev
```

## Guardrails for agents
- Verify identity/account before running task commands.
- Require confirmation before apply, delete, deploy, transfer, merge, or write actions.

## Suggested agent instruction
You may use Vault (`vault`) for secrets, identity, and pki from the terminal.. First install it if missing, then run the verify command. Start with read-only or inspection commands. Summarize what you found before changing anything. Ask for confirmation before commands that mutate remote state, spend money, deploy, delete data, merge code, or expose secrets.

Source: OpenCLI
