agentreadme

Report · marked 26 Aug 2026

hashicorp/vault

Solid foundations, held back in a few specific places.

Go · 36,167 stars · 9,257 files · branch main

Fix these first

01
Agent instruction file
Rename or symlink to AGENTS.md so tools other than one vendor's can read it. Keeping Copilot instructions alongside it costs nothing.
02
File sizes fit in context
A single file that fills the context window forces an agent to work from fragments, and it will confidently edit code it never saw. Splitting the worst offenders pays for itself immediately.
03
Repository weight
Large binaries and vendored trees slow every operation an agent performs. Git LFS or a separate assets repo keeps the working tree navigable.

The full marking

Every deduction below names the file or setting it came from.

Instructions 20/27 B+

Whether the repo tells an agent how to behave before it starts guessing.

Agent instruction file 8/12
Copilot instructions is present, but not the vendor-neutral AGENTS.md.
Rename or symlink to AGENTS.md so tools other than one vendor's can read it. Keeping Copilot instructions alongside it costs nothing.
Instruction quality 10/12
Specific enough that an agent can act on it.
Worth fixing: has no code blocks.
2,206 characters, a workable length
names the actual commands to run
uses headings, so an agent can skim it
README as an entry point 2/3
README exists but never explains how to get the thing running.
Give the README an Install and a Usage heading with real commands under each. Agents pattern-match on those headings.
Setup 18/20 A

Whether an agent can install the project and get it running without a human.

Deterministic install 6/6
go.sum pins the dependency tree.
Found go.sum
Discoverable commands 6/6
Commands are declared where an agent will look for them.
Makefile
scripts/ directory
Environment config 2/4
Env vars are mentioned in the README but there's no example file to copy.
Add a .env.example listing every variable with a safe placeholder value. It's the cheapest possible fix and it unblocks the whole first run.
Pinned runtime version 2/2
The language runtime version is pinned.
Found .nvmrc
Reproducible environment 2/2
dockerfile gives a known-good environment.
Verification loop 22/22 A+

Whether an agent can check its own work. This is the category that most decides whether agent output is trustworthy.

Tests exist 8/8
1575 test files against 4835 source files.
e.g. api/api_test.go, api/auth/approle/approle_test.go, api/auth/cert/cert_test.go
Test command is discoverable 7/7
An agent can find and run `make test`.
Continuous integration 4/4
35 GitHub Actions workflows define what "passing" means.
Lint and format rules 3/3
.golangci.yml encodes the house style.
Static type checking n/a
Not applicable — the Go compiler type checks every build.
Context economy 13/20 B

Whether the repo fits in a context window, or fights it.

No committed build output 6/6
No generated directories committed.
.gitignore hygiene 3/3
.gitignore covers 100 patterns.
File sizes fit in context 2/6
17 source files are over 100KB.
A single file that fills the context window forces an agent to work from fragments, and it will confidently edit code it never saw. Splitting the worst offenders pays for itself immediately.
builtin/logical/pki/backend_test.go — 291KB
vault/logical_system.go — 241KB
vault/logical_system_test.go — 219KB
Repository weight 2/5
About 359MB checked out. Large enough that cloning and searching are both slow.
Large binaries and vendored trees slow every operation an agent performs. Git LFS or a separate assets repo keeps the working tree navigable.

Here is your AGENTS.md

Drafted from what is actually in this repository: the install command from your lockfile, the commands you already declare, your real directory layout. Anything marked TODO needs a person. Save it at the root as AGENTS.md.

AGENTS.md — drafted for hashicorp/vault
# AGENTS.md

A tool for secrets management, encryption as a service, and privileged access management

## Setup

```
go mod download
```

## Commands

```
make default
make bin
make dev       # run locally
make dev       # run locally
make dev-ui
make dev-ui
```

## Layout

- `ui/`      2361 source files
- `vault/`   480 source files
- `builtin/` 404 source files
- `command/` 365 source files
- `sdk/`     354 source files
- `tools/`   195 source files

## Conventions

- Tests live alongside the code they cover, following `api/api_test.go`.
- CI defines what passing means. See `.github/workflows/actionlint.yml`, and keep it green.
- TODO: add the two or three conventions a newcomer always gets wrong here.

## Gotchas

- `builtin/logical/pki/backend_test.go` is 291KB. It will not fit comfortably in context, so read it in parts.

---

Drafted by agentreadme.com from what is in this repository. Everything marked TODO
needs a human. Check it in as AGENTS.md at the root.

Open the raw markdown  or  curl -o AGENTS.md agentreadme.com/draft/hashicorp/vault.md

Show the mark

The badge re-checks daily, so it keeps up as the repository changes. Use mark again to force it now.

agent ready 79 out of 100

[![agent ready](https://agentreadme.com/badge/hashicorp/vault.svg)](https://agentreadme.com/hashicorp/vault)

Other Go repositories, marked

avelino/awesome-go 78 A- ollama/ollama 85 A golang/go 31 D kubernetes/kubernetes 72 B+ microsoft/TypeScript 82 A- fatedier/frp 96 A+

All Go repositories

Think this mark is wrong?

Every deduction above names the file it came from, so this can be settled by looking. If a check missed something, that is a rule worth fixing.

Open an issue, already filled in