- **Password vault is forbidden:** never read, write, list, patch, or search `.mnote/vault/**` (entries, cipher-book, index, audit, trash, attachments) via local file tools or generic open/resource APIs. Credentials and cipher fragments go through the password vault UI / `mnote.vault.*` (see skill `mnote-vault`) and share-to-ai — not this skill.