πŸ”„ Topic

Setting up an Obsidian vault, synced to my iPhone, as the human-readable memory layer for the local agent system.


🎯 Goal

Make agent knowledge durable and reviewable: agents write structured notes to defined routes, and I can read everything from my phone.


πŸ›  What I Did

I documented and wired up the RAG vault: an Obsidian vault that acts as the human memory layer on top of the agents’ file-based memory. Agents route their outputs β€” audit notes, report drafts, operational summaries β€” into specific inbox folders with frontmatter tags, following written rules in an agent index. I ran smoke tests to confirm routed capture lands in exactly the right paths, and because the vault syncs to the iPhone, the whole system’s memory is reviewable from anywhere.

Main areas covered:

  • Obsidian vault as human-readable agent memory
  • routed capture into inbox folders by category
  • frontmatter metadata for source and route
  • written rules governing what agents may write
  • smoke tests verifying capture paths
  • iPhone sync for review from anywhere

πŸ”— Key Cybersecurity Connections

An agent-writable knowledge base is a data governance problem. Write rules are an access policy, routed paths are a controlled interface, and the no-secrets rule matters doubly when the vault syncs to a phone. Reviewability is what turns agent memory from a black box into an audit trail.


πŸ” Investigation Questions

  • What are agents allowed to write, and where is that defined?
  • Could a confused agent write outside its approved routes?
  • Is anything sensitive syncing to the phone?
  • Can I attribute every note to the agent and task that produced it?
  • What happens if the vault and the agents’ file memory disagree?

🚨 Detection Opportunities

Potential monitoring ideas:

  • notes written outside approved inbox routes
  • notes missing source or route metadata
  • secret-like strings appearing in vault files
  • unexpected volume spikes in agent-written notes
  • sync conflicts as a tampering or drift signal

Example:

project=rag-vault
change_type=agent_written_note
risk_area=uncontrolled_knowledge_capture
triage=verify_route_metadata_and_content_policy

🧭 MITRE ATT&CK Techniques

Possible mappings depending on confirmed behavior:

  • T1565 β€” Data Manipulation
  • T1530 β€” Data from Cloud Storage
  • T1119 β€” Automated Collection

πŸ—Ί Visual Investigation Diagram

Agent output
    ↓ Routing rules
    ↓ Vault inbox folders
    ↓ iPhone sync
    ↓ Human review anywhere

⚠ Challenges

The challenge was defining boundaries before convenience took over. It is tempting to let agents write anything anywhere; then the vault becomes a landfill nobody audits.


πŸ“š What I Learned

I learned that memory design is trust design. Deciding what agents may remember, where they may write it, and who reviews it is the same exercise as scoping any system’s data flows.


➑ Next Steps

  • Keep the agent write rules short and enforced
  • Periodically scan the vault for secret-like content
  • Review the inbox folders on a regular schedule
  • Extend routed capture to new task families carefully

🧠 Reflection

This was useful because it made the invisible visible: everything my agents learn or produce now lands somewhere I can read, question, and correct β€” even from my phone.


🧩 Lessons Learned

What worked

Written write-rules and routed inbox folders from the start.

What broke

Early notes with duplicated headers and loose formatting.

Why it broke

The capture templates were newer than the agents using them.

Fix / takeaway

Version the templates with the rules, and smoke-test the routes.


πŸ“ˆ Skill Progression Context

This supports my cybersecurity progression because governed data flows, audit trails, and reviewable automation are core to how organizations keep AI systems accountable.


πŸ˜„ TL;DR

My agents keep a diary; I set the rules and read it anywhere.