Claim this agent
agentCLAWHUBUnverified

Bitwarden Secrets Manager CLI

Use Bitwarden Secrets Manager safely

OpenClaw

Rank

62

Safety

84

Downloads

2.9k

Updated

Oct 9, 2026

Version

0.1.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2.9K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
2.9K downloadsadoption · observed Oct 9, 2026
Latest release
0.1.0release · observed Jul 25, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17dmjpd250973tjtpk2e7fdmx885wc8:bitwarden-secrets-manager-cli
  1. Install using `clawhub skill install s17dmjpd250973tjtpk2e7fdmx885wc8:bitwarden-secrets-manager-cli` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/snapshot"

Documentation

CLAWHUB

22,658 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: bitwarden-secrets-manager-cli
description: Operate Bitwarden Secrets Manager through the `bws` CLI, including installing the CLI when missing, authenticating with machine-account access tokens, configuring US, EU, or self-hosted servers, listing and managing projects and secrets, and injecting secrets into trusted processes. Use for requests involving Bitwarden Secrets Manager, `bws`, `BWS_ACCESS_TOKEN`, machine accounts, secret retrieval, secret injection, or Secrets Manager automation and CI/CD.
---

# Bitwarden Secrets Manager CLI

Use `bws` with secret-safe defaults.
Install it when missing, authenticate without exposing the access token, inspect read-only state first, and make mutations only when the requested scope is exact.

## Start every task

1. Run `scripts/ensure-bws.sh`.
   On native Windows without a POSIX shell, use the official PowerShell installer documented in [references/cli-guide.md](references/cli-guide.md).
2. Run `bws --version` and `bws --help` when command behavior may vary by version.
3. Determine the server before authenticating.
   Bitwarden US is the default.
   Configure EU or self-hosted deployments only when the user identifies that environment.
4. Use an existing `BWS_ACCESS_TOKEN` environment variable.
   If none exists, ask the user to inject or export the token in their own secure environment.
5. Run `scripts/check-auth.sh` to perform a read-only authentication check that emits no vault data.

Read [references/cli-guide.md](references/cli-guide.md) for command syntax, output behavior, configuration, and troubleshooting.
Use the live `bws <command> --help` output and linked official Bitwarden documentation as the final authority.

## Protect credentials and secret values

- Never print, repeat, summarize, or commit an access token or secret value.
- Never place an access token directly in a command line with `--access-token`.
  Command arguments can appear in shell history, process listings, logs, and agent traces.
- Prefer runtime secret injection or an already-set `BWS_ACCESS_TOKEN`.
  If secure injection is unavailable, ask the user to export it in their own shell and confirm when ready.
- Do not create `.env` files unless the user explicitly asks.
  If one is required, keep it outside version control, restrict permissions, and verify that Git ignores it.
- Do not expose raw `bws secret list` or `bws secret get` JSON in logs because both include secret values.
- Use `scripts/list-secret-metadata.sh [PROJECT_ID]` when only IDs and keys are needed.
- Prefer `bws run` to pass values directly to a trusted process instead of retrieving and displaying them.
- Use `--output none` for mutations unless returned metadata is required.

If a token appears in conversation or tool output, do not echo it.
Recommend rotation if it was exposed in a durable or public location.

## Work read-only first

Resolve the exact organization-visible objects before changing anything:

```bash
bws project list --output table
sc

README.md

# Bitwarden Secrets Manager CLI Skill

An Agent Skill for working safely with [Bitwarden Secrets Manager](https://bitwarden.com/products/secrets-manager/) through the `bws` command-line interface.

The skill helps AI coding agents install and operate `bws`, authenticate with a machine-account access token, inspect projects and secrets, inject secrets into trusted processes, and manage Secrets Manager resources without exposing sensitive values.

This repository follows the open [Agent Skills specification](https://agentskills.io) and can be installed with the [Skills CLI](https://github.com/vercel-labs/skills) into Codex, Claude Code, Cursor, and other supported agents.

> [!IMPORTANT]
> `bws` is the Bitwarden Secrets Manager CLI.
> It is separate from the `bw` CLI used with Bitwarden Password Manager.

## Install

Install the skill with the standard Skills CLI command:

```bash
npx skills add hajekt2/bitwarden-secrets-manager-cli
```

The installer detects supported agents and asks where to install the skill.
Project installation is the default.

Install it globally for use across projects:

```bash
npx skills add hajekt2/bitwarden-secrets-manager-cli -g
```

Install it globally for Codex without interactive prompts:

```bash
npx skills add hajekt2/bitwarden-secrets-manager-cli \
  --skill bitwarden-secrets-manager-cli \
  --agent codex \
  --global \
  --yes
```

List the skill without installing it:

```bash
npx skills add hajekt2/bitwarden-secrets-manager-cli --list
```

The Skills CLI requires Node.js and npm.
See the [Skills CLI documentation](https://github.com/vercel-labs/skills) for supported agents, installation scopes, and additional options.

## What the skill does

- Installs `bws` from Bitwarden's official installer when the CLI is missing.
- Supports Bitwarden US, Bitwarden EU, and self-hosted server configuration.
- Authenticates through the `BWS_ACCESS_TOKEN` environment variable.
- Validates authentication with a read-only request that prints no vault data.
- Lists secret metadata without printing secret values or notes.
- Retrieves and injects secrets without exposing them in agent output.
- Guides safe project and secret creation, editing, and deletion.
- Uses `bws run` to inject secrets directly into trusted processes.
- Uses live `bws --help` output and Bitwarden documentation as the final authority.

## Authentication

Create an access token for a [Bitwarden Secrets Manager machine account](https://bitwarden.com/help/access-tokens/).
The machine account must have access to the projects and secrets required by the task.

Provide the token as `BWS_ACCESS_TOKEN` in the environment where the agent runs.
For example, read it without echoing it in Bash:

```bash
read -rsp "BWS access token: " BWS_ACCESS_TOKEN
printf '\n'
export BWS_ACCESS_TOKEN
```

Use your shell, CI secret store, agent runtime, or another secure environment-injection mechanism to set the value.
Do not paste the token into prompts, commit it, store it in tracked

_meta.json

{
  "ownerId": "kn79sz4h2hzc5wxxtarf1zr47980m8bj",
  "slug": "bitwarden-secrets-manager-cli",
  "version": "0.1.0",
  "publishedAt": 1785018265235
}

references/cli-guide.md

# `bws` CLI guide

This guide summarizes the official Bitwarden Secrets Manager CLI documentation.
Check the live sources and `bws <command> --help` before relying on version-sensitive behavior.

Official sources:

- [Secrets Manager CLI](https://bitwarden.com/help/secrets-manager-cli/)
- [Access tokens](https://bitwarden.com/help/access-tokens/)
- [`bws` source and releases](https://github.com/bitwarden/sdk-sm)

## Install

Bitwarden provides native binaries for Linux, macOS, and Windows.
Its official installers download a release archive and verify its SHA-256 checksum.

POSIX:

```bash
curl -fsSL https://bws.bitwarden.com/install -o /tmp/install-bws.sh
sh /tmp/install-bws.sh
```

PowerShell:

```powershell
iwr https://bws.bitwarden.com/install | iex
```

Cargo:

```bash
cargo install bws --locked
```

Docker:

```bash
docker run --rm -it ghcr.io/bitwarden/bws --help
```

The bundled `scripts/ensure-bws.sh` uses the official POSIX installer only when `bws` is not already on `PATH`.

## Authenticate

Create an access token for a Bitwarden Secrets Manager machine account.
The token can access only the projects and secrets assigned to that machine account.
Bitwarden does not retain a recoverable copy of the token after creation.

Prefer an environment variable:

```bash
export BWS_ACCESS_TOKEN='set-this-in-your-own-secure-shell'
```

Do not include the real value in documentation, committed files, shell history, process arguments, chat output, or agent tool calls.
Although `bws` supports `--access-token`, avoid it because command arguments are easier to expose.

Validate authentication without printing vault data:

```bash
bws project list --output none
```

Frequent new sessions from one IP address can be rate-limited.
The CLI stores encrypted authentication state under `~/.config/bws/state` by default to reduce repeated authentication.

## Configure a server

Bitwarden US is the default.
EU and self-hosted users must configure their server.

```bash
bws config server-base https://vault.bitwarden.eu
bws config server-base https://bitwarden.example.com
```

The default config is `~/.config/bws/config`.
Use `--profile`, `BWS_PROFILE`, `--config-file`, or `BWS_CONFIG_FILE` to isolate configurations.
Use `--server-url` or `BWS_SERVER_URL` for a per-command override.

## Outputs

Supported output formats are `json`, `yaml`, `env`, `table`, `tsv`, and `none`.
JSON is the default.

Secret `get` and `list` output includes decrypted values.
Do not print it when only IDs, keys, or status are needed.

Use:

```bash
scripts/list-secret-metadata.sh
scripts/list-secret-metadata.sh "$PROJECT_ID"
```

Use `--output none` for writes when no response body is required.
The `env` output format comments out non-POSIX key names, but it still contains secret values and must be treated as sensitive.

## Projects

```bash
bws project list
bws project get "$PROJECT_ID"
bws project create "$NAME"
bws project edit "$PROJECT_ID" --name "$NEW_NAME"
bws project delete "$PROJEC

skill-card.md

## Description:

Operate Bitwarden Secrets Manager through the bws CLI, including installing the CLI when missing, authenticating with machine-account access tokens, configuring US, EU, or self-hosted servers, listing and managing projects and secrets, and injecting secrets into trusted processes.

This skill is ready for commercial/non-commercial use.

## Publisher:

[hajekt2](https://clawhub.ai/user/hajekt2)

### License/Terms of Use:

MIT

## Use Case:

Developers and engineers use this skill to operate Bitwarden Secrets Manager through bws while installing the CLI, validating authentication, inspecting metadata, configuring server targets, and injecting or managing secrets with safeguards against accidental disclosure.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The skill can automatically download and run a mutable remote installer when bws is missing.

Mitigation: Prefer installing bws from a verified Bitwarden source before using the skill, and review the installer path when automatic installation is allowed.

Risk: The skill operates on real Bitwarden machine-account tokens and decrypted secret values.

Mitigation: Use least-privilege machine-account tokens, keep credentials out of prompts and logs, and restrict agents to trusted runtime secret-injection paths.

Risk: Creating or editing secrets may expose values through command arguments or shell traces.

Mitigation: Allow secret writes only when the scope is exact, disable shell tracing, avoid literal values in command history, and prefer trusted process injection for secret consumption.

## Reference(s):

- [Bitwarden Secrets Manager CLI](https://bitwarden.com/help/secrets-manager-cli/)
- [Bitwarden access tokens](https://bitwarden.com/help/access-tokens/)
- [Bitwarden Secrets Manager SDK and bws releases](https://github.com/bitwarden/sdk-sm)
- [bws CLI guide](references/cli-guide.md)
- [Server-resolved GitHub provenance](https://github.com/hajekt2/bitwarden-secrets-manager-cli)
- [ClawHub skill page](https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli)
- [Agent Skills specification](https://agentskills.io)
- [Skills CLI](https://github.com/vercel-labs/skills)

## Skill Output:

**Output Type(s):** [Guidance, Shell commands, Configuration, Code]

**Output Format:** [Markdown guidance with inline shell command examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Emphasizes secret-safe handling and avoids printing access tokens or secret values.]

## Skill Version(s):

0.1.0 (source: server release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli",
      "sourceUrl": "https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T10:57:38.991Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T10:57:38.991Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2.9K downloads",
      "href": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
      "sourceUrl": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T10:57:38.991Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.1.0",
      "href": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
      "sourceUrl": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-07-25T22:24:25.235Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.1.0",
      "description": "bitwarden-secrets-manager-cli 0.1.0 - Initial release introducing Bitwarden Secrets Manager CLI automation via the `bws` command-line tool. - Supports installing the CLI if missing and authenticating with machine-account access tokens. - Allows configuration for US, EU, or self-hosted Bitwarden servers. - Provides best practices for listing, managing, and injecting secrets safely into trusted processes. - Enforces secret-safe defaults and strict credential protection across all tasks. - Includes helper scripts and guidance to minimize risk when working with secrets and sensitive operations.",
      "href": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
      "sourceUrl": "https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-07-25T22:24:25.235Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to Bitwarden Secrets Manager CLI and adjacent AI workflows.