agentCLAWHUBUnverified

secrets-manager

Encrypted local secret store for OpenClaw agents. AES-256-GCM authenticated encryption with per-secret random IVs, master key in restricted-permission .master-key file. Store, retrieve, rotate, and audit secrets. Safe command injection (writes to temp file by default; --inject-stdout requires --confirm-expose). Master key is recoverable from .master-key file; losing it makes stored secrets unrecoverable.

OpenClaw

Rank

62

Safety

84

Downloads

1.6k

Updated

Oct 10, 2026

Version

1.1.19

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.6K downloadsadoption · observed Oct 10, 2026
Latest release
1.1.19release · observed Sep 13, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s175p518b8g47fx6r9zyvs95ks876t4t:secrets-manager
  1. Install using `clawhub skill install s175p518b8g47fx6r9zyvs95ks876t4t:secrets-manager` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/jlacroix82/secrets-manager before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-secrets-manager/snapshot"

Documentation

CLAWHUB

152,767 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: secrets-manager
version: 1.1.19
description: Encrypted local secret store for OpenClaw agents. AES-256-GCM authenticated encryption with per-secret random IVs, master key in restricted-permission .master-key file. Store, retrieve, rotate, and audit secrets. Safe command injection (writes to temp file by default; --inject-stdout requires --confirm-expose). Master key is recoverable from .master-key file; losing it makes stored secrets unrecoverable.
permissions: ["fs", "env", "exec", "shell", "elevated"]
---

# Secrets Manager 🔐

**Encrypted local secret store.** AES-256-GCM authenticated encryption. Master key auto-generated on first store and stored in the skill's private storage directory with restricted permissions (owner-only).

> **Important**: If you lose `.master-key`, all stored secrets become unrecoverable. Back it up.

## ⚠️ Important Warnings

### Encryption: AES-256-GCM (Authenticated)
- 256-bit master key, per-secret 96-bit random IV, 128-bit GCM auth tag
- Tampered ciphertext returns `null` from decrypt (no partial decryption)
- Master key stored in the skill's private storage directory with restricted permissions (owner-only)
- Override via `SECRETS_MASTER_KEY=<hex>` env var
- Losing the master key = all secrets unrecoverable

### `--get --raw` Prints Plaintext to stdout
The secret value goes to stdout, which may be captured in:
- Shell history / terminal scrollback
- Process logs / journald / syslog
- CI/CD pipeline output
- Agent transcripts / OpenClaw session history

Use only when piping to a private process:
```bash
node secrets-manager.js --get --raw api-key > /tmp/api-key.txt
# Restrict file permissions after writing
```

### `--inject` Default: Safe (writes to temp file with restricted permissions)
By default, `--inject "command {{secret}}"` substitutes and writes to a private temp file. **The resolved command is NEVER printed to stdout** unless you pass **both** flags:
```bash
--inject-stdout --confirm-expose "command {{secret}}"
```
The skill refuses to print the resolved command without `--confirm-expose`.

### Rotation: Old Values Are Archived
Rotated secrets keep the old encrypted value as `retired`. Rotate again to discard the archive. There is no `--undo` for archival.

### Storage Location
Encrypted secrets and master key stored in the skill's private storage directory with restricted permissions (owner-only). Override via `--dir <path>` or `SECRETS_DIR=<path>`.

## Permissions

This skill requires the following capabilities:

| Permission | Scope | Reason |
|---|---|---|
| `fs.read` | Private storage | Read encrypted secrets and master key |
| `fs.write` | Private storage | Write encrypted secrets, master key, permission rules |
| `run-cli` | CLI invocation | Invoke `secrets-manager.js` for store/get/rotate/audit operations |
| `elevated` | File permissions | Set restricted permissions on secret files to ensure owner-only access |

Elevation is required only for restricted permission enforcement on files

README.md

# Secrets Manager

**Encrypted local secret storage for OpenClaw agents.** AES-256-GCM authenticated encryption, rotation tracking, audit, and safe command injection.

> **TL;DR**: Secrets are encrypted at rest with AES-256-GCM. The master key is stored separately in `.master-key` with restricted permissions (owner-only). If you lose `.master-key`, your secrets are unrecoverable — back it up.

## Features

- **AES-256-GCM Encryption** — secrets encrypted at rest with a 256-bit master key and per-secret random 96-bit IVs. Authenticated encryption (GCM auth tag) detects tampering.
- **Secure Storage** — `store`, `get`, `list`, `delete` lifecycle
- **Auto-Expiry & Rotation** — 90-day default rotation cycle with audit reporting
- **Safe Command Injection** — substitutes `{{placeholder}}` and writes to a private temp file with restricted permissions by default. NEVER prints secrets to stdout unless you opt in.
- **Masked Output** — default output shows masked values (`sup****ue`)
- **Status & Audit** — health checks, expired/stale secret reporting
- **Zero External Dependencies** — pure Node.js `crypto` module

## ⚠️ Security Warnings

### Raw Mode (`--get --raw`) Prints Secrets to stdout
The secret value goes to stdout, which may be captured in:
- Shell history / terminal scrollback
- Process logs / journald / syslog
- CI/CD pipeline output
- Agent transcripts / OpenClaw session history
- Downstream tool output

Use only when piping directly to a private process or writing to a file with restricted permissions:
```bash
node secrets-manager.js --get --raw api-key > /tmp/api-key.txt
# Restrict file permissions after writing
```

### Command Injection (`--inject`) Default: Safe
By default, `--inject` substitutes `{{secrets}}` and writes the resolved command to a temp file with restricted permissions, then prints **only the file path** to stdout. Run the command with `sh /path/to/file`.

To print the resolved command to stdout (DANGEROUS — leaks secrets to logs), use **both** flags:
```bash
node secrets-manager.js --inject-stdout --confirm-expose "curl -H 'Authorization: Bearer {{api-key}}' https://api.example.com"
```
The skill will refuse to print the resolved command unless you pass `--confirm-expose`.

### Master Key Backup
The master key is stored in a restricted-permission file within the skill's private data directory (owner-only). If you lose this file, all stored secrets are unrecoverable. Back it up to a secure location (encrypted disk, password manager, OS keychain).

You can also use `SECRETS_MASTER_KEY=<hex>` env var instead of the file (useful for ephemeral environments).

### Not for Production Credentials (But Better Than Plain JSON)
This is a local agent tool with file-based key storage. For production-grade secret management with HSM-backed keys, audit trails, and access policies, use HashiCorp Vault, AWS Secrets Manager, etc. That said, **this skill provides real AES-256-GCM encryption** — secrets are not stored in plaintext or base64.

_meta.json

{
  "ownerId": "kn7b6eyf5vc7khg5fr63pjm8xd82qvw5",
  "slug": "secrets-manager",
  "version": "1.1.19",
  "publishedAt": 1789302192890
}

skill-card.md

## Description:

Encrypted local secret store for OpenClaw agents. AES-256-GCM authenticated encryption with per-secret random IVs, master key in restricted-permission .master-key file. Store, retrieve, rotate, and audit secrets. Safe command injection writes to a restricted temp file by default and requires explicit confirmation before printing resolved commands. Losing the master key makes stored secrets unrecoverable.

This skill is ready for commercial/non-commercial use.

## Publisher:

[jlacroix82](https://clawhub.ai/user/jlacroix82)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and agent operators use this skill to store, retrieve, rotate, audit, and inject local secrets for OpenClaw workflows while keeping default display output masked.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Credential values may be exposed through argv, persistent temp scripts, or audit output.

Mitigation: Review and fix credential handling before storing high-value production credentials; prefer masked output and default temp-file injection until the release has been remediated.

Risk: The release requests shell and elevated permissions that may be broader than necessary.

Mitigation: Limit deployment to reviewed environments, constrain the storage directory, and confirm that elevated permissions are only used for restrictive file-permission enforcement.

Risk: The local master key is required to recover stored secrets.

Mitigation: Back up the master key to a secure location and test recovery before relying on the store for important credentials.

## Reference(s):

- [ClawHub skill page](https://clawhub.ai/jlacroix82/skills/secrets-manager)
- [Publisher profile](https://clawhub.ai/user/jlacroix82)
- [README](artifact/README.md)
- [Vetting report](artifact/VET-REPORT.md)

## Skill Output:

**Output Type(s):** [Text, Shell commands, Files, Configuration]

**Output Format:** [CLI text output, masked secret values by default, and restricted-permission temp shell scripts for command injection]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [May emit plaintext secrets only when explicitly requested through raw retrieval or confirmed stdout injection.]

## Skill Version(s):

1.1.19 (source: frontmatter and server release evidence)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.

VET-REPORT.md

# Vetting Report: secrets-manager
**Date:** 2026-09-13 08:11 EDT
**Vetter:** JARVIS (skill-vetter skill)
**Source:** local (/home/jarvis/.openclaw/workspace)
**Verdict:** PASS
**Risk score:** 8/100

## Findings

### Critical
- (none)

### Warnings
- 1 network URLs
- No description in frontmatter

### Notes
- (none)

## Permission footprint
- Tools requested: exec process read write 

## Network footprint
https://api.openai.com/v1/chat

## Side effects
- Reads: SKILL.md
- Writes: VET-REPORT.md (this file)
- Network: 1 distinct hosts

## Verdict rationale
Score 8/100 with 0 critical findings and 2 warnings.
Github ReposUpdated 15h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/jlacroix82/skills/secrets-manager",
      "sourceUrl": "https://clawhub.ai/jlacroix82/skills/secrets-manager",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T06:53:23.949Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-secrets-manager/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-secrets-manager/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T06:53:23.949Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.6K downloads",
      "href": "https://clawhub.ai/jlacroix82/secrets-manager",
      "sourceUrl": "https://clawhub.ai/jlacroix82/secrets-manager",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T06:53:23.949Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.1.19",
      "href": "https://clawhub.ai/jlacroix82/secrets-manager",
      "sourceUrl": "https://clawhub.ai/jlacroix82/secrets-manager",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-13T12:23:12.890Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-secrets-manager/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-secrets-manager/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.1.19",
      "description": "**Skill 1.1.19 adds safe command injection and clarifies permission, storage, and leak prevention.** - New `--inject` mode: inject secrets into commands via temp file with restricted permissions (owner-only); blocks leaking to stdout by default. - To print resolved commands with secrets to stdout, user must provide both `--inject-stdout` and `--confirm-expose` for explicit confirmation. - Permissions updated: now claims `fs`, `env`, `exec`, `shell`, `elevated` to enforce strict storage protections. - Documentation and warnings expanded in README and SKILL.md, including main security exposures, rotation/archive rules, and usage guidance. - Storage, audit, and rotation features unchanged; injection and leak-prevention are strengthened. - Changelog and outdated docs files removed; new vetting report added.",
      "href": "https://clawhub.ai/jlacroix82/secrets-manager",
      "sourceUrl": "https://clawhub.ai/jlacroix82/secrets-manager",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-13T12:23:12.890Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to secrets-manager and adjacent AI workflows.