agentCLAWHUBUnverified

identity-aiops

Use this skill whenever the user needs to operate a Keycloak or authentik identity provider — a one-shot overview, realm settings, users with sessions/credentials/groups/lockout status, authentication and admin events, OAuth/OIDC clients, four flagship RCAs (login-failure/lockout-storm, stale access, client misconfiguration, MFA coverage), and governed writes (disable/enable a user, revoke sessions, require a password reset, replace redirect URIs, rotate a client secret). Always use this skill for "Keycloak", "authentik", "realm", "SSO users", "login failures", "brute force logins", "locked out users", "stale accounts", "service account misuse", "redirect URI", "PKCE", "implicit flow", "client secret rotation", "MFA coverage", "who has no 2FA" when the context is a Keycloak/authentik IdP. Do NOT use when the target is something other than a Keycloak/authentik identity provider (a hypervisor, storage appliance, backup product, container-orchestration cluster, firewall, database, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Cloud IdPs (Okta, Entra ID, Auth0) are out of scope. Governed identity operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).

OpenClaw

Rank

62

Safety

84

Downloads

1.4k

Updated

Oct 10, 2026

Version

0.8.5

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.4K downloadsadoption · observed Oct 10, 2026
Latest release
0.8.5release · observed Sep 16, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:identity-aiops
  1. Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:identity-aiops` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/identity-aiops before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-identity-aiops/snapshot"

Documentation

CLAWHUB

149,454 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: identity-aiops
slug: identity-aiops
displayName: "Identity AIops"
summary: "Governed Keycloak + authentik identity ops: users, events, clients, MFA, RCA. 29 tools."
license: MIT
homepage: https://github.com/AIops-tools/Identity-AIops
tags: [aiops, mcp, governance, identity]
description: >
  Use this skill whenever the user needs to operate a Keycloak or authentik identity provider — a one-shot overview, realm settings, users with sessions/credentials/groups/lockout status, authentication and admin events, OAuth/OIDC clients, four flagship RCAs (login-failure/lockout-storm, stale access, client misconfiguration, MFA coverage), and governed writes (disable/enable a user, revoke sessions, require a password reset, replace redirect URIs, rotate a client secret).
  Always use this skill for "Keycloak", "authentik", "realm", "SSO users", "login failures", "brute force logins", "locked out users", "stale accounts", "service account misuse", "redirect URI", "PKCE", "implicit flow", "client secret rotation", "MFA coverage", "who has no 2FA" when the context is a Keycloak/authentik IdP.
  Do NOT use when the target is something other than a Keycloak/authentik identity provider (a hypervisor, storage appliance, backup product, container-orchestration cluster, firewall, database, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Cloud IdPs (Okta, Entra ID, Auth0) are out of scope.
  Governed identity operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).
installer:
  kind: uv
  package: identity-aiops
argument-hint: "[a user/client id, a realm, or describe your identity task]"
allowed-tools:
  - Bash
metadata: {"openclaw":{"requires":{"anyBins":["identity-aiops","uvx"]},"optional":{"env":["IDENTITY_AIOPS_CONFIG","IDENTITY_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/Identity-AIops","emoji":"🔐","os":["macos","linux"]}}
compatibility: >
  Standalone, self-governed identity-provider operations across Keycloak (admin REST API /admin/realms/{realm}/..., OAuth2 client-credentials grant against the realm token endpoint with automatic refresh-on-401) and authentik (API v3 /api/v3/..., long-lived API token as a Bearer header). Each target in the config names its own platform, and a name-keyed platform registry selects the API shape, so the same tools work on both and one config can span a mixed estate. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.
  All write operations are audited to a local SQLite DB under ~/.identity-aiops/ (relocatable via IDENTITY_AIOPS_HOME).
  Credentials: the Keycloak confidential client's client secret or the authentik API token is stored ENCRYPTED in ~/.identity-aiops/secrets.enc (Fernet/AES-128 + scrypt-derived key) — never plaintext on disk. Run 'identity-aiops init' to onboard (it asks for the platform, base URL, and — Keycloak — rea

_meta.json

{
  "ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
  "slug": "identity-aiops",
  "version": "0.8.5",
  "publishedAt": 1789601143154
}

references/agent-guardrails.md

# Agent guardrails — running identity-aiops with a smaller / local model

If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.

The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.

## Authorization is not this tool's job — decide it where it belongs

Whether a write should happen is your decision, or the account's. The tool does
not gate it — there is no read-only switch and no approval prompt to configure.
The two right places to control read vs write:

- **The account you connect with.** Give the Keycloak service account (or the
  authentik token) only the roles you want the agent to have — `view-users` /
  `view-events` / `view-clients` and no `manage-*`. A write then fails at the
  server, which is the only place the permission actually lives — no skill-side
  flag can be argued around by a model, but a revoked permission cannot be.
- **Your agent's system prompt.** If you want an observe-only session, tell the
  model not to call the write tools (they are clearly tagged `[WRITE]`).

What the tool *does* guarantee is that you can always see what happened:

## What the tool enforces — do not waste prompt budget on these

| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Don't invent a value when a field is missing" | A field the IdP did not return comes back as `null`, never as `""`. Absent and empty are distinguishable in the payload — a `lastLogin` of `null` means "no sign-in on record", not "signed in at an empty time". |
| "Tell me if the output was cut off" | Every listing returns `{"users": [...], "returned": N, "limit": L, "truncated": true/false}` (same shape for `events`, `groups`, `members`, `clients`, `sessions`, `identityProviders`). Truncation is measured — one extra row is fetched — not guessed from a length coincidence. |
| "Tell me if the analysis only saw part of the data" | The four analyses echo `inputsTruncated` / `feedTruncated`, and `truncated` + `maxRows` when a finding list was capped. The `*Count` fields are always the full totals. |
| "Make it show the number it judged on" | `client_misconfig_audit` ranks clients by `riskScore` — the summed severity weights, echoed as `severityWeights` so the score is recomputable — and every finding carries its own `severity`. `login_failure_rca` findings each carry the counts that tripped them (`failures`, `distinctUsers`, `distinctIps`); the thresholds they were compared against are reported separately under `thresholds`, not on the finding. |
| "Confirm before anything destructive" | Write CLI commands have `--dry-run` plus double confirmation. |
| "Log

references/capabilities.md

# identity-aiops capabilities

> **29 MCP tools** (21 read, 6 write, 2 undo) across Keycloak (admin REST `/admin/realms/{realm}/...`,
> client-credentials grant, refresh-on-401) and authentik (API v3 `/api/v3/...`,
> Bearer token). The concrete REST paths below are modelled from each project's
> public API and need live verification.

A per-target `platform` field (`keycloak` / `authentik`) selects the API shape;
the same tool name resolves to the right path on each IdP via the platform
registry. Every substituted path segment (realm, user id, client id) is
percent-encoded centrally.

## Realm / system (read)

| Tool | Keycloak path | authentik path | Returns |
|------|---------------|----------------|---------|
| `identity_overview` | (composite) | (composite) | platform/realm, user/client/IdP counts, failed-login feed size |
| `realm_info` | `/admin/realms/{realm}` | `/api/v3/admin/system/` | brute-force protection, password/OTP policy (KC); version/environment (AK) |
| `list_identity_providers` | `/admin/realms/{realm}/identity-provider/instances` | `/api/v3/sources/all/` | federated IdPs / sources with enabled state |

## Users / groups (read)

| Tool | Keycloak path | authentik path | Returns |
|------|---------------|----------------|---------|
| `list_users` | `/admin/realms/{realm}/users` | `/api/v3/core/users/` | normalized users (id, username, enabled, lastLogin, serviceAccount) |
| `user_detail` | `/admin/realms/{realm}/users/{id}` | `/api/v3/core/users/{id}/` | one user incl. requiredActions/attributes |
| `user_count` | `/admin/realms/{realm}/users/count` | `/api/v3/core/users/` (pagination.count) | total users — the doctor probe |
| `user_sessions` | `/admin/realms/{realm}/users/{id}/sessions` | `/api/v3/core/authenticated_sessions/?user=` | active sessions (id, IP, start/last access) |
| `user_credentials` | `/admin/realms/{realm}/users/{id}/credentials` | `/api/v3/authenticators/admin/all/?user=` | credentials/devices with second-factor flags |
| `list_groups` | `/admin/realms/{realm}/groups` | `/api/v3/core/groups/` | groups |
| `group_members` | `/admin/realms/{realm}/groups/{id}/members` | `/api/v3/core/groups/{id}/` (users_obj) | normalized member users |
| `user_lockout_status` | `/admin/realms/{realm}/attack-detection/brute-force/users/{id}` | — (teaching error) | failure count, locked state, last failure IP |

## Events (read)

| Tool | Keycloak path | authentik path | Returns |
|------|---------------|----------------|---------|
| `login_events` | `/admin/realms/{realm}/events` | `/api/v3/events/events/` | normalized events {time, type, user, ip, client, error} |
| `admin_events` | `/admin/realms/{realm}/admin-events` | `/api/v3/events/events/` (admin actions) | admin/config changes {operation, resource, actor, ip} |

## Clients (read)

| Tool | Keycloak path | authentik path | Returns |
|------|---------------|----------------|---------|
| `list_clients` | `/admin/realms/{realm}/clients` | `/api/v3/providers/oauth2/` | no

references/cli-reference.md

# identity-aiops CLI reference

All read commands print normalized JSON. All write commands take `--dry-run`
(preview, no call, no audit) and otherwise require **double confirmation**;
confirmed writes execute through the governed MCP twins, so they land in
`~/.identity-aiops/audit.db` with undo where applicable. `--target/-t` selects
a target from config (default: the first one).

## Setup / health

```bash
identity-aiops init                 # onboarding wizard (platform, base URL, realm, secret)
identity-aiops doctor               # config + secrets + token acquisition + user-count probe
identity-aiops doctor --skip-auth   # config/secrets checks only (no network)
identity-aiops overview             # one-shot estate summary
identity-aiops mcp                  # start the MCP server (stdio)
```

## Secrets (encrypted store)

```bash
identity-aiops secret set <target>    # store/replace a secret (hidden prompt)
identity-aiops secret list            # target names only — never values
identity-aiops secret remove <target>
identity-aiops secret migrate         # legacy .env / env vars → secrets.enc
```

Master password: `IDENTITY_AIOPS_MASTER_PASSWORD` (non-interactive/MCP) or an
interactive prompt on a TTY.

## Events

```bash
identity-aiops events                          # recent auth events
identity-aiops events --type LOGIN_ERROR -n 50 # Keycloak failed logins
identity-aiops events --type login_failed      # authentik failed logins
identity-aiops events --user alice
```

## Users

```bash
identity-aiops users list [--search alice] [--limit 200]
identity-aiops users show <user-id>
identity-aiops users sessions <user-id>
identity-aiops users credentials <user-id>          # MFA surface

# governed writes
identity-aiops users disable <user-id> [--dry-run]          # med, undo: enable
identity-aiops users enable <user-id> [--dry-run]           # HIGH
identity-aiops users revoke-sessions <user-id> [--dry-run]  # med, irreversible
identity-aiops users require-reset <user-id> [--clear] [--dry-run]
```

## Clients

```bash
identity-aiops clients list [--limit 200]
identity-aiops clients show <client-id>

# governed writes
identity-aiops clients set-redirect-uris <client-id> -u https://a/cb -u https://b/cb [--dry-run]  # HIGH
identity-aiops clients rotate-secret <client-id> [--dry-run]                                       # HIGH, masked
```

## Environment variables

| Variable | Purpose |
|----------|---------|
| `IDENTITY_AIOPS_HOME` | relocate all state (config, secrets, audit, undo) |
| `IDENTITY_AIOPS_CONFIG` | alternate config.yaml path (MCP server) |
| `IDENTITY_AIOPS_MASTER_PASSWORD` | unlock secrets.enc non-interactively |
| `IDENTITY_AUDIT_APPROVED_BY` / `IDENTITY_AUDIT_RATIONALE` | optional audit annotations (who/why), recorded when set |
| `IDENTITY_MAX_TOOL_CALLS` / `IDENTITY_MAX_TOOL_SECONDS` | session budget ceilings |
| `IDENTITY_<TARGET>_SECRET` | legacy plaintext secret fallback (deprecated) |
Github ReposUpdated 21h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/zw008/skills/identity-aiops",
      "sourceUrl": "https://clawhub.ai/zw008/skills/identity-aiops",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T14:17:47.744Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-identity-aiops/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-identity-aiops/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T14:17:47.744Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.4K downloads",
      "href": "https://clawhub.ai/zw008/identity-aiops",
      "sourceUrl": "https://clawhub.ai/zw008/identity-aiops",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T14:17:47.744Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.8.5",
      "href": "https://clawhub.ai/zw008/identity-aiops",
      "sourceUrl": "https://clawhub.ai/zw008/identity-aiops",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-16T23:25:43.154Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-identity-aiops/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-identity-aiops/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.8.5",
      "description": "- Updated documentation for agent guardrails in references/agent-guardrails.md. - Removed obsolete skill-card.md file. - General documentation updates and cleanup.",
      "href": "https://clawhub.ai/zw008/identity-aiops",
      "sourceUrl": "https://clawhub.ai/zw008/identity-aiops",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-16T23:25:43.154Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to identity-aiops and adjacent AI workflows.