{"id":"5458da4b-cabc-40ce-9353-204c0a94a03d","entityType":"agent","slug":"clawhub-hajekt2-bitwarden-secrets-manager-cli","name":"Bitwarden Secrets Manager CLI","canonicalUrl":"https://www.xpersona.co/agent/clawhub-hajekt2-bitwarden-secrets-manager-cli","canonicalPath":"/agent/clawhub-hajekt2-bitwarden-secrets-manager-cli","generatedAt":"2026-10-09T22:08:11.965Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T10:57:38.991Z","emptyReason":null},"description":"Use Bitwarden Secrets Manager safely","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.9K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17dmjpd250973tjtpk2e7fdmx885wc8:bitwarden-secrets-manager-cli","sourceUrl":"https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli","homepage":"https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":69,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Bitwarden Secrets Manager CLI technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T10:57:38.991Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T10:57:38.991Z","emptyReason":null},"stars":null,"forks":null,"downloads":2884,"packageName":null,"latestVersion":"0.1.0","tractionLabel":"2.9K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T10:57:38.991Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T10:57:38.991Z","lastCrawledAt":"2026-10-09T10:57:38.991Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T10:57:38.991Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.0","createdAt":"2026-07-25T22:24:25.235Z","changelog":"bitwarden-secrets-manager-cli 0.1.0 - Initial release introducing Bitwarden Secrets Manager CLI automation via the `bws` command-line tool. - Supports installing the CLI if missing and authenticating with machine-account access tokens. - Allows configuration for US, EU, or self-hosted Bitwarden servers. - Provides best practices for listing, managing, and injecting secrets safely into trusted processes. - Enforces secret-safe defaults and strict credential protection across all tasks. - Includes helper scripts and guidance to minimize risk when working with secrets and sensitive operations.","fileCount":14,"zipByteSize":12106}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17dmjpd250973tjtpk2e7fdmx885wc8:bitwarden-secrets-manager-cli","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17dmjpd250973tjtpk2e7fdmx885wc8:bitwarden-secrets-manager-cli` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/hajekt2/bitwarden-secrets-manager-cli before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T22:08:11.964Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hajekt2-bitwarden-secrets-manager-cli/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T10:57:38.991Z","emptyReason":null},"readme":"Skill: Bitwarden Secrets Manager CLI\n\nOwner: hajekt2\n\nSummary: Use Bitwarden Secrets Manager safely\n\nTags: latest:0.1.0\n\nVersion history:\n\nv0.1.0 | 2026-07-25T22:24:25.235Z | auto\n\nbitwarden-secrets-manager-cli 0.1.0\n\n- Initial release introducing Bitwarden Secrets Manager CLI automation via the `bws` command-line tool.\n- Supports installing the CLI if missing and authenticating with machine-account access tokens.\n- Allows configuration for US, EU, or self-hosted Bitwarden servers.\n- Provides best practices for listing, managing, and injecting secrets safely into trusted processes.\n- Enforces secret-safe defaults and strict credential protection across all tasks.\n- Includes helper scripts and guidance to minimize risk when working with secrets and sensitive operations.\n\nArchive index:\n\nArchive v0.1.0: 14 files, 12106 bytes\n\nFiles: .gitignore (22b), agents (0b), agents/openai.yaml (222b), LICENSE (1068b), README.md (6360b), references (0b), references/cli-guide.md (5249b), scripts (0b), scripts/check-auth.sh (536b), scripts/ensure-bws.sh (1115b), scripts/list-secret-metadata.sh (826b), skill-card.md (2858b), SKILL.md (5457b), _meta.json (148b)\n\nFile v0.1.0:SKILL.md\n\n---\nname: bitwarden-secrets-manager-cli\ndescription: Operate Bitwarden Secrets Manager through the `bws` CLI, including installing the CLI when missing, authenticating with machine-account access tokens, configuring US, EU, or self-hosted servers, listing and managing projects and secrets, and injecting secrets into trusted processes. Use for requests involving Bitwarden Secrets Manager, `bws`, `BWS_ACCESS_TOKEN`, machine accounts, secret retrieval, secret injection, or Secrets Manager automation and CI/CD.\n---\n\n# Bitwarden Secrets Manager CLI\n\nUse `bws` with secret-safe defaults.\nInstall it when missing, authenticate without exposing the access token, inspect read-only state first, and make mutations only when the requested scope is exact.\n\n## Start every task\n\n1. Run `scripts/ensure-bws.sh`.\n   On native Windows without a POSIX shell, use the official PowerShell installer documented in [references/cli-guide.md](references/cli-guide.md).\n2. Run `bws --version` and `bws --help` when command behavior may vary by version.\n3. Determine the server before authenticating.\n   Bitwarden US is the default.\n   Configure EU or self-hosted deployments only when the user identifies that environment.\n4. Use an existing `BWS_ACCESS_TOKEN` environment variable.\n   If none exists, ask the user to inject or export the token in their own secure environment.\n5. Run `scripts/check-auth.sh` to perform a read-only authentication check that emits no vault data.\n\nRead [references/cli-guide.md](references/cli-guide.md) for command syntax, output behavior, configuration, and troubleshooting.\nUse the live `bws <command> --help` output and linked official Bitwarden documentation as the final authority.\n\n## Protect credentials and secret values\n\n- Never print, repeat, summarize, or commit an access token or secret value.\n- Never place an access token directly in a command line with `--access-token`.\n  Command arguments can appear in shell history, process listings, logs, and agent traces.\n- Prefer runtime secret injection or an already-set `BWS_ACCESS_TOKEN`.\n  If secure injection is unavailable, ask the user to export it in their own shell and confirm when ready.\n- Do not create `.env` files unless the user explicitly asks.\n  If one is required, keep it outside version control, restrict permissions, and verify that Git ignores it.\n- Do not expose raw `bws secret list` or `bws secret get` JSON in logs because both include secret values.\n- Use `scripts/list-secret-metadata.sh [PROJECT_ID]` when only IDs and keys are needed.\n- Prefer `bws run` to pass values directly to a trusted process instead of retrieving and displaying them.\n- Use `--output none` for mutations unless returned metadata is required.\n\nIf a token appears in conversation or tool output, do not echo it.\nRecommend rotation if it was exposed in a durable or public location.\n\n## Work read-only first\n\nResolve the exact organization-visible objects before changing anything:\n\n```bash\nbws project list --output table\nscripts/list-secret-metadata.sh\nscripts/list-secret-metadata.sh \"$PROJECT_ID\"\n```\n\nListing projects does not expose secret values.\nThe metadata helper deliberately removes each secret's value and note before printing.\n\nFor a specific value, avoid rendering it:\n\n```bash\nSECRET_VALUE=\"$(bws secret get \"$SECRET_ID\" --output json | jq -r '.value')\"\nexport SECRET_VALUE\ntrusted-command-reading-env\nunset SECRET_VALUE\n```\n\nDo not run the example unchanged.\nAdapt it so the trusted destination consumes the variable, and ensure shell tracing is disabled.\n\n## Inject secrets into a trusted process\n\nUse `bws run` when secret keys are valid environment-variable names:\n\n```bash\nbws run --project-id \"$PROJECT_ID\" -- trusted-command\n```\n\nUse `--no-inherit-env` when the child should receive a minimal inherited environment:\n\n```bash\nbws run --project-id \"$PROJECT_ID\" --no-inherit-env -- trusted-command\n```\n\nTreat `--no-inherit-env` as environment cleanup, not a sandbox.\nExecute only binaries and scripts the user trusts because the child process receives the secrets.\nUse `--uuids-as-keynames` when secret names are not POSIX-compatible or may collide.\n\n## Change projects or secrets\n\nBefore create, edit, or delete operations:\n\n1. Confirm the exact project or secret ID and intended new state.\n2. Verify the access token has the required machine-account scope.\n3. Keep values in environment variables or another secure runtime channel.\n4. Use `--output none` unless non-secret response metadata is needed.\n5. Re-read metadata after the change and report only IDs, keys, and status.\n\nExamples:\n\n```bash\nbws project create \"$PROJECT_NAME\" --output none\nbws project edit \"$PROJECT_ID\" --name \"$NEW_NAME\" --output none\nbws secret create \"$SECRET_KEY\" \"$SECRET_VALUE\" \"$PROJECT_ID\" --output none\nbws secret edit \"$SECRET_ID\" --value \"$SECRET_VALUE\" --output none\n```\n\nDeletion is destructive.\nRequire explicit user authorization for the resolved IDs immediately before running `bws secret delete` or `bws project delete`.\n\n## Configure another Bitwarden server\n\nFor Bitwarden EU:\n\n```bash\nbws config server-base https://vault.bitwarden.eu\n```\n\nFor self-hosted Bitwarden, use the base URL supplied by the user:\n\n```bash\nbws config server-base \"$BITWARDEN_BASE_URL\"\n```\n\nPrefer `BWS_SERVER_URL`, `BWS_PROFILE`, or a task-specific config file when the configuration should be temporary or isolated.\nDo not overwrite an existing default profile without checking it first.\n\nFile v0.1.0:README.md\n\n# Bitwarden Secrets Manager CLI Skill\n\nAn Agent Skill for working safely with [Bitwarden Secrets Manager](https://bitwarden.com/products/secrets-manager/) through the `bws` command-line interface.\n\nThe skill helps AI coding agents install and operate `bws`, authenticate with a machine-account access token, inspect projects and secrets, inject secrets into trusted processes, and manage Secrets Manager resources without exposing sensitive values.\n\nThis repository follows the open [Agent Skills specification](https://agentskills.io) and can be installed with the [Skills CLI](https://github.com/vercel-labs/skills) into Codex, Claude Code, Cursor, and other supported agents.\n\n> [!IMPORTANT]\n> `bws` is the Bitwarden Secrets Manager CLI.\n> It is separate from the `bw` CLI used with Bitwarden Password Manager.\n\n## Install\n\nInstall the skill with the standard Skills CLI command:\n\n```bash\nnpx skills add hajekt2/bitwarden-secrets-manager-cli\n```\n\nThe installer detects supported agents and asks where to install the skill.\nProject installation is the default.\n\nInstall it globally for use across projects:\n\n```bash\nnpx skills add hajekt2/bitwarden-secrets-manager-cli -g\n```\n\nInstall it globally for Codex without interactive prompts:\n\n```bash\nnpx skills add hajekt2/bitwarden-secrets-manager-cli \\\n  --skill bitwarden-secrets-manager-cli \\\n  --agent codex \\\n  --global \\\n  --yes\n```\n\nList the skill without installing it:\n\n```bash\nnpx skills add hajekt2/bitwarden-secrets-manager-cli --list\n```\n\nThe Skills CLI requires Node.js and npm.\nSee the [Skills CLI documentation](https://github.com/vercel-labs/skills) for supported agents, installation scopes, and additional options.\n\n## What the skill does\n\n- Installs `bws` from Bitwarden's official installer when the CLI is missing.\n- Supports Bitwarden US, Bitwarden EU, and self-hosted server configuration.\n- Authenticates through the `BWS_ACCESS_TOKEN` environment variable.\n- Validates authentication with a read-only request that prints no vault data.\n- Lists secret metadata without printing secret values or notes.\n- Retrieves and injects secrets without exposing them in agent output.\n- Guides safe project and secret creation, editing, and deletion.\n- Uses `bws run` to inject secrets directly into trusted processes.\n- Uses live `bws --help` output and Bitwarden documentation as the final authority.\n\n## Authentication\n\nCreate an access token for a [Bitwarden Secrets Manager machine account](https://bitwarden.com/help/access-tokens/).\nThe machine account must have access to the projects and secrets required by the task.\n\nProvide the token as `BWS_ACCESS_TOKEN` in the environment where the agent runs.\nFor example, read it without echoing it in Bash:\n\n```bash\nread -rsp \"BWS access token: \" BWS_ACCESS_TOKEN\nprintf '\\n'\nexport BWS_ACCESS_TOKEN\n```\n\nUse your shell, CI secret store, agent runtime, or another secure environment-injection mechanism to set the value.\nDo not paste the token into prompts, commit it, store it in tracked `.env` files, or pass it through the `--access-token` command-line option.\n\nThe skill validates authentication with:\n\n```bash\nscripts/check-auth.sh\n```\n\nThis performs a read-only project request with `--output none`.\nIt does not print project data, secret metadata, secret values, or the token.\n\n## Example prompts\n\n```text\nUse $bitwarden-secrets-manager-cli to install bws if needed and verify authentication without printing vault data.\n```\n\n```text\nUse $bitwarden-secrets-manager-cli to list the secret IDs and keys available to this machine account without showing values.\n```\n\n```text\nUse $bitwarden-secrets-manager-cli to run npm start with secrets from project <PROJECT_ID>.\n```\n\n```text\nUse $bitwarden-secrets-manager-cli to create a secret in project <PROJECT_ID>, keeping the value out of logs and output.\n```\n\nAgents can also invoke the skill automatically when a request mentions Bitwarden Secrets Manager, `bws`, `BWS_ACCESS_TOKEN`, machine accounts, or secret injection.\n\n## Safety model\n\n- Keep access tokens and secret values out of prompts, logs, process arguments, and version control.\n- Start with read-only discovery before changing remote state.\n- Filter `bws secret list` and `bws secret get` output because raw responses include decrypted values.\n- Use `--output none` for mutations unless response metadata is required.\n- Resolve exact resource IDs before editing or deleting anything.\n- Require explicit authorization before deleting projects or secrets.\n- Run only trusted commands through `bws run` because the child process receives secret values.\n- Treat `--no-inherit-env` as environment cleanup, not as a security sandbox.\n\n## Repository contents\n\n```text\n.\n├── SKILL.md\n├── agents/\n│   └── openai.yaml\n├── references/\n│   └── cli-guide.md\n└── scripts/\n    ├── check-auth.sh\n    ├── ensure-bws.sh\n    └── list-secret-metadata.sh\n```\n\n- [`SKILL.md`](SKILL.md) contains the agent workflow and safety rules.\n- [`references/cli-guide.md`](references/cli-guide.md) summarizes installation, authentication, configuration, commands, and troubleshooting.\n- [`scripts/ensure-bws.sh`](scripts/ensure-bws.sh) detects or installs the official `bws` CLI on Linux and macOS.\n- [`scripts/check-auth.sh`](scripts/check-auth.sh) validates authentication without printing vault data.\n- [`scripts/list-secret-metadata.sh`](scripts/list-secret-metadata.sh) strips values and notes from secret-list output.\n\nOn native Windows, the skill uses Bitwarden's official PowerShell installer.\n\n## Update or remove\n\nUpdate the installed skill:\n\n```bash\nnpx skills update bitwarden-secrets-manager-cli\n```\n\nUpdate a global installation:\n\n```bash\nnpx skills update bitwarden-secrets-manager-cli --global\n```\n\nRemove a project installation:\n\n```bash\nnpx skills remove bitwarden-secrets-manager-cli\n```\n\nRemove a global installation:\n\n```bash\nnpx skills remove bitwarden-secrets-manager-cli --global\n```\n\n## Documentation\n\n- [Bitwarden Secrets Manager CLI](https://bitwarden.com/help/secrets-manager-cli/)\n- [Bitwarden access tokens](https://bitwarden.com/help/access-tokens/)\n- [Bitwarden Secrets Manager SDK and `bws` releases](https://github.com/bitwarden/sdk-sm)\n- [Skills CLI](https://github.com/vercel-labs/skills)\n- [Agent Skills specification](https://agentskills.io)\n\n## License\n\n[MIT](LICENSE)\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn79sz4h2hzc5wxxtarf1zr47980m8bj\",\n  \"slug\": \"bitwarden-secrets-manager-cli\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1785018265235\n}\n\nFile v0.1.0:references/cli-guide.md\n\n# `bws` CLI guide\n\nThis guide summarizes the official Bitwarden Secrets Manager CLI documentation.\nCheck the live sources and `bws <command> --help` before relying on version-sensitive behavior.\n\nOfficial sources:\n\n- [Secrets Manager CLI](https://bitwarden.com/help/secrets-manager-cli/)\n- [Access tokens](https://bitwarden.com/help/access-tokens/)\n- [`bws` source and releases](https://github.com/bitwarden/sdk-sm)\n\n## Install\n\nBitwarden provides native binaries for Linux, macOS, and Windows.\nIts official installers download a release archive and verify its SHA-256 checksum.\n\nPOSIX:\n\n```bash\ncurl -fsSL https://bws.bitwarden.com/install -o /tmp/install-bws.sh\nsh /tmp/install-bws.sh\n```\n\nPowerShell:\n\n```powershell\niwr https://bws.bitwarden.com/install | iex\n```\n\nCargo:\n\n```bash\ncargo install bws --locked\n```\n\nDocker:\n\n```bash\ndocker run --rm -it ghcr.io/bitwarden/bws --help\n```\n\nThe bundled `scripts/ensure-bws.sh` uses the official POSIX installer only when `bws` is not already on `PATH`.\n\n## Authenticate\n\nCreate an access token for a Bitwarden Secrets Manager machine account.\nThe token can access only the projects and secrets assigned to that machine account.\nBitwarden does not retain a recoverable copy of the token after creation.\n\nPrefer an environment variable:\n\n```bash\nexport BWS_ACCESS_TOKEN='set-this-in-your-own-secure-shell'\n```\n\nDo not include the real value in documentation, committed files, shell history, process arguments, chat output, or agent tool calls.\nAlthough `bws` supports `--access-token`, avoid it because command arguments are easier to expose.\n\nValidate authentication without printing vault data:\n\n```bash\nbws project list --output none\n```\n\nFrequent new sessions from one IP address can be rate-limited.\nThe CLI stores encrypted authentication state under `~/.config/bws/state` by default to reduce repeated authentication.\n\n## Configure a server\n\nBitwarden US is the default.\nEU and self-hosted users must configure their server.\n\n```bash\nbws config server-base https://vault.bitwarden.eu\nbws config server-base https://bitwarden.example.com\n```\n\nThe default config is `~/.config/bws/config`.\nUse `--profile`, `BWS_PROFILE`, `--config-file`, or `BWS_CONFIG_FILE` to isolate configurations.\nUse `--server-url` or `BWS_SERVER_URL` for a per-command override.\n\n## Outputs\n\nSupported output formats are `json`, `yaml`, `env`, `table`, `tsv`, and `none`.\nJSON is the default.\n\nSecret `get` and `list` output includes decrypted values.\nDo not print it when only IDs, keys, or status are needed.\n\nUse:\n\n```bash\nscripts/list-secret-metadata.sh\nscripts/list-secret-metadata.sh \"$PROJECT_ID\"\n```\n\nUse `--output none` for writes when no response body is required.\nThe `env` output format comments out non-POSIX key names, but it still contains secret values and must be treated as sensitive.\n\n## Projects\n\n```bash\nbws project list\nbws project get \"$PROJECT_ID\"\nbws project create \"$NAME\"\nbws project edit \"$PROJECT_ID\" --name \"$NEW_NAME\"\nbws project delete \"$PROJECT_ID\"\n```\n\nProject list and get responses contain metadata but no secret values.\nCreate, edit, and delete change remote state.\n\n## Secrets\n\nCurrent syntax uses `bws secret <verb>`.\nOlder `bws list secrets` examples are obsolete compatibility syntax.\n\n```bash\nbws secret list\nbws secret list \"$PROJECT_ID\"\nbws secret get \"$SECRET_ID\"\nbws secret create \"$KEY\" \"$VALUE\" \"$PROJECT_ID\"\nbws secret edit \"$SECRET_ID\" --key \"$KEY\" --value \"$VALUE\" --note \"$NOTE\"\nbws secret delete \"$SECRET_ID\"\n```\n\n`secret create` requires a key, value, and project ID.\n`secret edit` can change the key, value, note, or project ID.\nSecret read responses contain decrypted values.\nSecret values passed to create or edit are command arguments, so keep shell tracing disabled and avoid literal values in command history.\n\n## Run a process with secrets\n\n`bws run` injects accessible secrets as environment variables into a child process:\n\n```bash\nbws run --project-id \"$PROJECT_ID\" -- trusted-command\nbws run --project-id \"$PROJECT_ID\" --no-inherit-env -- trusted-command\nbws run --project-id \"$PROJECT_ID\" --uuids-as-keynames -- trusted-command\n```\n\nThe default shell is `sh` on Linux and macOS and PowerShell on Windows.\n`--no-inherit-env` reduces inherited variables but does not sandbox the child.\nRun only trusted code.\nSecret names that are invalid environment-variable names may be inaccessible to POSIX tools.\n`--uuids-as-keynames` converts secret IDs to safe environment-variable names.\n\n## Troubleshoot\n\n`Missing access token`:\n\n- Confirm `BWS_ACCESS_TOKEN` exists in the process that launches `bws`.\n- Do not print the variable while checking it.\n\nAuthorization or missing objects:\n\n- Confirm the machine account is assigned to the project.\n- Confirm its read or write permissions match the requested action.\n- Remember that unassigned projects and secrets are intentionally invisible.\n\nEU or self-hosted connection failure:\n\n- Check the configured server base, profile, config file, and `BWS_SERVER_URL`.\n\nRate limits:\n\n- Reuse encrypted CLI state.\n- Avoid starting many fresh authenticated sessions from the same IP in a short period.\n\nUnexpected syntax:\n\n- Run `bws --version`.\n- Run `bws <command> --help`.\n- Prefer `bws secret <verb>` and `bws project <verb>`.\n\nFile v0.1.0:skill-card.md\n\n## Description:\n\nOperate Bitwarden Secrets Manager through the bws CLI, including installing the CLI when missing, authenticating with machine-account access tokens, configuring US, EU, or self-hosted servers, listing and managing projects and secrets, and injecting secrets into trusted processes.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[hajekt2](https://clawhub.ai/user/hajekt2)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers and engineers use this skill to operate Bitwarden Secrets Manager through bws while installing the CLI, validating authentication, inspecting metadata, configuring server targets, and injecting or managing secrets with safeguards against accidental disclosure.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can automatically download and run a mutable remote installer when bws is missing.\n\nMitigation: Prefer installing bws from a verified Bitwarden source before using the skill, and review the installer path when automatic installation is allowed.\n\nRisk: The skill operates on real Bitwarden machine-account tokens and decrypted secret values.\n\nMitigation: Use least-privilege machine-account tokens, keep credentials out of prompts and logs, and restrict agents to trusted runtime secret-injection paths.\n\nRisk: Creating or editing secrets may expose values through command arguments or shell traces.\n\nMitigation: Allow secret writes only when the scope is exact, disable shell tracing, avoid literal values in command history, and prefer trusted process injection for secret consumption.\n\n## Reference(s):\n\n- [Bitwarden Secrets Manager CLI](https://bitwarden.com/help/secrets-manager-cli/)\n- [Bitwarden access tokens](https://bitwarden.com/help/access-tokens/)\n- [Bitwarden Secrets Manager SDK and bws releases](https://github.com/bitwarden/sdk-sm)\n- [bws CLI guide](references/cli-guide.md)\n- [Server-resolved GitHub provenance](https://github.com/hajekt2/bitwarden-secrets-manager-cli)\n- [ClawHub skill page](https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli)\n- [Agent Skills specification](https://agentskills.io)\n- [Skills CLI](https://github.com/vercel-labs/skills)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, Code]\n\n**Output Format:** [Markdown guidance with inline shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Emphasizes secret-safe handling and avoids printing access tokens or secret values.]\n\n## Skill Version(s):\n\n0.1.0 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.1.0:agents/openai.yaml\n\ninterface:\n  display_name: \"Bitwarden Secrets Manager CLI\"\n  short_description: \"Use Bitwarden Secrets Manager safely\"\n  default_prompt: \"Use $bitwarden-secrets-manager-cli to retrieve and inject secrets safely with bws.\"\n\nFile v0.1.0:LICENSE\n\nMIT License\n\nCopyright (c) 2026 Tomas Hajek\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.","readmeExcerpt":"Skill: Bitwarden Secrets Manager CLI Owner: hajekt2 Summary: Use Bitwarden Secrets Manager safely Tags: latest:0.1.0 Version history: v0.1.0 | 2026-07-25T22:24:25.235Z | auto bitwarden-secrets-manager-cli 0.1.0 - Initial release introducing Bitwarden Secrets Manager CLI automation via the bws command-line tool. - Supports installing the CLI if missing and authenticating with machine-account access tokens. - Allows co","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"bws project list --output table\nscripts/list-secret-metadata.sh\nscripts/list-secret-metadata.sh \"$PROJECT_ID\""},{"language":"bash","snippet":"SECRET_VALUE=\"$(bws secret get \"$SECRET_ID\" --output json | jq -r '.value')\"\nexport SECRET_VALUE\ntrusted-command-reading-env\nunset SECRET_VALUE"},{"language":"bash","snippet":"bws run --project-id \"$PROJECT_ID\" -- trusted-command"},{"language":"bash","snippet":"bws run --project-id \"$PROJECT_ID\" --no-inherit-env -- trusted-command"},{"language":"bash","snippet":"bws project create \"$PROJECT_NAME\" --output none\nbws project edit \"$PROJECT_ID\" --name \"$NEW_NAME\" --output none\nbws secret create \"$SECRET_KEY\" \"$SECRET_VALUE\" \"$PROJECT_ID\" --output none\nbws secret edit \"$SECRET_ID\" --value \"$SECRET_VALUE\" --output none"},{"language":"bash","snippet":"bws config server-base https://vault.bitwarden.eu"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: bitwarden-secrets-manager-cli\ndescription: Operate Bitwarden Secrets Manager through the `bws` CLI, including installing the CLI when missing, authenticating with machine-account access tokens, configuring US, EU, or self-hosted servers, listing and managing projects and secrets, and injecting secrets into trusted processes. Use for requests involving Bitwarden Secrets Manager, `bws`, `BWS_ACCESS_TOKEN`, machine accounts, secret retrieval, secret injection, or Secrets Manager automation and CI/CD.\n---\n\n# Bitwarden Secrets Manager CLI\n\nUse `bws` with secret-safe defaults.\nInstall it when missing, authenticate without exposing the access token, inspect read-only state first, and make mutations only when the requested scope is exact.\n\n## Start every task\n\n1. Run `scripts/ensure-bws.sh`.\n   On native Windows without a POSIX shell, use the official PowerShell installer documented in [references/cli-guide.md](references/cli-guide.md).\n2. Run `bws --version` and `bws --help` when command behavior may vary by version.\n3. Determine the server before authenticating.\n   Bitwarden US is the default.\n   Configure EU or self-hosted deployments only when the user identifies that environment.\n4. Use an existing `BWS_ACCESS_TOKEN` environment variable.\n   If none exists, ask the user to inject or export the token in their own secure environment.\n5. Run `scripts/check-auth.sh` to perform a read-only authentication check that emits no vault data.\n\nRead [references/cli-guide.md](references/cli-guide.md) for command syntax, output behavior, configuration, and troubleshooting.\nUse the live `bws <command> --help` output and linked official Bitwarden documentation as the final authority.\n\n## Protect credentials and secret values\n\n- Never print, repeat, summarize, or commit an access token or secret value.\n- Never place an access token directly in a command line with `--access-token`.\n  Command arguments can appear in shell history, process listings, logs, and agent traces.\n- Prefer runtime secret injection or an already-set `BWS_ACCESS_TOKEN`.\n  If secure injection is unavailable, ask the user to export it in their own shell and confirm when ready.\n- Do not create `.env` files unless the user explicitly asks.\n  If one is required, keep it outside version control, restrict permissions, and verify that Git ignores it.\n- Do not expose raw `bws secret list` or `bws secret get` JSON in logs because both include secret values.\n- Use `scripts/list-secret-metadata.sh [PROJECT_ID]` when only IDs and keys are needed.\n- Prefer `bws run` to pass values directly to a trusted process instead of retrieving and displaying them.\n- Use `--output none` for mutations unless returned metadata is required.\n\nIf a token appears in conversation or tool output, do not echo it.\nRecommend rotation if it was exposed in a durable or public location.\n\n## Work read-only first\n\nResolve the exact organization-visible objects before changing anything:\n\n```bash\nbws project list --output table\nsc"},{"path":"README.md","content":"# Bitwarden Secrets Manager CLI Skill\n\nAn Agent Skill for working safely with [Bitwarden Secrets Manager](https://bitwarden.com/products/secrets-manager/) through the `bws` command-line interface.\n\nThe skill helps AI coding agents install and operate `bws`, authenticate with a machine-account access token, inspect projects and secrets, inject secrets into trusted processes, and manage Secrets Manager resources without exposing sensitive values.\n\nThis repository follows the open [Agent Skills specification](https://agentskills.io) and can be installed with the [Skills CLI](https://github.com/vercel-labs/skills) into Codex, Claude Code, Cursor, and other supported agents.\n\n> [!IMPORTANT]\n> `bws` is the Bitwarden Secrets Manager CLI.\n> It is separate from the `bw` CLI used with Bitwarden Password Manager.\n\n## Install\n\nInstall the skill with the standard Skills CLI command:\n\n```bash\nnpx skills add hajekt2/bitwarden-secrets-manager-cli\n```\n\nThe installer detects supported agents and asks where to install the skill.\nProject installation is the default.\n\nInstall it globally for use across projects:\n\n```bash\nnpx skills add hajekt2/bitwarden-secrets-manager-cli -g\n```\n\nInstall it globally for Codex without interactive prompts:\n\n```bash\nnpx skills add hajekt2/bitwarden-secrets-manager-cli \\\n  --skill bitwarden-secrets-manager-cli \\\n  --agent codex \\\n  --global \\\n  --yes\n```\n\nList the skill without installing it:\n\n```bash\nnpx skills add hajekt2/bitwarden-secrets-manager-cli --list\n```\n\nThe Skills CLI requires Node.js and npm.\nSee the [Skills CLI documentation](https://github.com/vercel-labs/skills) for supported agents, installation scopes, and additional options.\n\n## What the skill does\n\n- Installs `bws` from Bitwarden's official installer when the CLI is missing.\n- Supports Bitwarden US, Bitwarden EU, and self-hosted server configuration.\n- Authenticates through the `BWS_ACCESS_TOKEN` environment variable.\n- Validates authentication with a read-only request that prints no vault data.\n- Lists secret metadata without printing secret values or notes.\n- Retrieves and injects secrets without exposing them in agent output.\n- Guides safe project and secret creation, editing, and deletion.\n- Uses `bws run` to inject secrets directly into trusted processes.\n- Uses live `bws --help` output and Bitwarden documentation as the final authority.\n\n## Authentication\n\nCreate an access token for a [Bitwarden Secrets Manager machine account](https://bitwarden.com/help/access-tokens/).\nThe machine account must have access to the projects and secrets required by the task.\n\nProvide the token as `BWS_ACCESS_TOKEN` in the environment where the agent runs.\nFor example, read it without echoing it in Bash:\n\n```bash\nread -rsp \"BWS access token: \" BWS_ACCESS_TOKEN\nprintf '\\n'\nexport BWS_ACCESS_TOKEN\n```\n\nUse your shell, CI secret store, agent runtime, or another secure environment-injection mechanism to set the value.\nDo not paste the token into prompts, commit it, store it in tracked"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn79sz4h2hzc5wxxtarf1zr47980m8bj\",\n  \"slug\": \"bitwarden-secrets-manager-cli\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1785018265235\n}"},{"path":"references/cli-guide.md","content":"# `bws` CLI guide\n\nThis guide summarizes the official Bitwarden Secrets Manager CLI documentation.\nCheck the live sources and `bws <command> --help` before relying on version-sensitive behavior.\n\nOfficial sources:\n\n- [Secrets Manager CLI](https://bitwarden.com/help/secrets-manager-cli/)\n- [Access tokens](https://bitwarden.com/help/access-tokens/)\n- [`bws` source and releases](https://github.com/bitwarden/sdk-sm)\n\n## Install\n\nBitwarden provides native binaries for Linux, macOS, and Windows.\nIts official installers download a release archive and verify its SHA-256 checksum.\n\nPOSIX:\n\n```bash\ncurl -fsSL https://bws.bitwarden.com/install -o /tmp/install-bws.sh\nsh /tmp/install-bws.sh\n```\n\nPowerShell:\n\n```powershell\niwr https://bws.bitwarden.com/install | iex\n```\n\nCargo:\n\n```bash\ncargo install bws --locked\n```\n\nDocker:\n\n```bash\ndocker run --rm -it ghcr.io/bitwarden/bws --help\n```\n\nThe bundled `scripts/ensure-bws.sh` uses the official POSIX installer only when `bws` is not already on `PATH`.\n\n## Authenticate\n\nCreate an access token for a Bitwarden Secrets Manager machine account.\nThe token can access only the projects and secrets assigned to that machine account.\nBitwarden does not retain a recoverable copy of the token after creation.\n\nPrefer an environment variable:\n\n```bash\nexport BWS_ACCESS_TOKEN='set-this-in-your-own-secure-shell'\n```\n\nDo not include the real value in documentation, committed files, shell history, process arguments, chat output, or agent tool calls.\nAlthough `bws` supports `--access-token`, avoid it because command arguments are easier to expose.\n\nValidate authentication without printing vault data:\n\n```bash\nbws project list --output none\n```\n\nFrequent new sessions from one IP address can be rate-limited.\nThe CLI stores encrypted authentication state under `~/.config/bws/state` by default to reduce repeated authentication.\n\n## Configure a server\n\nBitwarden US is the default.\nEU and self-hosted users must configure their server.\n\n```bash\nbws config server-base https://vault.bitwarden.eu\nbws config server-base https://bitwarden.example.com\n```\n\nThe default config is `~/.config/bws/config`.\nUse `--profile`, `BWS_PROFILE`, `--config-file`, or `BWS_CONFIG_FILE` to isolate configurations.\nUse `--server-url` or `BWS_SERVER_URL` for a per-command override.\n\n## Outputs\n\nSupported output formats are `json`, `yaml`, `env`, `table`, `tsv`, and `none`.\nJSON is the default.\n\nSecret `get` and `list` output includes decrypted values.\nDo not print it when only IDs, keys, or status are needed.\n\nUse:\n\n```bash\nscripts/list-secret-metadata.sh\nscripts/list-secret-metadata.sh \"$PROJECT_ID\"\n```\n\nUse `--output none` for writes when no response body is required.\nThe `env` output format comments out non-POSIX key names, but it still contains secret values and must be treated as sensitive.\n\n## Projects\n\n```bash\nbws project list\nbws project get \"$PROJECT_ID\"\nbws project create \"$NAME\"\nbws project edit \"$PROJECT_ID\" --name \"$NEW_NAME\"\nbws project delete \"$PROJEC"},{"path":"skill-card.md","content":"## Description:\n\nOperate Bitwarden Secrets Manager through the bws CLI, including installing the CLI when missing, authenticating with machine-account access tokens, configuring US, EU, or self-hosted servers, listing and managing projects and secrets, and injecting secrets into trusted processes.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[hajekt2](https://clawhub.ai/user/hajekt2)\n\n### License/Terms of Use:\n\nMIT\n\n## Use Case:\n\nDevelopers and engineers use this skill to operate Bitwarden Secrets Manager through bws while installing the CLI, validating authentication, inspecting metadata, configuring server targets, and injecting or managing secrets with safeguards against accidental disclosure.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can automatically download and run a mutable remote installer when bws is missing.\n\nMitigation: Prefer installing bws from a verified Bitwarden source before using the skill, and review the installer path when automatic installation is allowed.\n\nRisk: The skill operates on real Bitwarden machine-account tokens and decrypted secret values.\n\nMitigation: Use least-privilege machine-account tokens, keep credentials out of prompts and logs, and restrict agents to trusted runtime secret-injection paths.\n\nRisk: Creating or editing secrets may expose values through command arguments or shell traces.\n\nMitigation: Allow secret writes only when the scope is exact, disable shell tracing, avoid literal values in command history, and prefer trusted process injection for secret consumption.\n\n## Reference(s):\n\n- [Bitwarden Secrets Manager CLI](https://bitwarden.com/help/secrets-manager-cli/)\n- [Bitwarden access tokens](https://bitwarden.com/help/access-tokens/)\n- [Bitwarden Secrets Manager SDK and bws releases](https://github.com/bitwarden/sdk-sm)\n- [bws CLI guide](references/cli-guide.md)\n- [Server-resolved GitHub provenance](https://github.com/hajekt2/bitwarden-secrets-manager-cli)\n- [ClawHub skill page](https://clawhub.ai/hajekt2/skills/bitwarden-secrets-manager-cli)\n- [Agent Skills specification](https://agentskills.io)\n- [Skills CLI](https://github.com/vercel-labs/skills)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Shell commands, Configuration, Code]\n\n**Output Format:** [Markdown guidance with inline shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Emphasizes secret-safe handling and avoids printing access tokens or secret values.]\n\n## Skill Version(s):\n\n0.1.0 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1396,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T10:57:38.991Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T10:57:38.991Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:08:11.965Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}