{"id":"05790383-0a39-4e32-af00-cd87736f5b73","slug":"clawhub-zw008-identity-aiops","name":"identity-aiops","description":"Use this skill whenever the user needs to operate a Keycloak or authentik identity provider — a one-shot overview, realm settings, users with sessions/credentials/groups/lockout status, authentication and admin events, OAuth/OIDC clients, four flagship RCAs (login-failure/lockout-storm, stale access, client misconfiguration, MFA coverage), and governed writes (disable/enable a user, revoke sessions, require a password reset, replace redirect URIs, rotate a client secret). Always use this skill for \"Keycloak\", \"authentik\", \"realm\", \"SSO users\", \"login failures\", \"brute force logins\", \"locked out users\", \"stale accounts\", \"service account misuse\", \"redirect URI\", \"PKCE\", \"implicit flow\", \"client secret rotation\", \"MFA coverage\", \"who has no 2FA\" when the context is a Keycloak/authentik IdP. Do NOT use when the target is something other than a Keycloak/authentik identity provider (a hypervisor, storage appliance, backup product, container-orchestration cluster, firewall, database, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Cloud IdPs (Okta, Entra ID, Auth0) are out of scope. Governed identity operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).","canonicalUrl":"https://www.xpersona.co/agent/clawhub-zw008-identity-aiops","sourceUrl":"https://clawhub.ai/zw008/identity-aiops","homepage":"https://clawhub.ai/zw008/skills/identity-aiops","source":"CLAWHUB","vendor":{"slug":"clawhub","label":"Clawhub","url":"https://clawhub.ai/zw008/skills/identity-aiops"},"protocols":["OPENCLEW"],"capabilities":[],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":"0.8.5","freshnessAt":"2026-10-10T14:17:47.744Z","freshnessLabel":"Oct 10, 2026","securityReviewed":true,"openapiReady":false,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Oct 10, 2026"},{"label":"Vendor","value":"Clawhub"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"0.8.5"}],"factsPreview":[{"factKey":"vendor","category":"vendor","label":"Vendor","value":"Clawhub","href":"https://clawhub.ai/zw008/skills/identity-aiops","sourceUrl":"https://clawhub.ai/zw008/skills/identity-aiops","sourceType":"profile","confidence":"medium","observedAt":"2026-10-10T14:17:47.744Z","isPublic":true},{"factKey":"protocols","category":"compatibility","label":"Protocol compatibility","value":"OpenClaw","href":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-identity-aiops/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-identity-aiops/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-10-10T14:17:47.744Z","isPublic":true},{"factKey":"traction","category":"adoption","label":"Adoption signal","value":"1.4K downloads","href":"https://clawhub.ai/zw008/identity-aiops","sourceUrl":"https://clawhub.ai/zw008/identity-aiops","sourceType":"profile","confidence":"medium","observedAt":"2026-10-10T14:17:47.744Z","isPublic":true},{"factKey":"latest_release","category":"release","label":"Latest release","value":"0.8.5","href":"https://clawhub.ai/zw008/identity-aiops","sourceUrl":"https://clawhub.ai/zw008/identity-aiops","sourceType":"release","confidence":"medium","observedAt":"2026-09-16T23:25:43.154Z","isPublic":true},{"factKey":"handshake_status","category":"security","label":"Handshake status","value":"UNKNOWN","href":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-identity-aiops/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zw008-identity-aiops/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true}],"highlights":["1.4K downloads","Trust evidence available"],"agentCard":{"name":"identity-aiops","description":"Use this skill whenever the user needs to operate a Keycloak or authentik identity provider — a one-shot overview, realm settings, users with sessions/credentials/groups/lockout status, authentication and admin events, OAuth/OIDC clients, four flagship RCAs (login-failure/lockout-storm, stale access, client misconfiguration, MFA coverage), and governed writes (disable/enable a user, revoke sessions, require a password reset, replace redirect URIs, rotate a client secret). Always use this skill for \"Keycloak\", \"authentik\", \"realm\", \"SSO users\", \"login failures\", \"brute force logins\", \"locked out users\", \"stale accounts\", \"service account misuse\", \"redirect URI\", \"PKCE\", \"implicit flow\", \"client secret rotation\", \"MFA coverage\", \"who has no 2FA\" when the context is a Keycloak/authentik IdP. Do NOT use when the target is something other than a Keycloak/authentik identity provider (a hypervisor, storage appliance, backup product, container-orchestration cluster, firewall, database, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Cloud IdPs (Okta, Entra ID, Auth0) are out of scope. Governed identity operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).","source":"CLAWHUB","sourceId":"clawhub:s171xgnmqse0nqvgqvqnaq5f9183kyre:identity-aiops","homepage":"https://clawhub.ai/zw008/skills/identity-aiops","repository":"https://clawhub.ai/zw008/identity-aiops","documentation":"https://www.xpersona.co/agent/clawhub-zw008-identity-aiops","protocols":["OPENCLEW"],"examples":[{"kind":"example","language":"bash","snippet":"uv tool install identity-aiops\nidentity-aiops init       # wizard: pick platform (keycloak/authentik) + encrypted secret\nidentity-aiops doctor"},{"kind":"example","language":"bash","snippet":"openclaw plugins install clawhub:@zw008/identity-aiops\nopenclaw skills info identity-aiops          # expect: Visible to model: yes"}]}}