{"id":"a5ba9ca1-3cc2-47d6-ac58-d7776ff0eb76","slug":"sukiraman-canary","name":"canary","description":"Scans your OpenClaw environment for leaked secrets â€” API keys, tokens, credentials in .env files, installed skills, and shell history. Runs silently on startup, deep scans on demand. Fixes issues with your permission.","canonicalUrl":"https://www.xpersona.co/skill/sukiraman-canary","sourceUrl":"https://github.com/sukiraman/canary","homepage":null,"source":"GITHUB_OPENCLEW","vendor":{"slug":"sukiraman","label":"Sukiraman","url":"https://github.com/sukiraman/canary"},"protocols":["OPENCLEW"],"capabilities":["covers","see","always","be","stop","read","ask","decrypt","results","across","it","use","identify","should","make","time","list","only","add","plant","paths","tell","additional","exclude_paths","too","also","my","fix","path","from","your","anytime","tighten","is","state","clear","delete","exclude","uninstall"],"trustScore":null,"trustConfidence":"unknown","artifactCount":0,"benchmarkCount":0,"lastRelease":null,"freshnessAt":"2026-03-01T06:04:17.762Z","freshnessLabel":"Mar 1, 2026","securityReviewed":true,"openapiReady":true,"stats":[{"label":"Trust score","value":"Unknown"},{"label":"Compatibility","value":"OpenClaw"},{"label":"Freshness","value":"Mar 1, 2026"},{"label":"Vendor","value":"Sukiraman"},{"label":"Artifacts","value":"0"},{"label":"Benchmarks","value":"0"},{"label":"Last release","value":"Unpublished"}],"factsPreview":[{"factKey":"docs_crawl","category":"integration","label":"Crawlable docs","value":"6 indexed pages on the official domain","href":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceUrl":"https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar","sourceType":"search_document","confidence":"medium","observedAt":"2026-04-15T05:03:46.393Z","isPublic":true},{"factKey":"vendor","category":"vendor","label":"Vendor","value":"Sukiraman","href":"https://github.com/sukiraman/canary","sourceUrl":"https://github.com/sukiraman/canary","sourceType":"profile","confidence":"medium","observedAt":"2026-03-01T06:04:17.762Z","isPublic":true},{"factKey":"protocols","category":"compatibility","label":"Protocol compatibility","value":"OpenClaw","href":"https://www.xpersona.co/api/v1/agents/sukiraman-canary/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/sukiraman-canary/contract","sourceType":"contract","confidence":"medium","observedAt":"2026-02-24T19:44:21.401Z","isPublic":true},{"factKey":"auth_modes","category":"compatibility","label":"Auth modes","value":"api_key, oauth","href":"https://www.xpersona.co/api/v1/agents/sukiraman-canary/contract","sourceUrl":"https://www.xpersona.co/api/v1/agents/sukiraman-canary/contract","sourceType":"contract","confidence":"high","observedAt":"2026-02-24T19:44:21.401Z","isPublic":true},{"factKey":"schema_refs","category":"artifact","label":"Machine-readable schemas","value":"OpenAPI or schema references published","href":"https://github.com/sukiraman/canary#input","sourceUrl":"https://www.xpersona.co/api/v1/agents/sukiraman-canary/contract","sourceType":"contract","confidence":"high","observedAt":"2026-02-24T19:44:21.401Z","isPublic":true},{"factKey":"handshake_status","category":"security","label":"Handshake status","value":"UNKNOWN","href":"https://www.xpersona.co/api/v1/agents/sukiraman-canary/trust","sourceUrl":"https://www.xpersona.co/api/v1/agents/sukiraman-canary/trust","sourceType":"trust","confidence":"medium","observedAt":null,"isPublic":true}],"highlights":["Schema refs published","Trust evidence available"],"agentCard":{"name":"canary","description":"Scans your OpenClaw environment for leaked secrets â€” API keys, tokens, credentials in .env files, installed skills, and shell history. Runs silently on startup, deep scans on demand. Fixes issues with your permission.","source":"GITHUB_OPENCLEW","sourceId":"github:1152102382","repository":"https://github.com/sukiraman/canary","documentation":"https://www.xpersona.co/skill/sukiraman-canary/agent/sukiraman-canary","protocols":["OPENCLEW"],"capabilities":["covers","see","always","be","stop","read","ask","decrypt","results","across","it","use","identify","should","make","time","list","only","add","plant","paths","tell","additional","exclude_paths","too","also","my","fix","path","from","your","anytime","tighten","is","state","clear","delete","exclude","uninstall"],"languages":["typescript"],"install":{"command":"git clone https://github.com/sukiraman/canary.git","ecosystem":"git"},"examples":[{"kind":"example","language":"text","snippet":"# â”€â”€ AI Services â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€\n# OpenAI\nsk-[a-zA-Z0-9]{48,}\n\n# Anthropic\nsk-ant-[a-zA-Z0-9\\-]{36,}\n\n# Hugging Face\nhf_[a-zA-Z0-9]{34,}\n\n# â”€â”€ Cloud Providers â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€\n# AWS Access Key\nAKIA[0-9A-Z]{16}\n\n# AWS Secret Key (context-dependent: ONLY flag when found within 5 lines of an AWS access key or in a file/variable named aws, secret, or credential)\n[0-9a-zA-Z/+=]{40}\n\n# Google Cloud / Firebase API Key\nAIza[0-9A-Za-z\\-_]{35}\n\n# GCP Service Account JSON\n\"type\"\\s*:\\s*\"service_account\"\n\n# Azure Storage Account Key (base64, ~88 chars â€” ONLY flag in Azure config files or variables containing 'azure', 'storage', or 'account')\n[A-Za-z0-9+/]{86,}==\n\n# Azure Subscription Key (32 hex â€” ONLY flag when near 'Ocp-Apim-Subscription-Key' or in Azure config context)\n[0-9a-f]{32}\n\n# DigitalOcean\ndo[po]_v1_[a-f0-9]{64}\n\n# Heroku (ONLY flag when near 'HEROKU', 'heroku', or in heroku config context â€” bare UUIDs are too common)\n[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}\n\n# Cloudflare\nv1\\.0-[a-z0-9]{24,}\n\n# Vercel\nvercel_[a-zA-Z0-9]{24,}\n\n# â”€â”€ Code & Package Registries â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€\n# GitHub Personal Access Token\nghp_[a-zA-Z0-9]{36}\ngithub_pat_[a-zA-Z0-9_]{80,}\n\n# GitHub OAuth / App tokens\ngh[oprsu]_[a-zA-Z0-9]{36,}\n\n# GitLab\nglpat-[a-zA-Z0-9\\-_]{20,}\n\n# NPM\nnpm_[a-zA-Z0-9]{36,}\n\n# PyPI\npypi-[a-zA-Z0-9]{16,}\n\n# Docker Hub\ndckr_pat_[a-zA-Z0-9\\-_]{27,}\n\n# â”€â”€ Payment & SaaS â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€â”€\n# Stripe (live and test)\n[sr]k_(live|test)_[a-zA-Z0-9]{24,}\n\n# Twilio\nSK[0-9a-fA-F]{32}\n\n# SendGrid\nSG\\.[a-zA-Z0-9\\-_]{22,}\\.[a-zA-Z0-9\\-_]"},{"kind":"example","language":"yaml","snippet":"# .canary/config.yml\n\n# Add your own directories or files for Canary to include in deep scans\ncustom_paths:\n  - ~/projects/my-app/.env\n  - ~/work/secrets/\n  - /opt/myservice/config/\n  - ~/Dropbox/credentials/\n\n# Exclude paths you don't want Canary to scan\nexclude_paths:\n  - ~/projects/test-app/.env.example\n  - ~/.config/some-noisy-app/\n\n# Set to true to include custom paths in the light startup scan too\ninclude_in_light_scan: false"}]}}