Agent skill

Credentials

by alsk1992 in alsk1992/CloddsBot

Secure credential management for trading platforms. An agent skill from alsk1992/CloddsBot.

MITAuto-check passedBusiness, Finance & HR

Install Credentials

skills CLI
$ npx skills add alsk1992/CloddsBot --skill credentials -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alsk1992/CloddsBot credentials --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alsk1992/CloddsBot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/skills/bundled/credentials .claude/skills/credentials && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
credentials
GitHub stars
2.9k
Token cost
~1.4k tokens
SKILL.md length
164 words
Files
2
Skills in repo
118
Repo updated
First seen
Licence
MIT

At a glance

Secure credential management for trading platforms. An agent skill from alsk1992/CloddsBot.

  • Works in 5 steps: Strong encryption key — Use openssl rand… → Rotate keys regularly — Update API keys… → Test after adding — Always verify… → …
  • Tasks that involve Trading and backtesting
  • SKILL.md covers Chat Commands, TypeScript API Reference, Supported Platforms and Security Features, plus 2 more sections
  • Runs TypeScript scripts from its folder; calls openssl; needs CREDENTIALS_KEY and POLYMARKET_API_KEY

What it does

Credentials is an agent skill from alsk1992/CloddsBot. Secure credential management for trading platforms

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `index.ts`).

It sits in Business, Finance & HR, covering Trading and backtesting. The repository describes itself as: Open Source AI trading agent that operates autonomously across 1000+ markets - Polymarket, Kalshi, Binance, Hyperliquid, Solana DEXs, 5 EVM chains. Scans for edge, executes… The licence is MIT.

When your agent uses it

  • Tasks that involve Trading and backtesting

Example prompts

  • “/credentials”

Requirements

  • Node.js
  • A credential in CREDENTIALS_KEY
  • A credential in POLYMARKET_API_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Strong encryption key — Use openssl rand -hex 32
  2. Rotate keys regularly — Update API keys periodically
  3. Test after adding — Always verify credentials work
  4. Minimal permissions — Use read-only keys when possible
  5. Backup securely — Keep encrypted backups offline

What it can do on your machine

Read from SKILL.md and the folder at commit c930628. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    Shell commands in SKILL.md call:

    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CREDENTIALS_KEY
    • POLYMARKET_API_KEY
    • POLYMARKET_API_SECRET
    • POLYMARKET_PRIVATE_KEY
    • KALSHI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Credentials loads about 1.4k tokens when it runs. Until then it costs about 16 tokens; SKILL.md has 164 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~16
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alsk1992/CloddsBot at commit c930628, republished under its MIT licence (© alsk1992). 164 words, ~1,441 tokens.

Download SKILL.mdSave it as .claude/skills/credentials/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
credentials
description
Secure credential management for trading platforms
emoji
🔐

Credentials - Complete API Reference

Securely store and manage API credentials for trading platforms with AES-256-GCM encryption.


Chat Commands

Add Credentials
/creds add polymarket                       Interactive setup
/creds add kalshi --key abc --secret xyz    Direct setup
/creds add binance                          Add Binance API
/creds add hyperliquid                      Add wallet key
View Credentials
/creds list                                 List configured platforms
/creds status                               Encryption system status
/creds test polymarket                      Test API connection
/creds check polymarket                     Verify credentials work
Remove Credentials
/creds remove polymarket                    Remove platform creds
/creds clear                                Clear all (careful!)
Auth Status
/auth status                                Overall auth status
/auth refresh kalshi                        Refresh tokens
/auth cooldown                              View cooldown status

TypeScript API Reference

Create Credentials Manager
typescript
import { createCredentialsManager } from 'clodds/credentials';

const creds = createCredentialsManager({
  // Encryption key (required)
  encryptionKey: process.env.CREDENTIALS_KEY,

  // Storage backend
  storage: 'sqlite',  // 'sqlite' | 'postgres'
  dbPath: './credentials.db',

  // Cooldown settings
  cooldownMinutes: 15,
  maxFailures: 3,
});
Set Credentials
typescript
// Polymarket (API + signing key)
await creds.setCredentials({
  userId: 'user-123',
  platform: 'polymarket',
  credentials: {
    apiKey: 'pk_...',
    apiSecret: 'sk_...',
    privateKey: '0x...',  // For order signing
    funderAddress: '0x...',
  },
});

// Kalshi (API key)
await creds.setCredentials({
  userId: 'user-123',
  platform: 'kalshi',
  credentials: {
    email: 'user@example.com',
    apiKey: 'key_...',
  },
});

// Binance Futures
await creds.setCredentials({
  userId: 'user-123',
  platform: 'binance',
  credentials: {
    apiKey: 'abc...',
    apiSecret: 'xyz...',
  },
});

// Hyperliquid (wallet)
await creds.setCredentials({
  userId: 'user-123',
  platform: 'hyperliquid',
  credentials: {
    privateKey: '0x...',
    walletAddress: '0x...',
  },
});
Get Credentials
typescript
// Get for specific platform
const polymarketCreds = await creds.getCredentials({
  userId: 'user-123',
  platform: 'polymarket',
});

if (polymarketCreds) {
  console.log(`API Key: ${polymarketCreds.apiKey}`);
  // Credentials are decrypted on retrieval
}

// List user's configured platforms
const platforms = await creds.listUserPlatforms('user-123');
console.log(`Configured: ${platforms.join(', ')}`);
Delete Credentials
typescript
// Remove single platform
await creds.deleteCredentials({
  userId: 'user-123',
  platform: 'kalshi',
});

// Remove all for user
await creds.deleteAllCredentials('user-123');
Test Credentials
typescript
// Test API connection
const result = await creds.testCredentials({
  userId: 'user-123',
  platform: 'polymarket',
});

if (result.success) {
  console.log(`✓ Connected to ${result.platform}`);
  console.log(`  Balance: $${result.balance}`);
} else {
  console.log(`✗ Failed: ${result.error}`);
}
Cooldown Management
typescript
// Mark failed auth attempt
await creds.markFailure({
  userId: 'user-123',
  platform: 'kalshi',
  error: 'Invalid API key',
});

// Check if in cooldown
const inCooldown = await creds.isInCooldown({
  userId: 'user-123',
  platform: 'kalshi',
});

if (inCooldown) {
  const remaining = await creds.getCooldownRemaining({
    userId: 'user-123',
    platform: 'kalshi',
  });
  console.log(`Cooldown: ${remaining} minutes remaining`);
}

// Mark successful auth (resets failures)
await creds.markSuccess({
  userId: 'user-123',
  platform: 'kalshi',
});
Build Trading Context
typescript
// Get ready-to-use trading context
const context = await creds.buildTradingContext({
  userId: 'user-123',
  platform: 'polymarket',
});

// Context includes authenticated client
await context.client.getBalance();
await context.client.placeOrder({ ... });

Supported Platforms

PlatformCredentials Required
PolymarketAPI key, secret, private key, funder address
KalshiEmail, API key
BetfairApp key, session token
SmarketsAPI key
BinanceAPI key, secret
BybitAPI key, secret
HyperliquidPrivate key, wallet address
MEXCAPI key, secret

Security Features

FeatureDescription
AES-256-GCMMilitary-grade encryption at rest
Per-user keysIsolated credential storage
CooldownRate limits on failed attempts
No loggingSecrets never logged
Memory wipeCredentials cleared from memory after use

Environment Variables

bash
# Required encryption key (generate with: openssl rand -hex 32)
CREDENTIALS_KEY=your-64-char-hex-key

# Optional: per-platform keys
POLYMARKET_API_KEY=pk_...
POLYMARKET_API_SECRET=sk_...
POLYMARKET_PRIVATE_KEY=0x...
KALSHI_EMAIL=user@example.com
KALSHI_API_KEY=key_...

Best Practices

  1. Strong encryption key — Use openssl rand -hex 32
  2. Rotate keys regularly — Update API keys periodically
  3. Test after adding — Always verify credentials work
  4. Minimal permissions — Use read-only keys when possible
  5. Backup securely — Keep encrypted backups offline

© alsk1992, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in src/skills/bundled/credentials of alsk1992/CloddsBot.

  • SKILL.md
  • index.ts

Open the folder on GitHubat commit c930628

Compare with similar skills

Credentials next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Credentials compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Credentials this skillalsk1992/CloddsBot2.9k—~1.4kAutomated safety check: PassMIT
Tushare Datazillionare/zillionare3182 repos~2.3kAutomated safety check: PassNone
Tradingview MCPatilaahmettaner/tradingview-mcp4.9k—~1.3kAutomated safety check: PassMIT
Digital Oraclekomako-workshop/digital-oracle867—~5.9kAutomated safety check: PassMIT
Polyclawchainstacklabs/polyclaw3601 repos~2kAutomated safety check: PassApache-2.0
Markdownfacioquo/stock-indicators-dotnet1.2k—~812Automated safety check: PassApache-2.0

Similar skills

  • Tushare Data

    zillionare/zillionare

    面向中文自然语言的 Tushare 数据研究技能。用于把“看看这只股票最近怎么样”“帮我查财报趋势”“最近哪个板块最强”“北向资金在买什么”“给我导出一份行情数据”这类请求,转成可执行的数据获取、清洗、对比、筛选、导出与简要分析流程。适用于 A 股、指数、ETF/基金、财务、估值、资金流、公告新闻、板块概念与宏观数据等研究场景。

    318 GitHub starsUsed in 2 repos~2.3k tokens
    Business, Finance & HRAuto-check passed
  • Tradingview MCP

    atilaahmettaner/tradingview-mcp

    AI Trading Intelligence — live prices, 30+ technical indicators, backtesting (6 strategies), walk-forward overfitting detection, trade logs, equity curves, licensed news sentiment (Marketaux), and…

    4.9k GitHub stars~1.3k tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Digital Oracle

    komako-workshop/digital-oracle

    Answer prediction questions using market trading data, not opinions.

    867 GitHub stars~5.9k tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • Polyclaw

    chainstacklabs/polyclaw

    Trade on Polymarket via split + CLOB execution. An agent skill from chainstacklabs/polyclaw.

    360 GitHub starsUsed in 1 repo~2k tokens
    Business, Finance & HRAuto-check passed
  • Markdown

    facioquo/stock-indicators-dotnet

    Format and lint Markdown in this repository against GitHub Flavored Markdown and its markdownlint-cli2 configuration — headers, lists, code fences, callouts (VitePress containers on docs-site pages…

    1.2k GitHub stars~812 tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Openmobius Skill

    MobiusQuant/OpenMobius-skill

    Provides multi-school trading Q&A, chart/OHLCV analysis, annotation, and fresh-market workflows covering ICT/SMC, ChanLun, Wyckoff, Price Action, Order Flow, VSA, and Elliott Wave.

    695 GitHub stars~7.2k tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed

More from alsk1992/CloddsBot

All 118 skills in this repo
  • Qmd

    alsk1992/CloddsBot

    Local hybrid search for markdown notes and docs. An agent skill from alsk1992/CloddsBot.

    2.9k GitHub starsUsed in 3 repos~1.2k tokens
    Auto-check passed
  • Drift SDK

    alsk1992/CloddsBot

    Drift Protocol perpetual futures trading on Solana (direct SDK)

    2.9k GitHub starsUsed in 1 repo~625 tokens
    Auto-check passed
  • Edge

    alsk1992/CloddsBot

    Find mispriced markets by comparing to external models and data sources

    2.9k GitHub starsUsed in 1 repo~472 tokens
    Auto-check passed
  • Embeddings

    alsk1992/CloddsBot

    Vector embeddings configuration and semantic search. An agent skill from alsk1992/CloddsBot.

    2.9k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • News

    alsk1992/CloddsBot

    Monitor news and correlate with prediction market movements. An agent skill from alsk1992/CloddsBot.

    2.9k GitHub starsUsed in 1 repo~462 tokens
    Auto-check passed
  • Opportunity

    alsk1992/CloddsBot

    Find and execute cross-platform arbitrage opportunities across prediction markets

    2.9k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Questions about Credentials

What does Credentials do?

Secure credential management for trading platforms. An agent skill from alsk1992/CloddsBot. Credentials is an agent skill from alsk1992/CloddsBot.

When should I use Credentials?

Credentials fits situations like: tasks that involve Trading and backtesting.

How do I install Credentials in Claude Code?

Run `npx skills add alsk1992/CloddsBot --skill credentials -a claude-code`. Or copy the skill folder (src/skills/bundled/credentials in alsk1992/CloddsBot) into .claude/skills/credentials in your project. Claude Code loads it when a task matches its description.

How do I install Credentials in Codex?

Run `npx skills add alsk1992/CloddsBot --skill credentials -a codex`. Or copy the skill folder (src/skills/bundled/credentials in alsk1992/CloddsBot) into .agents/skills/credentials in your project. Codex loads it when a task matches its description.

Can I use Credentials in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alsk1992/CloddsBot --skill credentials -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/credentials, .gemini/skills/credentials, .github/skills/credentials and .opencode/skills/credentials in your project.

What does Credentials need to run?

Going by SKILL.md and its folder, Credentials needs TypeScript for the scripts in its folder, the command-line tools its instructions call (openssl) and credentials named CREDENTIALS_KEY, POLYMARKET_API_KEY, POLYMARKET_API_SECRET and POLYMARKET_PRIVATE_KEY. Our summary lists: Node.js; A credential in CREDENTIALS_KEY; A credential in POLYMARKET_API_KEY.

Does Credentials access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Credentials safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Credentials use?

Credentials is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Credentials use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Credentials?

Skills that share tags, products or a category with Credentials: Tushare Data (zillionare/zillionare, 318 stars), Tradingview MCP (atilaahmettaner/tradingview-mcp, 4.9k stars), Digital Oracle (komako-workshop/digital-oracle, 867 stars) and Polyclaw (chainstacklabs/polyclaw, 360 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Credentials?

alsk1992 (a GitHub user) maintains it in alsk1992/CloddsBot, which has 2,901 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 2, 2026.

Source: alsk1992/CloddsBot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.