Agent skill

Use Avibe Vault

by avibe-bot in avibe-bot/avibe

Use Avibe Vault for API keys, tokens, passwords, protected credentials, authenticated HTTP requests, or digest signing without exposing secret values to the agent.

MITAuto-check passed

Install Use Avibe Vault

skills CLI
$ npx skills add avibe-bot/avibe --skill use-avibe-vault -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install avibe-bot/avibe use-avibe-vault --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/avibe-bot/avibe.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/use-avibe-vault .claude/skills/use-avibe-vault && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
use-avibe-vault
GitHub stars
624
Token cost
~1.1k tokens
SKILL.md length
594 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Use Avibe Vault for API keys, tokens, passwords, protected credentials, authenticated HTTP requests, or digest signing without exposing secret values to the agent.

  • Reaches api.github.com; needs OPENAI_API_KEY and GITHUB_TOKEN

What it does

Use Avibe Vault is an agent skill from avibe-bot/avibe. Use Avibe Vault for API keys, tokens, passwords, protected credentials, authenticated HTTP requests, or digest signing without exposing secret values to the agent.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: The local-first Agent OS — your AI partner lives on your own machine. Drive the official Claude Code, Codex & OpenCode from your browser or any chat app. The licence is MIT.

Example prompts

  • “/use-avibe-vault”

Requirements

  • Python 3
  • A credential in OPENAI_API_KEY
  • A credential in GITHUB_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 61e315a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY
    • GITHUB_TOKEN
    • WALLET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Use Avibe Vault loads about 1.1k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 594 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from avibe-bot/avibe at commit 61e315a, republished under its MIT licence (© avibe-bot). 594 words, ~1,108 tokens.

Download SKILL.mdSave it as .claude/skills/use-avibe-vault/SKILL.md (or your agent's skills folder).
name
use-avibe-vault
description
Use Avibe Vault for API keys, tokens, passwords, protected credentials, authenticated HTTP requests, or digest signing without exposing secret values to the agent.
slug
use-avibe-vault
version
0.2.0

Use Avibe Vault

When a task needs API keys, access tokens, passwords, wallet private keys, or other sensitive credentials, prefer Avibe Vault: agents reference secrets by name, tag, or skill tag, and users do not need to paste plaintext into chat.

Core concepts:

  • Static secret: a regular secret value, such as an API key, token, database password, or deployment credential. Use it with vibe vault run for environment injection or vibe vault fetch for authenticated HTTP egress.
  • Keypair secret: a signing key for digests or transactions, such as a wallet key or deployment signer. It cannot be exported as an environment variable and cannot be used with run / fetch; use vibe vault sign.
  • Standard: for lower-risk routine automation. Agents can usually use it without interrupting the user unless it is configured to ask first.
  • Protected: for high-risk secrets, such as production databases or wallet/funds keys. Because protected secrets are end-to-end encrypted, use requires browser approval and passkey unlock.

Rules:

  • Refer to secrets only by secret name, tag, or skill tag.
  • Static secrets can be used with run / fetch; keypair secrets can only be used with vibe vault sign.
  • With vibe vault run, the child process receives static secrets as environment variables, so never run commands that may print env vars, debug config, or secret-bearing errors.
  • When protected run / fetch needs approval, Avibe automatically asks the user to decrypt and authorize access. After the user approves, Avibe resumes this session; it does not replay the command for you, so run the same run / fetch command again.
  • When protected sign needs approval, Avibe creates a browser signing request and returns immediately. Do not rerun sign; when Avibe resumes this session, follow the callback instruction to read the completed request result and continue with the returned signature.

Common commands:

Request that the user add a missing static secret. spec-json may contain only non-secret prefill metadata; the actual secret value is entered by the user in the browser: vibe vault request OPENAI_API_KEY --reason "Need OpenAI API access" --spec-json '{"kind":"static","protection":"protected","description":"OpenAI API key","tags":["openai","prod","skill:model-work"],"policy":{"allowed_hosts":["api.openai.com"],"auth":{"type":"bearer"}}}'

For a missing keypair/signing key, ask the user to create a keypair secret in the Vault UI; do not request or store private-key material as a static secret.

Show full SKILL.md (229 more words)Show less

On Avibe Web chat, a lighter manual prompt can mention the missing secret as a clickable placeholder in your reply, for example $<OPENAI_API_KEY>. The user can click it and fill the secret from Web chat. This has no reason or structured prefill metadata; use vibe vault request when those are needed.

List or find existing Vault entries: vibe vault list vibe vault list --tag prod vibe vault find --kind static --protection protected vibe vault find openai --tag prod vibe vault tags

Run a command with selected static secrets injected as environment variables: vibe vault run --env OPENAI_API_KEY,GITHUB_TOKEN -- python script.py vibe vault run --env GITHUB_TOKEN=GH_PAT --env OPENAI_API_KEY -- python script.py vibe vault run --tag deploy -- ./deploy.sh vibe vault run --skill github-release -- ./release.sh

Make an authenticated HTTP request. The credential is attached only at egress, and the agent never sees the secret: vibe vault fetch --auth GITHUB_PAT --url https://api.github.com/user

Request approval before a protected run with an existing static secret: vibe vault access PROD_DB_URL --skill deploy --command "run database migration" --egress "connect to production database"

For protected fetch, run vibe vault fetch; it creates the correct fetch approval request when needed.

Sign a 32-byte digest with a keypair secret. Standard keys may return the signature directly; protected keys create a browser approval request: vibe vault sign WALLET_KEY --digest <64-hex-digest> --scheme ecdsa-secp256k1-recoverable --command "sign deployment transaction"

For more details, run vibe vault --help.

© avibe-bot, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/use-avibe-vault of avibe-bot/avibe.

Open the folder on GitHubat commit 61e315a

Compare with similar skills

Use Avibe Vault next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Use Avibe Vault compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Use Avibe Vault this skillavibe-bot/avibe624—~1.1kAutomated safety check: PassMIT
Abusing Dpapi For Credential Accessmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: WarnApache-2.0
Azure Key VaultMicrosoftDocs/Agent-Skills776—~4.9kAutomated safety check: PassCC-BY-4.0
Protect With Passwordtransilienceai/communitytools563—~583Automated safety check: PassMIT
Performing Credential Access With Lazagnemukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.0
Obsidian Vault Maintaineropenclaw/openclaw392k1 repos~262Automated safety check: PassMIT

Similar skills

  • Abusing Dpapi For Credential Access

    mukul975/Anthropic-Cybersecurity-Skills

    Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Azure Key Vault

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Key Vault development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations &…

    776 GitHub stars~4.9k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Protect With Password

    transilienceai/communitytools

    Generate ONE strong password and apply it to each referenced file (PDF, Word, Excel, PowerPoint, or any type).

    563 GitHub stars~583 tokensUpdated 2 mo ago
    Documents & OfficeAuto-check passed
  • Performing Credential Access With Lazagne

    mukul975/Anthropic-Cybersecurity-Skills

    Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check: warnings
  • Obsidian Vault Maintainer

    openclaw/openclaw

    Maintain an Obsidian-friendly memory wiki vault with wikilinks, frontmatter, and official Obsidian CLI awareness.

    392k GitHub starsUsed in 1 repo~262 tokens
    Knowledge ManagementAuto-check passed
  • Credentials

    google-deepmind/science-skills

    Instructions for handling API keys and credentials safely, verifying their presence, and prompting the user to add them if missing using a safe protocol.

    3.2k GitHub stars~1k tokensUpdated yesterday
    Research & ScienceAuto-check: notes

More from avibe-bot/avibe

  • Use Avibe

    avibe-bot/avibe

    Safely inspect and modify local Avibe configuration, routing, runtime settings, watches, scheduled tasks, Avibe Cloud remote access, and operational state.

    624 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Agent Prompt Audit

    avibe-bot/avibe

    Audit and improve the prompt surface of Avibe Agents across backends (Claude, Codex/GPT, OpenCode) — global and project rules, Agent system prompts, Skills, delegation briefs, and Task and Watch…

    624 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • PR Delivery Loop

    avibe-bot/avibe

    Deliver implementation PRs across Avibe, avibe-backend, avibe-docs, avault, and vault-sandbox.

    624 GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • Background Watch Hook

    avibe-bot/avibe

    Use vibe watch to run a managed Harness waiter that returns to the same conversation later.

    624 GitHub stars~7.7k tokensUpdated today
    Auto-check passed
  • Use Show Pages

    avibe-bot/avibe

    Build, inspect, update, restore, or share Avibe Show Pages for visual explanations, diagrams, reports, or interactive prototypes.

    624 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Use Avibe Harness

    avibe-bot/avibe

    Use Avibe Harness for durable Agent delegation, Sessions, scheduled Tasks, Watches, Runs, queues, and work that must continue beyond the current turn.

    624 GitHub stars~3.7k tokensUpdated today
    Auto-check passed

Questions about Use Avibe Vault

What does Use Avibe Vault do?

Use Avibe Vault for API keys, tokens, passwords, protected credentials, authenticated HTTP requests, or digest signing without exposing secret values to the agent. Use Avibe Vault is an agent skill from avibe-bot/avibe. Use Avibe Vault for API keys, tokens, passwords, protected credentials, authenticated HTTP requests, or digest signing without exposing secret values to the agent.

How do I install Use Avibe Vault in Claude Code?

Run `npx skills add avibe-bot/avibe --skill use-avibe-vault -a claude-code`. Or copy the skill folder (skills/use-avibe-vault in avibe-bot/avibe) into .claude/skills/use-avibe-vault in your project. Claude Code loads it when a task matches its description.

How do I install Use Avibe Vault in Codex?

Run `npx skills add avibe-bot/avibe --skill use-avibe-vault -a codex`. Or copy the skill folder (skills/use-avibe-vault in avibe-bot/avibe) into .agents/skills/use-avibe-vault in your project. Codex loads it when a task matches its description.

Can I use Use Avibe Vault in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add avibe-bot/avibe --skill use-avibe-vault -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/use-avibe-vault, .gemini/skills/use-avibe-vault, .github/skills/use-avibe-vault and .opencode/skills/use-avibe-vault in your project.

What does Use Avibe Vault need to run?

Going by SKILL.md and its folder, Use Avibe Vault needs credentials named OPENAI_API_KEY, GITHUB_TOKEN and WALLET_KEY. Our summary lists: Python 3; A credential in OPENAI_API_KEY; A credential in GITHUB_TOKEN.

Does Use Avibe Vault access the network?

SKILL.md names 1 domain. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Use Avibe Vault safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Use Avibe Vault use?

Use Avibe Vault is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Use Avibe Vault use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Use Avibe Vault?

Skills that share tags, products or a category with Use Avibe Vault: Abusing Dpapi For Credential Access (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Azure Key Vault (MicrosoftDocs/Agent-Skills, 776 stars), Protect With Password (transilienceai/communitytools, 563 stars) and Performing Credential Access With Lazagne (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Use Avibe Vault?

avibe-bot (a GitHub organization) maintains it in avibe-bot/avibe, which has 624 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 11, 2026.

Source: avibe-bot/avibe on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.