Credential Manager
LeoYeAI/openclaw-master-skills
MANDATORY security foundation for OpenClaw. An agent skill from LeoYeAI/openclaw-master-skills.
Read this before any login, signup, password change, or checkout so the right credential source is used in the right order without ever exposing a secret.
$ npx skills add BetterWright/betterwright --skill credential-manager -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install BetterWright/betterwright credential-manager --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/BetterWright/betterwright.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/credential-manager .claude/skills/credential-manager && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "credential-manager" agent skill from https://github.com/BetterWright/betterwright/tree/main/skills/credential-manager into .claude/skills/credential-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "credential-manager", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/BetterWright/betterwright/tree/main/skills/credential-managerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add BetterWright/betterwright --skill credential-manager -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install BetterWright/betterwright credential-manager --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BetterWright/betterwright.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/credential-manager .agents/skills/credential-manager && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "credential-manager" agent skill from https://github.com/BetterWright/betterwright/tree/main/skills/credential-manager into .agents/skills/credential-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "credential-manager", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BetterWright/betterwright --skill credential-manager -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install BetterWright/betterwright credential-manager --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BetterWright/betterwright.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/credential-manager .cursor/skills/credential-manager && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "credential-manager" agent skill from https://github.com/BetterWright/betterwright/tree/main/skills/credential-manager into .cursor/skills/credential-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "credential-manager", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/BetterWright/betterwright.git --path skills/credential-manager--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add BetterWright/betterwright --skill credential-manager -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install BetterWright/betterwright credential-manager --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BetterWright/betterwright.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/credential-manager .gemini/skills/credential-manager && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "credential-manager" agent skill from https://github.com/BetterWright/betterwright/tree/main/skills/credential-manager into .gemini/skills/credential-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "credential-manager", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install BetterWright/betterwright credential-managerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add BetterWright/betterwright --skill credential-manager -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/BetterWright/betterwright.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/credential-manager .github/skills/credential-manager && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "credential-manager" agent skill from https://github.com/BetterWright/betterwright/tree/main/skills/credential-manager into .github/skills/credential-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "credential-manager", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BetterWright/betterwright --skill credential-manager -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install BetterWright/betterwright credential-manager --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BetterWright/betterwright.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/credential-manager .opencode/skills/credential-manager && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "credential-manager" agent skill from https://github.com/BetterWright/betterwright/tree/main/skills/credential-manager into .opencode/skills/credential-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "credential-manager", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
credential-managerRead this before any login, signup, password change, or checkout so the right credential source is used in the right order without ever exposing a secret.
Credential Manager is an agent skill from BetterWright/betterwright. Read this before any login, signup, password change, or checkout so the right credential source is used in the right order without ever exposing a secret.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: A persistent, policy-guarded Playwright browser for AI agents — network policy, encrypted credential vault, proof screenshots, and CAPTCHA solving. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ec55a32. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Credential Manager loads about 1.1k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 547 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from BetterWright/betterwright at commit ec55a32, republished under its MIT licence (© BetterWright). 547 words, ~1,096 tokens.
.claude/skills/credential-manager/SKILL.md (or your agent's skills folder).Use metadata to choose an account, then let the password manager detect and fill the form. Never fetch, inspect, transform, or print a stored secret.
Work down this ladder; stop at the first source that works.
../1password/SKILL.md, ../bitwarden/SKILL.md).credentials.list() returns matching
metadata only: id, username, label, category, saved URL, and match mode.
Filter with credentials.list({text, category}). If one account clearly
fits the task, call credentials.fill({id, submit: true}). BetterWright
detects the visible form and resolves/types the secret internally. MCP/Pi's
browser_login and the SDK's fillCredential use the same path.human.click and
re-snapshot; a session may already exist, an SSO button may be present, or
the user's own password manager may surface.credentials.fill({id, submit: true});
password-only pages are detected.usernameSelector, passwordSelector,
currentPasswordSelector, confirmPasswordSelector, or submitSelector
from a fresh snapshot. For an ambiguous rotation, pin current, new, and
confirmation password roles together. Do not guess selectors before
detection fails.credentials.generateAndFill({username, submit: true}). Generation
returns only an opaque pending id; the encrypted provisional entry is not an
active saved login yet.credentials.commitGenerated({pendingId}). On rejection or
abandonment, call credentials.discardGenerated({pendingId}).If generation fails but returns pendingCredential, do not generate again.
Inspect the visible site outcome, then commit or discard that exact recovery id.
After a complete host restart with no returned id, revisit the signup site and
call credentials.listPending(). Use its secret-free username, label, and
timestamps to identify the attempt; never guess or auto-pick among several.
For rotation, pass the existing credential id to generateAndFill. Commit
only after the site confirms the change; commit updates that item instead of
creating a duplicate. Rotation preserves its URL scope, so update matchMode
separately before rotating when needed. Choose an existing username/email when
the site allows it; never invent an address.
credentials.list() means no enabled item matches this site under
its URL policy. Fall through the ladder instead of searching unrelated
credentials.inputValue(), input.value, evaluate, console, or network probes on
secret fields.© BetterWright, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/credential-manager of BetterWright/betterwright.
Open the folder on GitHubat commit ec55a32
Credential Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Credential Manager this skillBetterWright/betterwright | 329 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Credential ManagerLeoYeAI/openclaw-master-skills | 2.2k | — | ~5.8k | Automated safety check: Notes | MIT | |
| Secrets Managementdavila7/claude-code-templates | 32k | 11 repos | ~2k | Automated safety check: Pass | MIT | |
| Project ManagerRightNow-AI/openfang | 18k | — | ~960 | Automated safety check: Pass | Apache-2.0 | |
| Hunting Credential Stuffing Attacksmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~732 | Automated safety check: Pass | Apache-2.0 | |
| Abusing Dpapi For Credential Accessmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.7k | Automated safety check: Warn | Apache-2.0 |
LeoYeAI/openclaw-master-skills
MANDATORY security foundation for OpenClaw. An agent skill from LeoYeAI/openclaw-master-skills.
davila7/claude-code-templates
Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.
RightNow-AI/openfang
Project management expert for Agile, estimation, risk management, and stakeholder communication
mukul975/Anthropic-Cybersecurity-Skills
Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins.
mukul975/Anthropic-Cybersecurity-Skills
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or…
github/awesome-copilot
Workflow for building and modifying content management systems across WordPress, Shopify, Wix, Squarespace, Drupal, WooCommerce, Joomla, HubSpot CMS Hub, Webflow, Adobe Experience Manager, and…
BetterWright/betterwright
Drive a persistent, policy-guarded real web browser via the betterwright CLI.
BetterWright/betterwright
Run a rigorous end-to-end product or feature review across architecture, data, APIs, permissions, billing, tests, and real browser UX.
BetterWright/betterwright
Read this when the browser profile has the 1Password extension and a login, signup, or payment form should be filled with it.
BetterWright/betterwright
Diagnose browser console errors and uncaught JavaScript exceptions without dumping routine logs.
BetterWright/betterwright
Read this when the browser profile has the Bitwarden extension and a login, signup, or payment form should be filled with it.
BetterWright/betterwright
GitHub navigation, review, and account-context guidance for working repos, issues, and pull requests in the browser.
Read this before any login, signup, password change, or checkout so the right credential source is used in the right order without ever exposing a secret. Credential Manager is an agent skill from BetterWright/betterwright. Read this before any login, signup, password change, or checkout so the right credential source is used in the right order without ever exposing a secret.
Run `npx skills add BetterWright/betterwright --skill credential-manager -a claude-code`. Or copy the skill folder (skills/credential-manager in BetterWright/betterwright) into .claude/skills/credential-manager in your project. Claude Code loads it when a task matches its description.
Run `npx skills add BetterWright/betterwright --skill credential-manager -a codex`. Or copy the skill folder (skills/credential-manager in BetterWright/betterwright) into .agents/skills/credential-manager in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BetterWright/betterwright --skill credential-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/credential-manager, .gemini/skills/credential-manager, .github/skills/credential-manager and .opencode/skills/credential-manager in your project.
SKILL.md names no scripts, command-line tools or credentials: Credential Manager is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Credential Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Credential Manager: Credential Manager (LeoYeAI/openclaw-master-skills, 2.2k stars), Secrets Management (davila7/claude-code-templates, 32k stars), Project Manager (RightNow-AI/openfang, 18k stars) and Hunting Credential Stuffing Attacks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
BetterWright (a GitHub organization) maintains it in BetterWright/betterwright, which has 329 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on September 29, 2026.
Source: BetterWright/betterwright on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.