Agent skill

C Secrets

by daxaur in daxaur/openpaw

Look up and manage secrets using 1Password CLI (op) or Bitwarden CLI (bw).

MITAuto-check passed

Install C Secrets

skills CLI
$ npx skills add daxaur/openpaw --skill c-secrets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install daxaur/openpaw c-secrets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/daxaur/openpaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/c-secrets .claude/skills/c-secrets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
c-secrets
GitHub stars
174
Token cost
~501 tokens
SKILL.md length
149 words
Files
1
Skills in repo
42
Repo updated
First seen
Licence
MIT

At a glance

Look up and manage secrets using 1Password CLI (op) or Bitwarden CLI (bw).

  • Works in 4 steps: Always pipe passwords to pbcopy —… → If the user asks to "show" or "display"… → For lookups, show non-sensitive fields… → …
  • SKILL.md covers What This Skill Does, CRITICAL RULE, CLI Tools and Usage Guidelines, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

C Secrets is an agent skill from daxaur/openpaw. Look up and manage secrets using 1Password CLI (op) or Bitwarden CLI (bw). Retrieve passwords, generate new passwords, and copy credentials to clipboard. CRITICAL: Never display passwords in plain text — always copy to clipboard.

Its SKILL.md is about 500 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Personal Assistant Wizard for Claude Code — npx pawmode. The licence is MIT.

Example prompts

  • “/c-secrets”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Always pipe passwords to pbcopy — confirm "Copied to clipboard" to the user instead of showing the value.
  2. If the user asks to "show" or "display" a password, redirect: copy it to clipboard and inform them.
  3. For lookups, show non-sensitive fields (username, URL, notes) but never the password itself.
  4. If vault is locked, prompt the user to unlock it manually before proceeding.

What it can do on your machine

Read from SKILL.md and the folder at commit a2562d1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

C Secrets loads about 501 tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 149 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~501

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from daxaur/openpaw at commit a2562d1, republished under its MIT licence (© daxaur). 149 words, ~501 tokens.

Download SKILL.mdSave it as .claude/skills/c-secrets/SKILL.md (or your agent's skills folder).
name
c-secrets
description
Look up and manage secrets using 1Password CLI (`op`) or Bitwarden CLI (`bw`). Retrieve passwords, generate new passwords, and copy credentials to clipboard. CRITICAL: Never display passwords in plain text — always copy to clipboard.
tags
[passwords, secrets, 1password, bitwarden, credentials, security]

What This Skill Does

Retrieves credentials and generates passwords using op (1Password CLI) or bw (Bitwarden CLI). All passwords are copied to clipboard — never printed to the terminal.

CRITICAL RULE

NEVER display passwords, tokens, or secret values in plain text output. Always use clipboard copy commands. This applies to every secret retrieval, no exceptions.

CLI Tools

1Password (op)
bash
# Copy a password to clipboard (PREFERRED — never print)
op item get "GitHub" --fields password | pbcopy

# Look up an item
op item get "GitHub"

# List all items
op item list

# Generate a password (copy to clipboard)
op generate-password --length 20 --symbols | pbcopy

# Get a specific field
op item get "AWS" --fields "Access Key ID"
Bitwarden (bw)
bash
# Unlock vault first (session token required)
export BW_SESSION=$(bw unlock --raw)

# Copy password to clipboard (PREFERRED)
bw get password "GitHub" | pbcopy

# Look up an item
bw get item "GitHub"

# Generate a password (copy to clipboard)
bw generate --length 20 --special | pbcopy

Usage Guidelines

  1. Always pipe passwords to pbcopy — confirm "Copied to clipboard" to the user instead of showing the value.
  2. If the user asks to "show" or "display" a password, redirect: copy it to clipboard and inform them.
  3. For lookups, show non-sensitive fields (username, URL, notes) but never the password itself.
  4. If vault is locked, prompt the user to unlock it manually before proceeding.

Notes

  • op requires 1Password app installed and CLI signed in: op signin
  • bw requires Bitwarden CLI installed and vault unlocked each session

© daxaur, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/c-secrets of daxaur/openpaw.

Open the folder on GitHubat commit a2562d1

Compare with similar skills

C Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

C Secrets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
C Secrets this skilldaxaur/openpaw174—~501Automated safety check: PassMIT
Openclaw Secret Scanning Maintaineropenclaw/openclaw392k—~2.5kAutomated safety check: PassMIT
Secret Scanninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Secrets Managementdavila7/claude-code-templates32k12 repos~2kAutomated safety check: PassMIT
Secrets Vault Manageralirezarezvani/claude-skills28k1 repos~3.6kAutomated safety check: NotesMIT
Dotenvx Secretskortix-ai/suna20k—~4.2kAutomated safety check: NotesCustom licence

Similar skills

  • Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.

    392k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Secret Scanning

    github/awesome-copilot

    Official

    Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    32k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Secrets Vault Manager

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…

    28k GitHub starsUsed in 1 repo~3.6k tokens
    DevOps & CloudAuto-check: notes
  • Dotenvx Secrets

    kortix-ai/suna

    How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).

    20k GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Leaked Secrets

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

    74k GitHub stars~596 tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from daxaur/openpaw

All 42 skills in this repo
  • C Lockin

    daxaur/openpaw

    Lock In Mode — orchestrate distraction blocking, environment setup, and session tracking.

    174 GitHub starsUsed in 1 repo~547 tokens
    Auto-check passed
  • C Notes

    daxaur/openpaw

    Manage Apple Notes and Apple Reminders from the CLI. An agent skill from daxaur/openpaw.

    174 GitHub starsUsed in 1 repo~450 tokens
    Auto-check passed
  • C Briefing

    daxaur/openpaw

    Daily briefing — morning summary of email, calendar, tasks, weather.

    174 GitHub stars~559 tokensUpdated 4 mo ago
    Auto-check passed
  • C Calendar

    daxaur/openpaw

    View and create calendar events via gog (Google Calendar) or icalBuddy (Apple Calendar).

    174 GitHub stars~566 tokensUpdated 4 mo ago
    Auto-check passed
  • C Contacts

    daxaur/openpaw

    macOS Contacts — search, list, and look up contact details via AppleScript.

    174 GitHub stars~466 tokensUpdated 4 mo ago
    Auto-check passed
  • C Email

    daxaur/openpaw

    Read, send, search, and label email via gog (Gmail CLI) or himalaya (IMAP).

    174 GitHub stars~547 tokensUpdated 4 mo ago
    Auto-check passed

Questions about C Secrets

What does C Secrets do?

Look up and manage secrets using 1Password CLI (op) or Bitwarden CLI (bw). C Secrets is an agent skill from daxaur/openpaw. Look up and manage secrets using 1Password CLI (op) or Bitwarden CLI (bw).

How do I install C Secrets in Claude Code?

Run `npx skills add daxaur/openpaw --skill c-secrets -a claude-code`. Or copy the skill folder (skills/c-secrets in daxaur/openpaw) into .claude/skills/c-secrets in your project. Claude Code loads it when a task matches its description.

How do I install C Secrets in Codex?

Run `npx skills add daxaur/openpaw --skill c-secrets -a codex`. Or copy the skill folder (skills/c-secrets in daxaur/openpaw) into .agents/skills/c-secrets in your project. Codex loads it when a task matches its description.

Can I use C Secrets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add daxaur/openpaw --skill c-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/c-secrets, .gemini/skills/c-secrets, .github/skills/c-secrets and .opencode/skills/c-secrets in your project.

What does C Secrets need to run?

SKILL.md names no scripts, command-line tools or credentials: C Secrets is instructions for the agent only.

Does C Secrets access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is C Secrets safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does C Secrets use?

C Secrets is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does C Secrets use?

About 501 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to C Secrets?

Skills that share tags, products or a category with C Secrets: Openclaw Secret Scanning Maintainer (openclaw/openclaw, 392k stars), Secret Scanning (github/awesome-copilot, 40k stars), Secrets Management (davila7/claude-code-templates, 32k stars) and Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains C Secrets?

daxaur (a GitHub user) maintains it in daxaur/openpaw, which has 174 GitHub stars. The repository holds 42 skills in this directory. The repository was last updated on May 23, 2026.

Source: daxaur/openpaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.