Agent skill

Keypo Signer

by keypo-us in keypo-us/keypo-cli

A skill your agent uses when managing Secure Enclave signing keys or encrypted secrets.

No licenceAuto-check: notesBackend & APIs

Install Keypo Signer

skills CLI
$ npx skills add keypo-us/keypo-cli --skill keypo-signer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install keypo-us/keypo-cli keypo-signer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/keypo-us/keypo-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/keypo-signer .claude/skills/keypo-signer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
keypo-signer
GitHub stars
182
Token cost
~3.6k tokens
SKILL.md length
1,352 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
None found

At a glance

A skill your agent uses when managing Secure Enclave signing keys or encrypted secrets.

  • Works in 3 steps: Human creates a session (one-time,… → Agent uses the session (repeated,… → Session expires automatically after TTL…
  • Managing Secure Enclave signing keys
  • SKILL.md covers CLI Usage Rule, Running Commands with Secrets…, Sessions (Unattended Agent… and Storing Secrets, plus 1 more section
  • Calls vault, sh and brew; needs API_KEY and PIMLICO_API_KEY

What it does

Keypo Signer is an agent skill from keypo-us/keypo-cli. Use when managing Secure Enclave signing keys or encrypted secrets. Use for creating/listing/deleting P-256 keys, signing digests, running commands with secrets injected via vault exec, storing/retrieving encrypted secrets. Also use when an agent needs API keys, private keys, or credentials injected into a subprocess without exposing them. Use vault sessions for unattended agent workflows that need repeated access to protected secrets.

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. The repository describes itself as: Local-first, hardware-bound key management and encrypted secrets for AI agents.

When your agent uses it

  • Managing Secure Enclave signing keys
  • Encrypted secrets
  • Creating/listing/deleting P-256 keys
  • Signing digests

Example prompts

  • “/keypo-signer”

Requirements

  • Python 3
  • A credential in PIMLICO_API_KEY
  • A credential in DEPLOYER_PRIVATE_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Human creates a session (one-time, interactive)
  2. Agent uses the session (repeated, unattended)
  3. Session expires automatically after TTL or usage limit.

What it can do on your machine

Read from SKILL.md and the folder at commit 7331b6f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • vault
    • sh
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • PIMLICO_API_KEY
    • DEPLOYER_PRIVATE_KEY
    • DB_PASSWORD
    • EXTRA_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Keypo Signer loads about 3.6k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 1,352 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:239
    ### Bulk import from .env file
  • NoteMentions a .env fileSKILL.md:242
    keypo-signer vault import .env --vault passcode
  • NoteMentions a .env fileSKILL.md:408
    | `vault import` | Bulk import from .env file | Yes (target vault's policy) |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,352 words (~3,608 tokens).

“A CLI for hardware-bound P-256 key management and encrypted secret storage using the Apple Secure Enclave. Keys never leave the hardware. Secrets are encrypted at rest and decrypted only into child process environments.”

— opening of SKILL.md by keypo-us
name
keypo-signer
version
0.4.7
metadata.author
keypo-us
metadata.compatibility
macOS Apple Silicon only

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/keypo-signer of keypo-us/keypo-cli.

Open the folder on GitHubat commit 7331b6f

Compare with similar skills

Keypo Signer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Keypo Signer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Keypo Signer this skillkeypo-us/keypo-cli182—~3.6kAutomated safety check: NotesNone
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from keypo-us/keypo-cli

  • Checkout Purchase

    keypo-us/keypo-cli

    A skill your agent uses when the user asks to buy a product from the Shopify store.

    182 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check: notes
  • Keypo Shopping

    keypo-us/keypo-cli

    MUST LOAD for any shopping, buying, gift, or product request.

    182 GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Keypo Wallet

    keypo-us/keypo-cli

    A skill your agent uses when interacting with keypo-wallet — checking wallet balances, listing wallets, sending transactions, or managing Secure Enclave signing keys.

    182 GitHub stars~2.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Portfolio Tracker

    keypo-us/keypo-cli

    A skill your agent uses when the user asks about token balances, what tokens a wallet holds, or wants a complete portfolio overview including ERC-20 tokens.

    182 GitHub stars~2.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Uniswap V3 Swap

    keypo-us/keypo-cli

    A skill your agent uses when the user wants to swap tokens on Base Sepolia (or Base mainnet) using Uniswap V3.

    182 GitHub stars~3.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Weth Base Sepolia

    keypo-us/keypo-cli

    Interact with Wrapped Ether (WETH) at 0x4200000000000000000000000000000000000006 on Base Sepolia.

    182 GitHub stars~1.5k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Keypo Signer

What does Keypo Signer do?

A skill your agent uses when managing Secure Enclave signing keys or encrypted secrets. Keypo Signer is an agent skill from keypo-us/keypo-cli. Use when managing Secure Enclave signing keys or encrypted secrets.

When should I use Keypo Signer?

Keypo Signer fits situations like: managing Secure Enclave signing keys; encrypted secrets; creating/listing/deleting P-256 keys; signing digests.

How do I install Keypo Signer in Claude Code?

Run `npx skills add keypo-us/keypo-cli --skill keypo-signer -a claude-code`. Or copy the skill folder (skills/keypo-signer in keypo-us/keypo-cli) into .claude/skills/keypo-signer in your project. Claude Code loads it when a task matches its description.

How do I install Keypo Signer in Codex?

Run `npx skills add keypo-us/keypo-cli --skill keypo-signer -a codex`. Or copy the skill folder (skills/keypo-signer in keypo-us/keypo-cli) into .agents/skills/keypo-signer in your project. Codex loads it when a task matches its description.

Can I use Keypo Signer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add keypo-us/keypo-cli --skill keypo-signer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/keypo-signer, .gemini/skills/keypo-signer, .github/skills/keypo-signer and .opencode/skills/keypo-signer in your project.

What does Keypo Signer need to run?

Going by SKILL.md and its folder, Keypo Signer needs the command-line tools its instructions call (vault, sh and brew) and credentials named API_KEY, PIMLICO_API_KEY, DEPLOYER_PRIVATE_KEY and DB_PASSWORD. Our summary lists: Python 3; A credential in PIMLICO_API_KEY; A credential in DEPLOYER_PRIVATE_KEY.

Does Keypo Signer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Keypo Signer safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Keypo Signer use?

No licence was found for Keypo Signer or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Keypo Signer use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Keypo Signer?

Skills that share tags, products or a category with Keypo Signer: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Keypo Signer?

keypo-us (a GitHub organization) maintains it in keypo-us/keypo-cli, which has 182 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on April 2, 2026.

Source: keypo-us/keypo-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.