Openclaw Secret Scanning Maintainer
openclaw/openclaw
Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
A skill your agent uses for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys…
$ npx skills add kitlangton/2password --skill 2password -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kitlangton/2password 2password --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kitlangton/2password.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/2password .claude/skills/2password && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "2password" agent skill from https://github.com/kitlangton/2password/tree/main/skills/2password into .claude/skills/2password/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "2password", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kitlangton/2password/tree/main/skills/2passwordType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kitlangton/2password --skill 2password -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kitlangton/2password 2password --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kitlangton/2password.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/2password .agents/skills/2password && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "2password" agent skill from https://github.com/kitlangton/2password/tree/main/skills/2password into .agents/skills/2password/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "2password", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kitlangton/2password --skill 2password -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kitlangton/2password 2password --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kitlangton/2password.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/2password .cursor/skills/2password && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "2password" agent skill from https://github.com/kitlangton/2password/tree/main/skills/2password into .cursor/skills/2password/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "2password", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kitlangton/2password.git --path skills/2password--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kitlangton/2password --skill 2password -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kitlangton/2password 2password --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kitlangton/2password.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/2password .gemini/skills/2password && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "2password" agent skill from https://github.com/kitlangton/2password/tree/main/skills/2password into .gemini/skills/2password/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "2password", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kitlangton/2password 2passwordInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kitlangton/2password --skill 2password -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kitlangton/2password.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/2password .github/skills/2password && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "2password" agent skill from https://github.com/kitlangton/2password/tree/main/skills/2password into .github/skills/2password/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "2password", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kitlangton/2password --skill 2password -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kitlangton/2password 2password --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kitlangton/2password.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/2password .opencode/skills/2password && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "2password" agent skill from https://github.com/kitlangton/2password/tree/main/skills/2password into .opencode/skills/2password/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "2password", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
2passwordA skill your agent uses for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys…
2password is an agent skill from kitlangton/2password. Use for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys, checking or updating login passwords, auditing vaults, and setting up unattended access. Prefer the 2password CLI over raw op whenever it covers the task.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: 1Password for coding agents: find, use, and save secrets without exposing them. The licence is MIT.
Read from SKILL.md and the folder at commit e011177. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OP_SERVICE_ACCOUNT_TOKENOPENAI_API_KEYSTRIPE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
2password loads about 1.7k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 746 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
2password env write .env.tpl "OPENAI_API_KEY=op://Personal/OpenAI API Key/credential" "STRIPE_KEY=op://Work/Stripe API K2password env run .env.tpl -- bun run dev # preferred: no plaintext on disk2password env resolve .env.tpl --output .env # only when a real file is required (mode 0600)h one prompt. Never loop over `read`. A `.env.tpl` that holds only `op://` references is safe to inspect; a resolved `.eAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kitlangton/2password at commit e011177, republished under its MIT licence (© kitlangton). 746 words, ~1,702 tokens.
.claude/skills/2password/SKILL.md (or your agent's skills folder).2password wraps the 1Password CLI (op) so you can work with secrets without seeing them, and with as few 1Password prompts as possible. All output is JSON.
op:// references around instead.find, many references in one env file run with env run.op whoami or any other preflight check. Just run the command; the desktop app authorizes it when needed.find first to check whether it already happened.2password find openai anthropic "github actions" # many queries, one prompt
2password find stripe --vault Work --account my.1password.comEach match appears once as { ref, title, kind }, with queries when you asked several. A query that matches nothing returns suggestions with close titles (typos included) from the same lookup. Use those rather than searching again or listing whole vaults. It never returns values.
2password run --env "OPENAI_API_KEY=op://Personal/OpenAI API Key/credential" -- bun run dev
2password env write .env.tpl "OPENAI_API_KEY=op://Personal/OpenAI API Key/credential" "STRIPE_KEY=op://Work/Stripe API Key/credential"
2password env run .env.tpl -- bun run dev # preferred: no plaintext on disk
2password env resolve .env.tpl --output .env # only when a real file is required (mode 0600)
2password read "op://Personal/OpenAI API Key/credential" # last resort: prints the valueAll references in a template resolve with one prompt. Never loop over read. A .env.tpl that holds only op:// references is safe to inspect; a resolved .env is plaintext.
run and env run keep the secret out of argv, the template, and 2password's own output, but the selected child process receives plaintext in its environment. Treat that child as a trusted secret consumer: do not inject credentials into environment-dump/debug commands or helpers whose purpose is to reveal the value.
2password create api-credential --title "OpenAI API Key" --vault Personal --clipboard
some-command-that-prints-a-key | 2password create api-credential --title "OpenAI API Key" --vault Personal --stdin--vault is required. Use the vault the user names, or their documented default; ask if neither exists.--url, --notes, and --account take non-secret metadata only."verified": true. Reuse the returned ref; don't read it to double-check.2password password "Example Airline" --vault Personal --clipboard # compare only
2password password "Example Airline" --vault Personal --clipboard --apply # update, then verifyThe command refuses logins that have passkeys or unnamed imported fields. Use --repair-imported-fields only after the user approves it.
2password inventory --vault Work # item and field metadata, never values or URL query strings
2password audit --vault Personal # duplicate titles, untagged machine credentials, old logins, transient URLsTreat findings as candidates for review. Propose renames or changes, and only make them after the user approves.
If the user is tired of approval prompts, suggest a service account. Only set one up when the user asks.
2password service-account setup --vault Automation --create-vault --write --save-vault PersonalAfter setup, every command authenticates silently with a token stored in macOS Keychain (on Windows, a DPAPI-encrypted file under %LOCALAPPDATA%), but it can only reach the Automation vault. On Windows, any process running as the user can decrypt that file, so the vault's narrow scope is the real boundary. Keep the credentials agents use in that vault.
2password --desktop <command> uses the normal desktop login, for example to reach other vaults.service-account status | connect --clipboard | recover | forget. forget removes only this Mac's copy; it doesn't revoke the account.2password service-account status.OP_SERVICE_ACCOUNT_TOKEN in the environment overrides the saved account (Linux, CI).run and env run remove the service-account token from the child process's environment.credential field, and a title like <Provider> API Key or <Provider> <Purpose> API Key.password field and a title like <Provider> or <Provider> <Account>.2password is built for agents, so your experience is how it improves. Speak up if a command fails unexpectedly or you had to work around it. The same goes for more approval prompts than expected, output that's awkward or too verbose, or anything in this skill that's unclear or wrong. Tell the user, and offer to open an issue. It posts publicly from their GitHub account, so get their okay first.
gh issue list --repo kitlangton/2password --state all --search "<keywords>" # add to an existing issue instead of duplicating it
gh issue create --repo kitlangton/2password --title "<what went wrong>" --body "<details>"Include the output of 2password doctor (versions and setup; it never prompts and is safe to share), the command you ran, and what you expected versus what happened. Never include secret values, item titles, vault or account names, or op:// references. Replace them with placeholders.
Use raw op for other item categories, editing, moving, sharing, deleting, and vault management. Pass plaintext through JSON templates on stdin, never in arguments. After discovery, refer to items and vaults by ID.
© kitlangton, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/2password of kitlangton/2password.
Open the folder on GitHubat commit e011177
2password next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| 2password this skillkitlangton/2password | 276 | — | ~1.7k | Automated safety check: Notes | MIT | |
| Openclaw Secret Scanning Maintaineropenclaw/openclaw | 392k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Secret Scanninggithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Leaked Secretsthedaviddias/Front-End-Checklist | 74k | — | ~596 | Automated safety check: Notes | MIT | |
| Secrets Managementdavila7/claude-code-templates | 32k | 12 repos | ~2k | Automated safety check: Pass | MIT | |
| Implementing Hashicorp Vault Dynamic Secretsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~5.2k | Automated safety check: Pass | Apache-2.0 |
openclaw/openclaw
Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
github/awesome-copilot
Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.
davila7/claude-code-templates
Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.
mukul975/Anthropic-Cybersecurity-Skills
Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets…
alirezarezvani/claude-skills
A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…
A skill your agent uses for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys…. 2password is an agent skill from kitlangton/2password. Use for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys, checking or updating login passwords, auditing vaults, and setting up unattended access.
2password fits situations like: including finding credentials; injecting them into commands; saving new API keys; updating login passwords.
Run `npx skills add kitlangton/2password --skill 2password -a claude-code`. Or copy the skill folder (skills/2password in kitlangton/2password) into .claude/skills/2password in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kitlangton/2password --skill 2password -a codex`. Or copy the skill folder (skills/2password in kitlangton/2password) into .agents/skills/2password in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kitlangton/2password --skill 2password -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/2password, .gemini/skills/2password, .github/skills/2password and .opencode/skills/2password in your project.
Going by SKILL.md and its folder, 2password needs the command-line tools its instructions call (gh) and credentials named OP_SERVICE_ACCOUNT_TOKEN, OPENAI_API_KEY and STRIPE_KEY. Our summary lists: A credential in OPENAI_API_KEY; A credential in STRIPE_KEY.
SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
2password is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with 2password: Openclaw Secret Scanning Maintainer (openclaw/openclaw, 392k stars), Secret Scanning (github/awesome-copilot, 40k stars), Leaked Secrets (thedaviddias/Front-End-Checklist, 74k stars) and Secrets Management (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kitlangton (a GitHub user) maintains it in kitlangton/2password, which has 276 GitHub stars. The repository was last updated on October 4, 2026.
Source: kitlangton/2password on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.