Agent skill

Credential Manager

by LeoYeAI in LeoYeAI/openclaw-master-skills

MANDATORY security foundation for OpenClaw. An agent skill from LeoYeAI/openclaw-master-skills.

MITAuto-check: notesDevOps & Cloud

Install Credential Manager

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill credential-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills credential-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/openclaw-credential-manager .claude/skills/credential-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
credential-manager
GitHub stars
2.2k
Token cost
~5.8k tokens
SKILL.md length
1,295 words
Files
16 (incl. scripts, references)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

MANDATORY security foundation for OpenClaw. An agent skill from LeoYeAI/openclaw-master-skills.

  • Works in 8 steps: Scan for Scattered Credentials → Consolidate into .env → Validate → …
  • Setting up OpenClaw
  • SKILL.md covers ⚠️ This Is Not Optional, The Foundation, What This Skill Does and Detection Parameters, plus 8 more sections
  • Runs Python and Shell scripts from its folder; calls jq, python3 and bash; needs MAIN_WALLET_PRIVATE_KEY and FARCASTER_CUSTODY_PRIVATE_KEY

What it does

Credential Manager is an agent skill from LeoYeAI/openclaw-master-skills. MANDATORY security foundation for OpenClaw. Consolidate scattered API keys and credentials into a secure .env file with proper permissions. Includes GPG encryption for high-value secrets, credential rotation tracking, deep scanning, and backup hardening. Use when setting up OpenClaw, migrating credentials, auditing security, or enforcing the .env standard. This is not optional — centralized credential management is a core requirement for secure OpenClaw deployments.

Its SKILL.md is about 5.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including scripts and reference files (for example `CHANGELOG.md`, `CONSOLIDATION-RULE.md` and `CORE-PRINCIPLE.md`).

It sits in DevOps & Cloud, covering Deployment. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • Setting up OpenClaw
  • Migrating credentials
  • Auditing security
  • Enforcing the .env standard

Example prompts

  • “/credential-manager”

Requirements

  • Python 3
  • A Bash shell
  • A credential in MAIN_WALLET_PRIVATE_KEY
  • A credential in CUSTODY_PRIVATE_KEY

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Scan for Scattered Credentials
  2. Consolidate into .env
  3. Validate
  4. Setup GPG and Encrypt Private Keys
  5. Initialize Rotation Tracking
  6. Cleanup Old Credential Files
  7. Update Scripts That Referenced Old Files
  8. Final Validation

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 8 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • jq
    • python3
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • MAIN_WALLET_PRIVATE_KEY
    • FARCASTER_CUSTODY_PRIVATE_KEY
    • API_KEY
    • PRIVATE_KEY
    • CUSTODY_PRIVATE_KEY
    • MOLTBOOK_API_KEY
    • SERVICE_API_KEY
    • ENV_KEY
    • WALLET_KEY
    • FARCASTER_SIGNER_PRIVATE_KEY
    • FARCASTER_LEGACY_CUSTODY_PRIVATE_KEY
    • FARCASTER_LEGACY_SIGNER_PRIVATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Credential Manager loads about 5.8k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 1,295 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~122
When it runs · the whole SKILL.md, loaded when a task matches
~5.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    d API keys and credentials into a secure .env file with proper permissions. Includes GPG encryption for high-value secre
  • NoteMentions a .env fileSKILL.md:10
    credentials into a secure, centralized `.env` file.
  • NoteMentions a .env fileSKILL.md:14
    Centralized `.env` credential management is a **core requirement** for OpenClaw security. If your credentials are scatte
  • NoteMentions a .env fileSKILL.md:16
    All credentials MUST be in `~/.openclaw/.env` ONLY. No workspace, no skills, no scripts directories.
  • NoteMentions a .env fileSKILL.md:26
    ~/.openclaw/.env (mode 600)
  • NoteMentions a .env fileSKILL.md:44
    3. **Consolidates** into `~/.openclaw/.env`
  • NoteMentions a .env fileSKILL.md:63
    - `~/.openclaw/workspace/.env` — Workspace env files
  • NoteMentions a .env fileSKILL.md:64
    - `~/.openclaw/workspace/*/.env` — Subdirectory env files
  • NoteMentions a .env fileSKILL.md:65
    - `~/.openclaw/workspace/skills/*/.env` — Skill env files
  • NoteMentions a .env fileSKILL.md:89
    - Symlink detection (validates symlinked .env targets)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,295 words, ~5,846 tokens.

Download SKILL.mdSave it as .claude/skills/credential-manager/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.
name
credential-manager
description
MANDATORY security foundation for OpenClaw. Consolidate scattered API keys and credentials into a secure .env file with proper permissions. Includes GPG encryption for high-value secrets, credential rotation tracking, deep scanning, and backup hardening. Use when setting up OpenClaw, migrating credentials, auditing security, or enforcing the .env standard. This is not optional — centralized credential management is a core requirement for secure OpenClaw deployments.

Credential Manager

STATUS: MANDATORY SECURITY FOUNDATION

Consolidate scattered API keys and credentials into a secure, centralized .env file.

⚠️ This Is Not Optional

Centralized .env credential management is a core requirement for OpenClaw security. If your credentials are scattered across multiple files, stop and consolidate them now.

THE RULE: All credentials MUST be in ~/.openclaw/.env ONLY. No workspace, no skills, no scripts directories.

See:

The Foundation

Every OpenClaw deployment MUST have:

~/.openclaw/.env (mode 600)

This is your single source of truth for all credentials. No exceptions.

Why?

  • Single location = easier to secure
  • File mode 600 = only you can read
  • Git-ignored = won't accidentally commit
  • Validated format = catches errors
  • Audit trail = know what changed

Scattered credentials = scattered attack surface. This skill fixes that.

What This Skill Does

  1. Scans for credentials in common locations (including deep scan for hardcoded secrets)
  2. Backs up existing credential files (timestamped, mode 600)
  3. Consolidates into ~/.openclaw/.env
  4. Secures with proper permissions (600 files, 700 directories)
  5. Validates security, format, and entropy
  6. Encrypts high-value secrets with GPG (wallet keys, private keys, mnemonics)
  7. Tracks credential rotation schedules
  8. Enforces best practices via fail-fast checks
  9. Cleans up old files after migration

Detection Parameters

The skill automatically detects credentials by scanning for:

File Patterns:

  • ~/.config/*/credentials.json — Service config directories
  • ~/.config/*/*.credentials.json — Nested credential files
  • ~/.openclaw/*.json — Credential files in OpenClaw root
  • ~/.openclaw/*-credentials* — Named credential files (e.g., farcaster-credentials.json)
  • ~/.openclaw/workspace/memory/*-creds.json — Memory credential files
  • ~/.openclaw/workspace/memory/*credentials*.json — Memory credential files
  • ~/.openclaw/workspace/.env — Workspace env files
  • ~/.openclaw/workspace/*/.env — Subdirectory env files
  • ~/.openclaw/workspace/skills/*/.env — Skill env files
  • ~/.local/share/*/credentials.json — Local share directories

Sensitive Key Patterns:

  • API keys, access tokens, bearer tokens
  • Secrets, passwords, passphrases
  • OAuth consumer keys
  • Private keys, signing keys, wallet keys
  • Mnemonics and seed phrases

Deep Scan (--deep flag):

  • Greps .sh, .js, .py, .mjs, .ts files for hardcoded secrets
  • Detects high-entropy strings matching common key prefixes (sk_, pk_, Bearer, 0x + 64 hex)
  • Excludes node_modules/, .git/
  • Reports file, line number, and key pattern matched

Security Checks:

  • File permissions (must be 600 for files, 700 for directories)
  • Backup permissions (must be 600 for backup files, 700 for backup dirs)
  • Git-ignore protection
  • Format validation (allows quoted values with spaces)
  • Entropy analysis (flags suspiciously low-entropy secrets)
  • Private key detection (flags 0x + 64 hex char values)
  • Mnemonic detection (flags 12/24 word values)
  • Symlink detection (validates symlinked .env targets)

Quick Start

bash
# Scan for credentials
./scripts/scan.py

# Deep scan (includes hardcoded secrets in scripts)
./scripts/scan.py --deep

# Review and consolidate
./scripts/consolidate.py

# Validate security
./scripts/validate.py

# Encrypt high-value secrets
./scripts/encrypt.py --keys MAIN_WALLET_PRIVATE_KEY,CUSTODY_PRIVATE_KEY

# Check rotation status
./scripts/rotation-check.py
Individual Operations
bash
# Scan only
./scripts/scan.py

# Consolidate specific service
./scripts/consolidate.py --service x

# Backup without removing
./scripts/consolidate.py --backup-only

# Clean up old files
./scripts/cleanup.py --confirm

Common Credential Locations

The skill scans these locations:

~/.config/*/credentials.json
~/.openclaw/*.json
~/.openclaw/*-credentials*
~/.openclaw/workspace/memory/*-creds.json
~/.openclaw/workspace/memory/*credentials*.json
~/.openclaw/workspace/*/.env
~/.openclaw/workspace/skills/*/.env
~/.env (if exists, merges)

Security Features

✅ File permissions: Sets .env to mode 600 (owner only) ✅ Directory permissions: Sets backup dirs to mode 700 (owner only) ✅ Backup permissions: Sets backup files to mode 600 (owner only) ✅ Git protection: Creates/updates .gitignore ✅ Backups: Timestamped backups before changes (secured) ✅ Validation: Checks format, permissions, entropy, and duplicates ✅ Template: Creates .env.example (safe to share) ✅ GPG encryption: Encrypts high-value secrets at rest ✅ Rotation tracking: Warns when credentials need rotation ✅ Deep scan: Detects hardcoded secrets in source files ✅ Symlink-aware: Validates symlinked .env targets

Output Structure

After migration:

~/.openclaw/
├── .env                     # All credentials (secure, mode 600)
├── .env.secrets.gpg         # GPG-encrypted high-value keys (mode 600)
├── .env.meta                # Rotation metadata (mode 600)
├── .env.example             # Template (safe to share)
├── .gitignore               # Protects .env and .env.secrets.gpg
└── backups/                 # (mode 700)
    └── credentials-old-YYYYMMDD/  # (mode 700)
        └── *.bak            # Backup files (mode 600)

GPG Encryption for High-Value Secrets

Private keys, wallet keys, and mnemonics should never exist as plaintext on disk. Use GPG encryption for these.

Setup GPG
bash
# First-time setup (generates OpenClaw GPG key, configures agent cache)
./scripts/setup-gpg.sh
Encrypt High-Value Keys
bash
# Encrypt specific keys (moves them from .env to .env.secrets.gpg)
./scripts/encrypt.py --keys MAIN_WALLET_PRIVATE_KEY,CUSTODY_PRIVATE_KEY,SIGNER_PRIVATE_KEY

# The .env will contain placeholders:
# MAIN_WALLET_PRIVATE_KEY=GPG:MAIN_WALLET_PRIVATE_KEY
How Scripts Access Encrypted Keys

The enforce.py module handles this transparently:

python
from enforce import get_credential

# Works for both plaintext and GPG-encrypted keys
key = get_credential('MAIN_WALLET_PRIVATE_KEY')
# If value starts with "GPG:", decrypts from .env.secrets.gpg automatically
GPG Agent Caching

On headless servers (VPS), the GPG agent caches the passphrase:

  • Default cache TTL: 8 hours
  • Configurable via setup-gpg.sh
  • Passphrase required once after reboot, then cached
What to Encrypt
Key TypeEncrypt?Why
Wallet private keys✅ YesControls funds
Custody/signer private keys✅ YesControls identity
Mnemonics / seed phrases✅ YesMaster recovery
API keys (services)❌ NoRevocable, low damage
Agent IDs, names, URLs❌ NoNot secrets

Credential Rotation Tracking

Setup Rotation Metadata
bash
# Initialize rotation tracking for all keys
./scripts/rotation-check.py --init

Creates ~/.openclaw/.env.meta:

json
{
  "MAIN_WALLET_PRIVATE_KEY": {
    "created": "2026-01-15",
    "lastRotated": null,
    "rotationDays": 90,
    "risk": "critical"
  },
  "MOLTBOOK_API_KEY": {
    "created": "2026-02-04",
    "lastRotated": null,
    "rotationDays": 180,
    "risk": "low"
  }
}
Check Rotation Status
bash
# Check which keys need rotation
./scripts/rotation-check.py

# Output:
# 🔴 MAIN_WALLET_PRIVATE_KEY: 26 days old (critical, rotate every 90 days)
# ✅ MOLTBOOK_API_KEY: 7 days old (low, rotate every 180 days)
Rotation Schedules
Risk LevelRotation PeriodExamples
Critical90 daysWallet keys, private keys
Standard180 daysAPI keys for paid services
Low365 daysFree-tier API keys, agent IDs
Add to Heartbeat (Optional)

Add rotation checks to HEARTBEAT.md for periodic monitoring:

markdown
## Credential Rotation (weekly)
If 7+ days since last rotation check:
1. Run: ./scripts/rotation-check.py
2. If any keys overdue: notify human
3. Update lastRotationCheck timestamp

Supported Services

Common services auto-detected:

  • X (Twitter): OAuth 1.0a credentials
  • Farcaster: Custody keys, signer keys, FID credentials
  • Molten: Agent intent matching
  • Moltbook: Agent social network
  • Botchan/4claw: Net Protocol
  • OpenAI, Anthropic, Google: AI providers
  • GitHub, GitLab: Code hosting
  • Coinbase/CDP: Crypto wallet credentials
  • Generic: API_KEY, *_TOKEN, *_SECRET patterns

See references/supported-services.md for full list.

Scripts

All scripts support --help for detailed usage.

scan.py
bash
# Scan and report
./scripts/scan.py

# Deep scan (includes hardcoded secrets in scripts)
./scripts/scan.py --deep

# Include custom paths
./scripts/scan.py --paths ~/.myapp/config ~/.local/share/creds

# JSON output
./scripts/scan.py --format json
consolidate.py
bash
# Interactive mode (prompts before changes)
./scripts/consolidate.py

# Auto-confirm (no prompts)
./scripts/consolidate.py --yes

# Backup only
./scripts/consolidate.py --backup-only

# Specific service
./scripts/consolidate.py --service molten
validate.py
bash
# Full validation (permissions, format, entropy, security)
./scripts/validate.py

# Check permissions only
./scripts/validate.py --check permissions

# Fix issues automatically
./scripts/validate.py --fix
encrypt.py
bash
# Encrypt specific high-value keys
./scripts/encrypt.py --keys MAIN_WALLET_PRIVATE_KEY,CUSTODY_PRIVATE_KEY

# List currently encrypted keys
./scripts/encrypt.py --list

# Decrypt (move back to plaintext .env)
./scripts/encrypt.py --decrypt --keys MAIN_WALLET_PRIVATE_KEY
rotation-check.py
bash
# Check rotation status
./scripts/rotation-check.py

# Initialize tracking for all keys
./scripts/rotation-check.py --init

# Record a rotation
./scripts/rotation-check.py --rotated MOLTBOOK_API_KEY
setup-gpg.sh
bash
# First-time GPG setup for OpenClaw
./scripts/setup-gpg.sh

# Configure cache timeout (hours)
./scripts/setup-gpg.sh --cache-hours 12
cleanup.py
bash
# Dry run (shows what would be deleted)
./scripts/cleanup.py

# Actually delete old files
./scripts/cleanup.py --confirm

# Keep backups
./scripts/cleanup.py --confirm --keep-backups

Migration Workflow

This is the exact step-by-step flow, tested and verified on a live OpenClaw deployment.

Step 1: Scan for Scattered Credentials
bash
cd /path/to/openclaw/skills/credential-manager

# Basic scan — finds credential files by path patterns
./scripts/scan.py

# Deep scan — also greps source files for hardcoded secrets
./scripts/scan.py --deep

What to look for in output:

  • ⚠️ files with mode != 600 (insecure permissions)
  • Symlinked .env files (should point to main ~/.openclaw/.env)
  • JSON credential files outside ~/.openclaw/.env
  • Deep scan hits on hardcoded keys in scripts

Example output:

⚠️ /home/user/.openclaw/farcaster-credentials.json
   Type: json
   Keys: custodyPrivateKey, signerPrivateKey, ...
   Mode: 644
   ⚠️  Should be 600 for security

✅ /home/user/.openclaw/.env
   Type: env
   Keys: API_KEY, X_CONSUMER_KEY, ...
   Mode: 600
Show full SKILL.md (532 more words)Show less
Step 2: Consolidate into .env
bash
./scripts/consolidate.py

Interactive flow:

  1. Script scans and lists all credential files found
  2. Backs up existing .env to ~/.openclaw/backups/credentials-old-YYYYMMDD/
  3. Loads existing .env keys
  4. Processes each credential file:
    • Auto-detects service (x, farcaster, moltbook, molten, etc.)
    • Normalizes key names (e.g., custodyPrivateKey → FARCASTER_CUSTODY_PRIVATE_KEY)
    • Shows mapping: key → ENV_KEY
  5. Asks for confirmation: Proceed? [y/N]
  6. Writes merged .env (mode 600)
  7. Creates .env.example template (safe to share)
  8. Updates .gitignore

For credentials not auto-detected (e.g., nested JSON like farcaster-credentials.json with multiple accounts), manually add to .env:

bash
cat >> ~/.openclaw/.env << 'EOF'

# FARCASTER (Active: mr-teeclaw, FID 2700953)
FARCASTER_FID=2700953
FARCASTER_FNAME=mr-teeclaw
FARCASTER_CUSTODY_ADDRESS=0x...
FARCASTER_CUSTODY_PRIVATE_KEY=0x...
FARCASTER_SIGNER_PUBLIC_KEY=...
FARCASTER_SIGNER_PRIVATE_KEY=...

# FARCASTER LEGACY (teeclaw, FID 2684290)
FARCASTER_LEGACY_FID=2684290
FARCASTER_LEGACY_CUSTODY_ADDRESS=0x...
FARCASTER_LEGACY_CUSTODY_PRIVATE_KEY=0x...
FARCASTER_LEGACY_SIGNER_PUBLIC_KEY=...
FARCASTER_LEGACY_SIGNER_PRIVATE_KEY=...
EOF

chmod 600 ~/.openclaw/.env
Step 3: Validate
bash
./scripts/validate.py

Checks performed:

  • ✅ .env permissions (must be 600)
  • ✅ .gitignore coverage
  • ✅ Format validation (key format, quoting, duplicates)
  • ✅ Security analysis:
    • Detects plaintext private keys (0x + 64 hex chars) → recommends GPG
    • Detects mnemonic/seed phrases (12/24 word values) → recommends GPG
    • Entropy analysis on SECRET/PRIVATE_KEY/PASSWORD fields
    • Flags weak/placeholder values
  • ✅ Backup permissions (files must be 600, directories 700)

Fix issues automatically:

bash
./scripts/validate.py --fix

This fixes: file permissions, directory permissions, backup permissions, gitignore. It does NOT auto-fix format issues or encrypt keys — those require manual action.

Step 4: Setup GPG and Encrypt Private Keys
bash
# First-time GPG setup (configures agent cache, tests encrypt/decrypt)
./scripts/setup-gpg.sh
# Optional: --cache-hours 12 (default: 8)

Encrypt high-value keys:

bash
# Encrypt wallet + Farcaster private keys
./scripts/encrypt.py --keys MAIN_WALLET_PRIVATE_KEY,FARCASTER_CUSTODY_PRIVATE_KEY,FARCASTER_SIGNER_PRIVATE_KEY,FARCASTER_LEGACY_CUSTODY_PRIVATE_KEY,FARCASTER_LEGACY_SIGNER_PRIVATE_KEY

What happens:

  1. Prompts for a GPG passphrase (or reads OPENCLAW_GPG_PASSPHRASE env var)
  2. Extracts specified key values from .env
  3. Stores them encrypted in ~/.openclaw/.env.secrets.gpg (AES256, mode 600)
  4. Replaces .env values with GPG:KEY_NAME placeholders
  5. Scripts using get_credential() or _load_cred() decrypt transparently

Save passphrase to .env for automated decryption:

bash
echo 'OPENCLAW_GPG_PASSPHRASE=your-passphrase-here' >> ~/.openclaw/.env
chmod 600 ~/.openclaw/.env

Verify encryption:

bash
# Check .env has GPG placeholders
grep "GPG:" ~/.openclaw/.env

# List all encrypted keys
./scripts/encrypt.py --list
Step 5: Initialize Rotation Tracking
bash
./scripts/rotation-check.py --init

Auto-classifies all keys by risk:

  • Critical (90-day rotation): *PRIVATE_KEY, *MNEMONIC, *SEED, *WALLET_KEY, *CUSTODY*, *SIGNER*
  • Standard (180-day rotation): *API_KEY, *SECRET, *TOKEN, *BEARER, *CONSUMER*, *ACCESS*
  • Low (365-day rotation): Everything else

Creates ~/.openclaw/.env.meta (mode 600) with creation dates and rotation schedules.

Check rotation status anytime:

bash
./scripts/rotation-check.py
Step 6: Cleanup Old Credential Files
bash
# Dry run first — see what would be deleted
./scripts/cleanup.py

# Actually delete (prompts for 'DELETE' confirmation)
./scripts/cleanup.py --confirm

Also manually remove migrated files not caught by the scanner:

bash
# Example: farcaster-credentials.json was manually migrated
cp ~/.openclaw/farcaster-credentials.json ~/.openclaw/backups/credentials-old-YYYYMMDD/farcaster-credentials.json.bak
chmod 600 ~/.openclaw/backups/credentials-old-YYYYMMDD/farcaster-credentials.json.bak
rm ~/.openclaw/farcaster-credentials.json
Step 7: Update Scripts That Referenced Old Files

Any scripts that loaded from JSON credential files or hardcoded paths need updating.

Pattern — Bash scripts:

bash
# OLD (insecure):
FARCASTER_CREDS="/home/user/.openclaw/farcaster-credentials.json"
fid=$(jq -r '.fid' "$FARCASTER_CREDS")
private_key=$(jq -r '.custodyPrivateKey' "$FARCASTER_CREDS")

# NEW (secure, GPG-aware):
ENV_FILE="$HOME/.openclaw/.env"

_load_cred() {
  local key="$1"
  local value
  value=$(grep "^${key}=" "$ENV_FILE" | head -1 | cut -d= -f2-)
  if [[ "$value" == GPG:* ]]; then
    local gpg_key="${value#GPG:}"
    local passphrase="${OPENCLAW_GPG_PASSPHRASE:-}"
    if [ -n "$passphrase" ]; then
      value=$(echo "$passphrase" | gpg -d --batch --quiet --passphrase-fd 0 "$HOME/.openclaw/.env.secrets.gpg" | python3 -c "import json,sys; print(json.load(sys.stdin).get('$gpg_key',''))")
    else
      value=$(gpg -d --batch --quiet "$HOME/.openclaw/.env.secrets.gpg" | python3 -c "import json,sys; print(json.load(sys.stdin).get('$gpg_key',''))")
    fi
  fi
  echo "$value"
}

fid=$(_load_cred "FARCASTER_FID")
private_key=$(_load_cred "FARCASTER_CUSTODY_PRIVATE_KEY")

Pattern — Node.js scripts:

javascript
// OLD (insecure):
const creds = JSON.parse(fs.readFileSync('~/.openclaw/farcaster-credentials.json'));
const privateKey = creds.custodyPrivateKey;

// NEW (secure, GPG-aware):
const ENV_PATH = path.join(os.homedir(), '.openclaw/.env');
const SECRETS_PATH = path.join(os.homedir(), '.openclaw/.env.secrets.gpg');

function loadCred(key) {
  const content = fs.readFileSync(ENV_PATH, 'utf8');
  for (const line of content.split('\n')) {
    if (line.startsWith(key + '=')) {
      let value = line.slice(key.length + 1).trim();
      if (value.startsWith('GPG:')) {
        const { execSync } = require('child_process');
        const passphrase = process.env.OPENCLAW_GPG_PASSPHRASE || '';
        const cmd = passphrase
          ? `echo "${passphrase}" | gpg -d --batch --quiet --passphrase-fd 0 "${SECRETS_PATH}"`
          : `gpg -d --batch --quiet "${SECRETS_PATH}"`;
        const secrets = JSON.parse(execSync(cmd, { encoding: 'utf8' }));
        return secrets[value.slice(4)] || '';
      }
      return value;
    }
  }
  return '';
}

const privateKey = loadCred('FARCASTER_CUSTODY_PRIVATE_KEY');

Pattern — Python scripts:

python
# Use the enforce module (recommended):
import sys
from pathlib import Path
sys.path.insert(0, str(Path.home() / 'openclaw/skills/credential-manager/scripts'))
from enforce import get_credential

private_key = get_credential('FARCASTER_CUSTODY_PRIVATE_KEY')  # Auto-decrypts GPG
Step 8: Final Validation
bash
# Run full validation — should show all green
./scripts/validate.py

# Verify encrypted keys
./scripts/encrypt.py --list

# Check rotation status
./scripts/rotation-check.py

# Test a script that uses credentials
bash /path/to/your/script.sh

Expected final state:

~/.openclaw/
├── .env                     # All credentials (mode 600, private keys = GPG:*)
├── .env.secrets.gpg         # GPG-encrypted private keys (mode 600)
├── .env.meta                # Rotation tracking metadata (mode 600)
├── .env.example             # Template (safe to share)
├── .gitignore               # Protects .env, .env.secrets.gpg, .env.meta
└── backups/                 # (mode 700)
    └── credentials-old-YYYYMMDD/  # (mode 700)
        └── *.bak            # Backup files (mode 600)

For Skill Developers: Enforce This Standard

Other OpenClaw skills MUST validate credentials are secure before using them:

Python Skills
python
#!/usr/bin/env python3
import sys
from pathlib import Path

# Add credential-manager scripts to path
sys.path.insert(0, str(Path.home() / '.openclaw/skills/credential-manager/scripts'))

# Enforce secure .env (exits if not compliant)
from enforce import require_secure_env, get_credential

require_secure_env()

# Now safe to load credentials (handles GPG-encrypted keys transparently)
api_key = get_credential('SERVICE_API_KEY')
wallet_key = get_credential('MAIN_WALLET_PRIVATE_KEY')  # Auto-decrypts from GPG
Bash Skills
bash
#!/usr/bin/env bash
set -euo pipefail

# Validate .env exists and is secure
if ! python3 ~/.openclaw/skills/credential-manager/scripts/enforce.py; then
    exit 1
fi

# Now safe to load
source ~/.openclaw/.env

This creates a fail-fast system: If credentials aren't properly secured, skills refuse to run. Users are forced to fix it.

Loading Credentials

After migration, load from .env:

Python
python
import os
from pathlib import Path

# Load .env
env_file = Path.home() / '.openclaw' / '.env'
with open(env_file) as f:
    for line in f:
        if '=' in line and not line.strip().startswith('#'):
            key, val = line.strip().split('=', 1)
            os.environ[key] = val

# Use credentials
api_key = os.getenv('SERVICE_API_KEY')
Bash
bash
# Load .env
set -a
source ~/.openclaw/.env
set +a

# Use credentials
echo "$SERVICE_API_KEY"
Using Existing Loaders

If you migrated using OpenClaw scripts:

python
from load_credentials import get_credentials
creds = get_credentials('x')

Adding New Credentials

Edit ~/.openclaw/.env:

bash
# Add new service
NEW_SERVICE_API_KEY=your_key_here
NEW_SERVICE_SECRET=your_secret_here

Update template too:

bash
# Edit .env.example
NEW_SERVICE_API_KEY=your_key_here
NEW_SERVICE_SECRET=your_secret_here

If the new credential is high-value (private key, wallet key):

bash
# Add to .env first, then encrypt
./scripts/encrypt.py --keys NEW_SERVICE_PRIVATE_KEY

Security Best Practices

See references/security.md for detailed security guidelines.

Quick checklist:

  • ✅ .env has 600 permissions
  • ✅ .env is git-ignored
  • ✅ Backup files have 600 permissions
  • ✅ Backup directories have 700 permissions
  • ✅ No credentials in code or logs (use --deep scan to verify)
  • ✅ Private keys encrypted with GPG
  • ✅ Rotation schedule established and tracked
  • ✅ Symlinked .env files point to the main .env only
  • ✅ No credentials in shell history (use source, not export KEY=val)

Rollback

If something goes wrong:

bash
# Find your backup
ls -la ~/.openclaw/backups/

# Restore specific file
cp ~/.openclaw/backups/credentials-old-YYYYMMDD/x-credentials.json.bak \
   ~/.config/x/credentials.json

# Decrypt GPG secrets back to plaintext
./scripts/encrypt.py --decrypt --keys MAIN_WALLET_PRIVATE_KEY

Notes

  • Non-destructive by default: Original files backed up before removal
  • Idempotent: Safe to run multiple times
  • Extensible: Add custom credential patterns in scripts
  • Secure: Never logs full credentials, only metadata
  • GPG-aware: Transparently handles encrypted and plaintext credentials
  • Backup-hardened: All backups secured with proper permissions
  • Symlink-aware: Detects and validates symlinked credential files

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 15 other files (scripts, references) in skills/openclaw-credential-manager of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • CHANGELOG.md
  • CONSOLIDATION-RULE.md
  • CORE-PRINCIPLE.md
  • README.md
  • _meta.json
  • references/security.md
  • references/supported-services.md
  • scripts/cleanup.py
  • scripts/consolidate.py
  • scripts/encrypt.py
  • scripts/enforce.py
  • scripts/rotation-check.py
  • scripts/scan.py
  • scripts/setup-gpg.sh
  • scripts/validate.py

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Credential Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Credential Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Credential Manager this skillLeoYeAI/openclaw-master-skills2.2k—~5.8kAutomated safety check: NotesMIT
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
KubeSphere ServiceMesh Managerkubesphere/kubesphere17k—~2.4kAutomated safety check: PassCustom licence
Vercelremotion-dev/remotion63k—~1.2kAutomated safety check: PassCustom licence
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Vercel

    remotion-dev/remotion

    Official

    Set up a Codex monitor for Vercel deployments and preview URLs.

    63k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Credential Manager

What does Credential Manager do?

MANDATORY security foundation for OpenClaw. An agent skill from LeoYeAI/openclaw-master-skills. Credential Manager is an agent skill from LeoYeAI/openclaw-master-skills. MANDATORY security foundation for OpenClaw.

When should I use Credential Manager?

Credential Manager fits situations like: setting up OpenClaw; migrating credentials; auditing security; enforcing the .env standard.

How do I install Credential Manager in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill credential-manager -a claude-code`. Or copy the skill folder (skills/openclaw-credential-manager in LeoYeAI/openclaw-master-skills) into .claude/skills/credential-manager in your project. Claude Code loads it when a task matches its description.

How do I install Credential Manager in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill credential-manager -a codex`. Or copy the skill folder (skills/openclaw-credential-manager in LeoYeAI/openclaw-master-skills) into .agents/skills/credential-manager in your project. Codex loads it when a task matches its description.

Can I use Credential Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill credential-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/credential-manager, .gemini/skills/credential-manager, .github/skills/credential-manager and .opencode/skills/credential-manager in your project.

What does Credential Manager need to run?

Going by SKILL.md and its folder, Credential Manager needs Python and a shell for the scripts in its folder, the command-line tools its instructions call (jq, python3 and bash) and credentials named MAIN_WALLET_PRIVATE_KEY, FARCASTER_CUSTODY_PRIVATE_KEY, API_KEY and PRIVATE_KEY. Our summary lists: Python 3; A Bash shell; A credential in MAIN_WALLET_PRIVATE_KEY; A credential in CUSTODY_PRIVATE_KEY.

Does Credential Manager access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Credential Manager safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Credential Manager use?

Credential Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Credential Manager use?

About 5.8k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Credential Manager?

Skills that share tags, products or a category with Credential Manager: Kubeshark Installer (kubeshark/kubeshark, 12k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), KubeSphere ServiceMesh Manager (kubesphere/kubesphere, 17k stars) and Vercel (remotion-dev/remotion, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Credential Manager?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.