Secure key management for AI agents. An agent skill from profbernardoj/everclaw-community-branches.

MITAuto-check: warningsSecurity

Install Bagman

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add profbernardoj/everclaw-community-branches --skill bagman -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install profbernardoj/everclaw-community-branches bagman --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/profbernardoj/everclaw-community-branches.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/bagman .claude/skills/bagman && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bagman
GitHub stars
112
Token cost
~4.4k tokens
SKILL.md length
794 words
Files
27 (incl. references)
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Secure key management for AI agents. An agent skill from profbernardoj/everclaw-community-branches.

  • Works in 8 steps: Secret Retrieval → Output Sanitization (MANDATORY) → Input Validation → …
  • Handling private keys
  • SKILL.md covers When to Use This Skill, Quick Start, Core Rules and Architecture, plus 10 more sections
  • Runs Python and TypeScript scripts from its folder; calls python and brew; needs PRIVATE_KEY and SESSION_KEY

What it does

Bagman is an agent skill from profbernardoj/everclaw-community-branches. Secure key management for AI agents. Use when handling private keys, API secrets, wallet credentials, or when building systems that need agent-controlled funds. Covers secure storage, session keys, leak prevention, prompt injection defense, and MetaMask Delegation Framework integration.

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 29 other files, including reference files (for example `.clawhub/origin.json`, `_meta.json` and `examples/backends/__init__.py`).

It sits in Security, covering Prompt injection and agent security and Cryptography. The repository describes itself as: Decentralized AI inference for OpenClaw agents. Powered by Morpheus AI. Stake MOR, access Kimi K2.5 + 10 models, never run out of inference. The licence is MIT.

When your agent uses it

  • Handling private keys
  • Wallet credentials
  • Building systems that need agent-controlled funds

Example prompts

  • “/bagman”

Requirements

  • Python 3
  • Node.js
  • A credential in SESSION_KEY
  • A credential in PRIVATE_KEY

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Secret Retrieval
  2. Output Sanitization (MANDATORY)
  3. Input Validation
  4. Operation Allowlisting
  5. Confirmation Flow
  6. Session Keys (ERC-4337)
  7. Pre-commit Hook
  8. Defense Layers

What it can do on your machine

Read from SKILL.md and the folder at commit 0b30b36. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python and TypeScript, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PRIVATE_KEY
    • SESSION_KEY
    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bagman loads about 4.4k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 794 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~19k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteMentions a .env fileSKILL.md:109
    op run --env-file=.env.tpl -- python agent.py
  • NoteMentions a .env fileSKILL.md:112
    ### .env.tpl (safe to commit - no secrets)
  • WarningContains instruction-override wording (e.g. “without asking the user”)SKILL.md:253
    | Override | "ignore previous instructions" | Block |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from profbernardoj/everclaw-community-branches at commit 0b30b36, republished under its MIT licence (© profbernardoj). 794 words, ~4,446 tokens.

Download SKILL.mdSave it as .claude/skills/bagman/SKILL.md (or your agent's skills folder). This skill also uses 26 other files; get the full folder from GitHub.
name
bagman
description
Secure key management for AI agents. Use when handling private keys, API secrets, wallet credentials, or when building systems that need agent-controlled funds. Covers secure storage, session keys, leak prevention, prompt injection defense, and MetaMask Delegation Framework integration.
version
2.2.0
homepage
https://github.com/zscole/bagman-skill

Bagman

Secure key management patterns for AI agents handling wallets, private keys, and secrets.

When to Use This Skill

  • Agent needs wallet/blockchain access
  • Handling API keys, credentials, or secrets
  • Building systems where AI controls funds
  • Preventing secret leakage via prompts or outputs

Quick Start

bash
# Install 1Password CLI
brew install 1password-cli

# Authenticate
eval $(op signin)

# Create vault for agent credentials
op vault create "Agent-Credentials"

# Run examples
cd examples && python test_suite.py

Core Rules

RuleWhy
Never store raw private keysConfig, env, memory, or conversation = leaked
Use delegated accessSession keys with time/value/scope limits
Secrets via secret manager1Password, Vault, AWS Secrets Manager
Sanitize all outputsScan for key patterns before any response
Validate all inputsCheck for injection attempts before wallet ops

Architecture

┌─────────────────────────────────────────────────────┐
│                   AI Agent                          │
├─────────────────────────────────────────────────────┤
│  Session Key (bounded)                              │
│  ├─ Expires after N hours                           │
│  ├─ Max spend per tx/day                            │
│  └─ Whitelist of allowed contracts/methods          │
├─────────────────────────────────────────────────────┤
│  Secret Manager (1Password/Vault)                   │
│  ├─ Retrieve at runtime only                        │
│  ├─ Never persist to disk                           │
│  └─ Audit trail of accesses                         │
├─────────────────────────────────────────────────────┤
│  Smart Account (ERC-4337)                           │
│  ├─ Programmable permissions                        │
│  └─ Recovery without key exposure                   │
└─────────────────────────────────────────────────────┘

Implementation Files

FilePurpose
examples/secret_manager.py1Password integration for runtime secret retrieval
examples/sanitizer.pyOutput sanitization (keys, seeds, tokens)
examples/validator.pyInput validation (prompt injection defense)
examples/session_keys.pyERC-4337 session key configuration
examples/delegation_integration.tsMetaMask Delegation Framework (EIP-7710)
examples/pre-commitGit hook to block secret commits
examples/test_suite.pyAdversarial test suite
docs/prompt-injection.mdDeep dive on injection defense
docs/secure-storage.mdSecret storage patterns
docs/session-keys.mdSession key architecture
docs/leak-prevention.mdOutput sanitization patterns
docs/delegation-framework.mdOn-chain permission enforcement (EIP-7710)

1. Secret Retrieval

1Password CLI Pattern
bash
# Retrieve at runtime (never store result)
SESSION_KEY=$(op read "op://Agents/my-agent/session-key")

# Run with injected secrets (never touch disk)
op run --env-file=.env.tpl -- python agent.py
.env.tpl (safe to commit - no secrets)
PRIVATE_KEY=op://Agents/trading-bot/session-key
RPC_URL=op://Infra/alchemy/sepolia-url
OPENAI_API_KEY=op://Services/openai/api-key
Python Usage
python
from secret_manager import get_session_key

# Retrieve validated session key
creds = get_session_key("trading-bot-session")

# Check validity
if creds.is_expired():
    raise ValueError("Session expired - request renewal from operator")

print(f"Time remaining: {creds.time_remaining()}")
print(f"Allowed contracts: {creds.allowed_contracts}")

# Use the key (never log it!)
client.set_signer(creds.session_key)

Configure 1Password vault permissions:

Agent-Credentials/
├── trading-bot-session    # Agent can read
├── payment-bot-session    # Agent can read
└── master-key             # Operator ONLY (agent has no access)

Principle: Agent credentials should be in a vault with read-only agent access. Master keys should be in a separate vault the agent cannot access.


2. Output Sanitization (MANDATORY)

⚠️ CRITICAL: Apply to ALL agent outputs before sending anywhere. No exceptions.

This includes:

  • Chat responses
  • Cron job summaries
  • Monitoring alerts
  • Status reports
  • Debug logs
  • Error messages
  • Any text that leaves the agent
python
from sanitizer import OutputSanitizer

def respond(content: str) -> str:
    """Mandatory sanitization before ANY output."""
    return OutputSanitizer.sanitize(content)

def cron_summary(task_result: dict) -> str:
    """Cron summaries MUST sanitize before delivery."""
    summary = format_summary(task_result)
    return OutputSanitizer.sanitize(summary)  # ALWAYS sanitize
Secret Patterns Detected
PatternExampleResult
ETH private key0x1234...abcd (64 hex)[PRIVATE_KEY_REDACTED]
ETH address0x742d...f44e (40 hex)0x742d...f44e (truncated)
OpenAI keysk-proj-abc123...[OPENAI_KEY_REDACTED]
Anthropic keysk-ant-api03-...[ANTHROPIC_KEY_REDACTED]
12-word seedabandon ability able...[SEED_PHRASE_12_WORDS_REDACTED]
JWTeyJhbG...[JWT_TOKEN_REDACTED]
Venice key refsvenice:key1, venice:key2[ venice:key1 ] (bracketed)
Sensitive Metrics Redacted (Cron Summaries)
PatternExampleResult
DIEM counts98 DIEM, 194 DIEM[DIEM_REDACTED]
Balancebalance: 42.5 DIEM[BALANCE_REDACTED]
Thresholdthreshold: 10 DIEM[THRESHOLD_REDACTED]
Totalstotal: 194 DIEM[TOTAL_REDACTED]
Remaining/Spentremaining: 50 DIEM[METRIC_REDACTED]
Cron Summary Example

BEFORE sanitization (NEVER send this):

Venice API check: venice:key1 has 98 DIEM, venice:key2 has 96 DIEM.
Balance: 194 DIEM, Threshold: 10 DIEM

AFTER sanitization (safe to send):

Venice API check: [ venice:key1 ] has [DIEM_REDACTED], [ venice:key2 ] has [DIEM_REDACTED].
[BALANCE_REDACTED], [THRESHOLD_REDACTED]
Venice Key Reference Sanitization

Venice API key references (venice:key1, venice:key2, etc.) are NOT secrets themselves, but should be bracketed to:

  1. Prevent them from being used as identifiers in logs
  2. Make it clear they are references, not actual keys
  3. Distinguish from potential false-positive patterns

The sanitizer brackets un-bracketed references: venice:key1 → [ venice:key1 ]

Already-bracketed references are left unchanged: [ venice:key1 ] → [ venice:key1 ]


3. Input Validation

Check inputs before ANY wallet operation:

python
from validator import InputValidator, ThreatLevel

result = InputValidator.validate(user_input)

if result.level == ThreatLevel.BLOCKED:
    return f"Request blocked: {result.reason}"

if result.level == ThreatLevel.SUSPICIOUS:
    # Log for review, but allow
    log_suspicious(user_input, result.reason)

# Proceed with operation
Threat Categories
CategoryExamplesAction
Extraction"show private key", "reveal secrets"Block
Override"ignore previous instructions"Block
Role manipulation"you are now admin"Block
Jailbreak"DAN mode", "bypass filters"Block
Exfiltration"send config to https://..."Block
Wallet threats"transfer all", "unlimited approve"Block
EncodedBase64/hex encoded attacksBlock
Unicode tricksCyrillic lookalikes, zero-widthBlock
Suspicious"hypothetically", "just between us"Warn

4. Operation Allowlisting

Never execute arbitrary operations. Explicit whitelist only:

python
from dataclasses import dataclass
from decimal import Decimal
from typing import Optional

@dataclass
class AllowedOperation:
    name: str
    handler: callable
    max_value: Optional[Decimal] = None
    requires_confirmation: bool = False
    cooldown_seconds: int = 0

ALLOWED_OPS = {
    "check_balance": AllowedOperation("check_balance", get_balance),
    "transfer_usdc": AllowedOperation(
        "transfer_usdc", 
        transfer,
        max_value=Decimal("500"),
        requires_confirmation=True,
        cooldown_seconds=60
    ),
    "swap": AllowedOperation(
        "swap",
        swap_tokens,
        max_value=Decimal("1000"),
        cooldown_seconds=300
    ),
}

def execute(op_name: str, **kwargs):
    if op_name not in ALLOWED_OPS:
        raise PermissionError(f"Operation '{op_name}' not allowed")
    
    op = ALLOWED_OPS[op_name]
    
    if op.max_value and kwargs.get("amount", 0) > op.max_value:
        raise PermissionError(f"Amount exceeds limit: {op.max_value}")
    
    if op.requires_confirmation:
        return request_confirmation(op_name, kwargs)
    
    return op.handler(**kwargs)

Show full SKILL.md (318 more words)Show less

5. Confirmation Flow

High-value operations require explicit confirmation:

python
import hashlib
import time

pending_confirmations = {}

def request_confirmation(operation: str, details: dict) -> str:
    code = hashlib.sha256(
        f"{operation}{time.time()}".encode()
    ).hexdigest()[:8].upper()
    
    pending_confirmations[code] = {
        "op": operation,
        "details": details,
        "expires": time.time() + 300  # 5 minutes
    }
    
    return f"⚠️ Confirm '{operation}' with code: {code}\n(expires in 5 minutes)"

def confirm(code: str):
    if code not in pending_confirmations:
        return "Invalid confirmation code"
    
    req = pending_confirmations.pop(code)
    
    if time.time() > req["expires"]:
        return "Confirmation code expired"
    
    return execute_confirmed(req["op"], req["details"])

6. Session Keys (ERC-4337)

Instead of giving agents master keys, issue bounded session keys:

python
from session_keys import SessionKeyManager

# Operator creates trading session for agent
config = SessionKeyManager.create_trading_session(
    agent_name="alpha-trader",
    operator_address="0x742d...",
    duration_hours=24,
    max_trade_usdc=1000,
    daily_limit_usdc=5000,
)

# Export for storage in 1Password
export_data = SessionKeyManager.export_for_1password(
    config, 
    session_key_hex="0x..."  # Generated session key
)

# op item create ... (store in 1Password)
Session Key Benefits
FeatureMaster KeySession Key
ExpirationNeverConfigurable (hours/days)
Spending limitsNonePer-tx and daily caps
Contract restrictionsFull accessWhitelist only
RevocationRequires key rotationInstant, no key change
AuditNoneFull operation log

7. Pre-commit Hook

Block commits containing secrets:

bash
# Install
cp examples/pre-commit .git/hooks/
chmod +x .git/hooks/pre-commit

Detected patterns:

  • ETH private keys (64 hex chars)
  • OpenAI/Anthropic/Groq keys
  • AWS access keys
  • GitHub/GitLab tokens
  • Slack/Discord tokens
  • PEM private keys
  • Generic PASSWORD/SECRET assignments
  • BIP-39 seed phrases

8. Defense Layers

USER INPUT
    │
    ▼
┌────────────────────────────┐
│ Layer 1: Input Validation  │  ← Regex + encoding + unicode checks
└────────────────────────────┘
    │
    ▼
┌────────────────────────────┐
│ Layer 2: Op Allowlisting   │  ← Explicit whitelist only
└────────────────────────────┘
    │
    ▼
┌────────────────────────────┐
│ Layer 3: Value Limits      │  ← Max per-tx and per-day
└────────────────────────────┘
    │
    ▼
┌────────────────────────────┐
│ Layer 4: Confirmation      │  ← Time-limited codes for $$$
└────────────────────────────┘
    │
    ▼
┌────────────────────────────┐
│ Layer 5: Isolated Exec     │  ← Wallet ops != conversation
└────────────────────────────┘
    │
    ▼
OUTPUT SANITIZATION

Common Mistakes

❌ Keys in memory files
markdown
# memory/2026-02-07.md
Private key: 0x9f01dad551039daad...

Fix: Store reference only: Private key: [stored in 1Password: test-wallet]

❌ Keys in error messages
python
except Exception as e:
    log(f"Failed with key {private_key}: {e}")

Fix: Never include credentials in error context

❌ Keys in .env.example
PRIVATE_KEY=sk-ant-api03-real-key...  # "for testing"

Fix: Use obviously fake: PRIVATE_KEY=your-key-here

❌ "All" in transfer requests
User: "Transfer all my USDC"
Agent: *executes unlimited transfer*

Fix: Block "all/everything/max" patterns, require explicit amounts

❌ Trusting conversation context
python
# Wallet has access to conversation history
self.wallet.execute(conversation[-1]["content"])

Fix: Wallet operations must be isolated from conversation context


Testing

bash
cd examples

# Run full test suite
python test_suite.py

# Test individual components
python sanitizer.py    # Output sanitization demo
python validator.py    # Input validation demo
python session_keys.py # Session key demo

Expected output: All tests passed

Test Evidence (v2.2.0 - 2026-03-11)

Sanitizer v3 Test Results - All 16 tests passed:

Output Sanitizer Test (v3)
============================================================

✅ PASS (expect detect)
   Input:     My key is 0x1234567890abcdef...
   Sanitized: My key is [PRIVATE_KEY_REDACTED]

✅ PASS (expect detect)
   Input:     Key: 1234567890abcdef...
   Sanitized: Key: [HEX_KEY_REDACTED]

✅ PASS (expect detect)
   Input:     First half: 1234567890abcdef...
   Sanitized: First half: [PARTIAL_KEY_REDACTED]

✅ PASS (expect detect)
   Input:     Send to 0x742d35Cc6634C0532925a3b844Bc454e4438f44e
   Sanitized: Send to 0x742d...f44e

✅ PASS (expect detect)
   Input:     Using sk-proj-abc123def456...
   Sanitized: Using [OPENAI_KEY_REDACTED]

✅ PASS (expect detect)
   Input:     API key is sk-ant-api03-abcdef...
   Sanitized: API key is [ANTHROPIC_KEY_REDACTED]

✅ PASS (expect detect)
   Input:     aws_secret_key=AKIAIOSFODNN7EXAMPLE...
   Sanitized: aws_secret_key=[AWS_ACCESS_KEY_REDACTED]...

✅ PASS (expect ignore)
   Input:     The hash is dGhpcyBpcyBhIHRlc3Q...
   Sanitized: The hash is dGhpcyBpcyBhIHRlc3Q...

✅ PASS (expect detect)
   Input:     abandon ability able about above absent...
   Sanitized: [SEED_PHRASE_12_WORDS_REDACTED]

✅ PASS (expect detect)
   Input:     Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
   Sanitized: Bearer [JWT_TOKEN_REDACTED]

✅ PASS (expect ignore)
   Input:     Normal text without secrets
   Sanitized: Normal text without secrets

✅ PASS (expect detect)
   Input:     Bot token: 123456789:ABCdefGHI...
   Sanitized: Bot token: [TELEGRAM_TOKEN_REDACTED]

============================================================
Cron Summary & Venice Key Sanitization Tests
------------------------------------------------------------

✅ PASS
   Input:     Venice API check: venice:key1 has 98 DIEM, venice:key2 has 96 DIEM. Total: 194 DIEM.
   Sanitized: Venice API check: [ venice:key1 ] has [DIEM_REDACTED], [ venice:key2 ] has [DIEM_REDACTED]...
   Expected fragment ✓: [ venice:key1 ]
   Expected fragment ✓: [ venice:key2 ]
   Expected fragment ✓: [DIEM_REDACTED]

✅ PASS
   Input:     Monitor: balance: 42.5 DIEM, threshold: 10 DIEM, total: 194 DIEM
   Sanitized: Monitor: [BALANCE_REDACTED], [THRESHOLD_REDACTED], [TOTAL_REDACTED]
   Expected fragment ✓: [BALANCE_REDACTED]
   Expected fragment ✓: [THRESHOLD_REDACTED]
   Expected fragment ✓: [TOTAL_REDACTED]

✅ PASS
   Input:     Using [ venice:key1 ] for fallback.
   Sanitized: Using [ venice:key1 ] for fallback.
   Expected fragment ✓: [ venice:key1 ]

✅ PASS
   Input:     remaining: 50 DIEM, spent: 30 DIEM
   Sanitized: remaining: [DIEM_REDACTED], spent: [DIEM_REDACTED]
   Expected fragment ✓: [DIEM_REDACTED]

============================================================
Results: 16 passed, 0 failed
All tests passed ✅

Key capabilities verified:

  • venice:key<N> references are bracketed: [ venice:key1 ]
  • Already-bracketed references remain unchanged
  • Sensitive metrics (balance, threshold, total, DIEM counts) are redacted
  • All existing secret detection patterns work correctly

Checklist

  • 1Password CLI installed and authenticated
  • Secrets in 1Password vault, not files
  • Session keys with expiry and limits
  • Output sanitization on all responses
  • Input validation before wallet ops
  • Pre-commit hook installed
  • Confirmation flow for high-value operations
  • Wallet operations isolated from conversation
  • .gitignore covers secrets and memory files
  • Test suite passes

Security Model Limitations

This skill provides defense in depth, not a guarantee. Adversaries may:

  1. Novel injection patterns - Regex can't catch everything; semantic analysis helps but isn't perfect
  2. Social engineering - Convincing the operator to approve malicious operations
  3. Timing attacks - Exploiting confirmation windows
  4. Encoding evasion - New encoding schemes not covered

Recommendation: Layer these defenses with:

  • Rate limiting
  • Anomaly detection
  • Human-in-the-loop for large transactions
  • Regular security audits

© profbernardoj, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 26 other files (references) in skills/bagman of profbernardoj/everclaw-community-branches.

  • SKILL.md
  • .clawhub/origin.json
  • _meta.json
  • examples/backends/__init__.py
  • examples/backends/auto.py
  • examples/backends/base.py
  • examples/backends/encrypted_file.py
  • examples/backends/env.py
  • examples/backends/keychain.py
  • examples/backends/onepassword.py
  • examples/bip39_wordlist.txt
  • examples/delegation_integration.test.ts
  • examples/delegation_integration.ts
  • examples/pre-commit
  • examples/sanitizer.py
  • examples/secret_manager.py
  • examples/session_keys.py
  • examples/test_suite.py
  • … and 9 more

Open the folder on GitHubat commit 0b30b36

Compare with similar skills

Bagman next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bagman compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bagman this skillprofbernardoj/everclaw-community-branches112—~4.4kAutomated safety check: WarnMIT
Agent Security Managerruvnet/ruflo74k2 repos~4.9kAutomated safety check: PassMIT
Clade Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: NotesMIT
BagmanLeoYeAI/openclaw-master-skills2.2k—~2.9kAutomated safety check: NotesMIT
Anth Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: NotesMIT
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0

Similar skills

  • Agent skill for security-manager - invoke with $agent-security-manager

    74k GitHub starsUsed in 2 repos~4.9k tokens
    SecurityAuto-check passed
  • Clade Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Secure your Anthropic integration — API key management, input validation, Use when working with security-basics patterns.

    2.8k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check: notes
  • Bagman

    LeoYeAI/openclaw-master-skills

    Secure key management for AI agents. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check: notes
  • Anth Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply Anthropic Claude API security best practices for key management, input validation, and prompt injection defense.

    2.8k GitHub stars~1.9k tokensUpdated today
    AI & LLM EngineeringAuto-check: notes
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 12 days ago
    SecurityAuto-check: notes

More from profbernardoj/everclaw-community-branches

All 12 skills in this repo
  • Memory Upgrade

    profbernardoj/everclaw-community-branches

    Diagnose and fix broken memory search in OpenClaw. An agent skill from profbernardoj/everclaw-community-branches.

    112 GitHub stars~574 tokensUpdated 1 mo ago
    Auto-check passed
  • Relationships

    profbernardoj/everclaw-community-branches

    Relationship CRM for tracking people, connections, and context.

    112 GitHub stars~765 tokensUpdated 1 mo ago
    Auto-check passed
  • Agent Chat

    profbernardoj/everclaw-community-branches

    XMTP real-time agent-to-agent and user-to-agent encrypted messaging daemon for EverClaw.

    112 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Night Shift

    profbernardoj/everclaw-community-branches

    Automated overnight task planning and execution engine for EverClaw.

    112 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Pii Guard

    profbernardoj/everclaw-community-branches

    Personally identifiable information (PII) leak prevention for EverClaw.

    112 GitHub stars~921 tokensUpdated 1 mo ago
    Auto-check passed
  • Xmtp Comms Guard

    profbernardoj/everclaw-community-branches

    Security middleware for all XMTP communications in EverClaw.

    112 GitHub stars~523 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Bagman

What does Bagman do?

Secure key management for AI agents. An agent skill from profbernardoj/everclaw-community-branches. Bagman is an agent skill from profbernardoj/everclaw-community-branches. Secure key management for AI agents.

When should I use Bagman?

Bagman fits situations like: handling private keys; wallet credentials; building systems that need agent-controlled funds.

How do I install Bagman in Claude Code?

Run `npx skills add profbernardoj/everclaw-community-branches --skill bagman -a claude-code`. Or copy the skill folder (skills/bagman in profbernardoj/everclaw-community-branches) into .claude/skills/bagman in your project. Claude Code loads it when a task matches its description.

How do I install Bagman in Codex?

Run `npx skills add profbernardoj/everclaw-community-branches --skill bagman -a codex`. Or copy the skill folder (skills/bagman in profbernardoj/everclaw-community-branches) into .agents/skills/bagman in your project. Codex loads it when a task matches its description.

Can I use Bagman in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add profbernardoj/everclaw-community-branches --skill bagman -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bagman, .gemini/skills/bagman, .github/skills/bagman and .opencode/skills/bagman in your project.

What does Bagman need to run?

Going by SKILL.md and its folder, Bagman needs Python and TypeScript for the scripts in its folder, the command-line tools its instructions call (python and brew) and credentials named PRIVATE_KEY, SESSION_KEY and OPENAI_API_KEY. Our summary lists: Python 3; Node.js; A credential in SESSION_KEY; A credential in PRIVATE_KEY.

Does Bagman access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Bagman safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): contains instruction-override wording (e.g. “without asking the user”). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Bagman use?

Bagman is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bagman use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Bagman?

Skills that share tags, products or a category with Bagman: Agent Security Manager (ruvnet/ruflo, 74k stars), Clade Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Bagman (LeoYeAI/openclaw-master-skills, 2.2k stars) and Anth Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bagman?

profbernardoj (a GitHub user) maintains it in profbernardoj/everclaw-community-branches, which has 112 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on September 2, 2026.

Source: profbernardoj/everclaw-community-branches on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.