Agent skill

API Credentials Hygiene

by sundial-org in sundial-org/awesome-openclaw-skills

Audits and hardens API credential handling (env vars, separation, rotation plan, least privilege, auditability).

No licenceAuto-check: notesDevOps & Cloud

Install API Credentials Hygiene

skills CLI
$ npx skills add sundial-org/awesome-openclaw-skills --skill api-credentials-hygiene -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sundial-org/awesome-openclaw-skills api-credentials-hygiene --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sundial-org/awesome-openclaw-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-credentials-hygiene .claude/skills/api-credentials-hygiene && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-credentials-hygiene
GitHub stars
663
Token cost
~919 tokens
SKILL.md length
411 words
Files
2 (incl. assets)
Skills in repo
353
Repo updated
First seen
Licence
None found

At a glance

Audits and hardens API credential handling (env vars, separation, rotation plan, least privilege, auditability).

  • Works in 7 steps: Inventory credentials → Define separation → Move secrets to env vars / secret… → …
  • Integrating services
  • SKILL.md covers PURPOSE, WHEN TO USE, INPUTS and OUTPUTS, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

API Credentials Hygiene is an agent skill from sundial-org/awesome-openclaw-skills. Audits and hardens API credential handling (env vars, separation, rotation plan, least privilege, auditability). Use when integrating services or preparing production deployments where secrets must be managed safely.

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including assets (for example `assets/dotenv-template.example.md`).

It sits in DevOps & Cloud, covering Deployment. It works with n8n. The repository describes itself as: Top OpenClaw skills, with the most popular and useful ones.

When your agent uses it

  • Integrating services
  • Preparing production deployments where secrets must be managed safely

Example prompts

  • “Use the api-credentials-hygiene skill to audit and hardens API credential handling (env vars, separation, rotation plan, least privilege…”
  • “/api-credentials-hygiene”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Inventory credentials
  2. Define separation
  3. Move secrets to env vars / secret manager references
  4. Least privilege
  5. Rotation plan
  6. Auditability
  7. STOP AND ASK THE USER if

What it can do on your machine

Read from SKILL.md and the folder at commit b80cde2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Credentials Hygiene loads about 919 tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 411 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~919

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:16
    an environment variable map and a secure .env template for this project.
  • NoteMentions a .env fileSKILL.md:27
    Current config files/redacted snippets (.env, compose, systemd, n8n creds list).
  • NoteMentions a .env fileSKILL.md:37
    - Optional: `.env` template (placeholders only).

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 411 words (~919 tokens).

“Audits and hardens API credential handling (env vars, separation, rotation plan, least privilege, auditability).”

— opening of SKILL.md by sundial-org
name
api-credentials-hygiene

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file (assets) in skills/api-credentials-hygiene of sundial-org/awesome-openclaw-skills.

  • SKILL.md
  • assets/dotenv-template.example.md

Open the folder on GitHubat commit b80cde2

Compare with similar skills

API Credentials Hygiene next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Credentials Hygiene compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Credentials Hygiene this skillsundial-org/awesome-openclaw-skills663—~919Automated safety check: NotesNone
Self-Hosted n8n Deploymentczlonkowski/n8n-skills6.4k—~3.5kAutomated safety check: NotesMIT
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
KubeSphere ServiceMesh Managerkubesphere/kubesphere17k—~2.4kAutomated safety check: PassCustom licence
Vercelremotion-dev/remotion62k—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Self-Hosted n8n Deployment

    czlonkowski/n8n-skills

    Deploys a production n8n instance to a fresh Linux server over SSH with Docker Compose and Caddy HTTPS, in single or queue mode, and covers updates, backups and hardening.

    6.4k GitHub stars~3.5k tokensUpdated 22 days ago
    DevOps & CloudAuto-check: notes
  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Vercel

    remotion-dev/remotion

    Official

    Set up a Codex monitor for Vercel deployments and preview URLs.

    62k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed

More from sundial-org/awesome-openclaw-skills

All 353 skills in this repo
  • UI UX Pro Max

    sundial-org/awesome-openclaw-skills

    UI/UX design intelligence and implementation guidance for building polished interfaces.

    663 GitHub starsUsed in 2 repos~657 tokens
    Auto-check passed
  • Web Deploy GitHub

    sundial-org/awesome-openclaw-skills

    Create and deploy single-page static websites to GitHub Pages with autonomous workflow.

    663 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Clawd Modifier

    sundial-org/awesome-openclaw-skills

    Modify Clawd, the Claude Code mascot. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~625 tokensUpdated 7 mo ago
    Auto-check passed
  • Figma

    sundial-org/awesome-openclaw-skills

    Professional Figma design analysis and asset export. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~1.7k tokensUpdated 7 mo ago
    Auto-check: notes
  • Edge Tts

    sundial-org/awesome-openclaw-skills

    Text-to-speech conversion using node-edge-tts npm package for generating audio from text.

    663 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Habit Flow

    sundial-org/awesome-openclaw-skills

    AI-powered atomic habit tracker with natural language logging, streak tracking, smart reminders, and coaching.

    663 GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed

Works with

Categories

Questions about API Credentials Hygiene

What does API Credentials Hygiene do?

Audits and hardens API credential handling (env vars, separation, rotation plan, least privilege, auditability). API Credentials Hygiene is an agent skill from sundial-org/awesome-openclaw-skills. Audits and hardens API credential handling (env vars, separation, rotation plan, least privilege, auditability).

When should I use API Credentials Hygiene?

API Credentials Hygiene fits situations like: integrating services; preparing production deployments where secrets must be managed safely.

How do I install API Credentials Hygiene in Claude Code?

Run `npx skills add sundial-org/awesome-openclaw-skills --skill api-credentials-hygiene -a claude-code`. Or copy the skill folder (skills/api-credentials-hygiene in sundial-org/awesome-openclaw-skills) into .claude/skills/api-credentials-hygiene in your project. Claude Code loads it when a task matches its description.

How do I install API Credentials Hygiene in Codex?

Run `npx skills add sundial-org/awesome-openclaw-skills --skill api-credentials-hygiene -a codex`. Or copy the skill folder (skills/api-credentials-hygiene in sundial-org/awesome-openclaw-skills) into .agents/skills/api-credentials-hygiene in your project. Codex loads it when a task matches its description.

Can I use API Credentials Hygiene in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sundial-org/awesome-openclaw-skills --skill api-credentials-hygiene -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-credentials-hygiene, .gemini/skills/api-credentials-hygiene, .github/skills/api-credentials-hygiene and .opencode/skills/api-credentials-hygiene in your project.

What does API Credentials Hygiene need to run?

SKILL.md names no scripts, command-line tools or credentials: API Credentials Hygiene is instructions for the agent only.

Does API Credentials Hygiene access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Credentials Hygiene safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does API Credentials Hygiene use?

No licence was found for API Credentials Hygiene or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does API Credentials Hygiene use?

About 919 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Credentials Hygiene?

Skills that share tags, products or a category with API Credentials Hygiene: Self-Hosted n8n Deployment (czlonkowski/n8n-skills, 6.4k stars), Kubeshark Installer (kubeshark/kubeshark, 12k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars) and KubeSphere ServiceMesh Manager (kubesphere/kubesphere, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Credentials Hygiene?

sundial-org (a GitHub organization) maintains it in sundial-org/awesome-openclaw-skills, which has 663 GitHub stars. The repository holds 353 skills in this directory. The repository was last updated on March 7, 2026.

Source: sundial-org/awesome-openclaw-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.