← 返回 Skills 市场
zscole

Openclaw

作者 zscole · GitHub ↗ · v1.0.0
cross-platform ✓ 安全检测通过
3175
总下载
3
收藏
55
当前安装
1
版本数
在 OpenClaw 中安装
/install openclaw
功能描述
Secure key management for AI agents. Use when handling private keys, API secrets, wallet credentials, or when building systems that need agent-controlled funds. Covers secure storage, session keys, leak prevention, and prompt injection defense.
安全使用建议
Before installing, confirm you meant to install the Bagman/Openclaw key-management guide. Treat wallet, session-key, environment-variable, and git history-rewrite snippets as templates to adapt carefully, preferably with test funds, short-lived least-privilege credentials, human approval for transfers, monitoring, and coordinated incident-response procedures.
功能分析
Type: OpenClaw Skill Name: openclaw Version: 1.0.0 This skill bundle is entirely focused on implementing robust security measures for AI agents handling sensitive data. It provides comprehensive guidance and code examples for secure secret management (using 1Password CLI), preventing key leakage (output sanitization, git pre-commit hooks, .gitignore), and defending against prompt injection attacks (input validation, operation allowlisting, isolation). All instructions and code are designed to enhance agent security, with no evidence of malicious intent, data exfiltration, or unauthorized execution.
能力评估
Purpose & Capability
The artifact purpose is coherent: it teaches secure key, wallet, session-key, leak-prevention, and prompt-injection defense patterns. There is a naming mismatch between marketplace metadata using Openclaw and the artifact frontmatter/name Bagman, so users should verify they intended this specific skill.
Instruction Scope
The instructions include high-impact examples for secret retrieval, wallet session keys, environment injection, and git history rewrite. These are aligned with the security-training purpose, but several examples would benefit from stronger warnings and tighter scoping before production use.
Install Mechanism
The bundle contains markdown files only and declares the 1Password CLI as a required binary; it does not include executable install scripts, background workers, or automatic setup behavior.
Credentials
Use of 1Password, vaults, secret scanning, output sanitization, and session keys is proportionate to a key-management guide. Some fallback examples expose plaintext or environment-based secrets transiently, which is a documentation caution rather than hidden behavior.
Persistence & Privilege
The skill discourages storing raw keys in files, logs, or agent memory and recommends delegated session keys with expiry and revocation. Its incident-response git rewrite example is powerful and should be treated as destructive unless coordinated.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install openclaw
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /openclaw 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of Bagman: secure key management patterns for AI agents. - Introduces a framework for handling private keys, API secrets, and wallet credentials with robust leak prevention and prompt injection defenses. - Enforces session-based access using 1Password CLI, never storing raw keys in env files, config, or agent memory. - Provides validated workflows, code snippets, and architecture diagrams for agent wallet access and key lifecycle management. - Includes output sanitization routines and pre-commit git hooks to prevent accidental secret leaks. - Outlines input validation strategies and isolation patterns to defend against prompt injection.
元数据
Slug openclaw
版本 1.0.0
许可证
累计安装 58
当前安装数 55
历史版本数 1
常见问题

Openclaw 是什么?

Secure key management for AI agents. Use when handling private keys, API secrets, wallet credentials, or when building systems that need agent-controlled funds. Covers secure storage, session keys, leak prevention, and prompt injection defense. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 3175 次。

如何安装 Openclaw?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install openclaw」即可一键安装,无需额外配置。

Openclaw 是免费的吗?

是的,Openclaw 完全免费(开源免费),可自由下载、安装和使用。

Openclaw 支持哪些平台?

Openclaw 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Openclaw?

由 zscole(@zscole)开发并维护,当前版本 v1.0.0。

💬 留言讨论