agentlair-vaultStore and fetch credentials securely at runtime via AgentLair Vault REST API. Use when an agent needs to read an API key, store a secret, rotate credentials,...
Install via ClawdBot CLI:
clawdbot install hawkaa/agentlair-vaultGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://agentlair.dev/v1/auth/keysCalls external URL not in known-safe list
https://agentlair.devAI Analysis
The skill's external API calls are consistent with its stated purpose of secure credential management, and the only data sent appears to be for legitimate vault operations. However, it does send data to an external service not on a known-safe list, which introduces a dependency and potential privacy consideration.
Audited Apr 17, 2026 · audit v1.0
Generated Aug 1, 2026
An AI agent needs to access multiple third-party APIs (e.g., OpenAI, Stripe, Slack) securely. Using AgentLair Vault, the agent fetches credentials at runtime without exposing them in config files or environment variables, reducing security risks and simplifying key rotation.
In a DevOps pipeline, automated scripts and agents require database passwords, deployment tokens, and cloud credentials. By storing these secrets in AgentLair Vault and retrieving them during builds, teams avoid hardcoding secrets in version control and can rotate them easily without pipeline changes.
Financial applications handle sensitive customer data and require strict security controls. Using AgentLair Vault, an agent can securely store and access banking API keys and transaction signing secrets, ensuring compliance with regulations and enabling audit trails.
A SaaS platform that integrates with customer-specific services (e.g., CRM, email) can use AgentLair Vault to store each customer's API keys individually. The agent retrieves the relevant key per tenant, ensuring isolation and preventing cross-tenant data leaks.
Security teams need to regularly rotate credentials to minimize breach impact. With AgentLair Vault's rotation capability, an agent can automatically update keys and secrets for various services, maintaining security posture without manual intervention.
Offer basic vault features free with limits, and charge for higher tiers with more keys, higher request rates, and advanced features like version history and audit logs. Revenue comes from subscription fees for premium plans.
Provide a self-hosted or on-premises version of AgentLair Vault with advanced security, compliance, and integration capabilities. Revenue generated through annual licensing fees and support contracts.
Charge based on API requests, number of secrets stored, or data transfer. This model is attractive for organizations with fluctuating needs, letting them pay for what they use.
💬 Integration Tip
To integrate AgentLair Vault, simply set the AGENTLAIR_API_KEY environment variable and use curl commands to store/fetch secrets. No complex SDKs required; integrate within minutes.
Scored Aug 1, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...