cloakShare one-time secrets between humans and agents via encrypted self-destructing links
Install via ClawdBot CLI:
clawdbot install saba-ch/cloakGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://cloak.opsy.sh/api/secretsCalls external URL not in known-safe list
https://cloak.opsy.shAI Analysis
The skill's external API usage is fully documented and consistent with its stated purpose of sharing one-time secrets. While it sends data to an external server not on a pre-approved list, the documentation explicitly warns against echoing secrets and emphasizes secure handling, showing no signs of credential harvesting or hidden malicious instructions.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Development teams can share API keys or tokens for third-party services securely without exposing them in chat logs or emails. The secret self-destructs after retrieval, ensuring it's only accessible once, reducing the risk of unauthorized access or leaks in collaborative environments.
IT support staff can send temporary passwords or access credentials to users for account recovery or system onboarding. The one-time link ensures credentials are not stored or visible after use, enhancing security during helpdesk operations and compliance with data protection policies.
Financial analysts can share sensitive data like transaction IDs or account numbers with auditors or clients via encrypted links. The self-destructing feature prevents data retention, aligning with regulatory requirements such as GDPR or PCI DSS for secure, ephemeral communication.
Healthcare providers can transmit patient identifiers or medical record access codes to authorized personnel for time-sensitive consultations. The secret is destroyed after retrieval, minimizing exposure of protected health information (PHI) and supporting HIPAA compliance in telemedicine workflows.
DevOps engineers can embed secrets like database passwords or encryption keys into CI/CD pipelines without hardcoding them. By retrieving secrets via Cloak during deployment, it ensures secure, automated environment setup while maintaining audit trails and reducing manual handling risks.
Offer a free tier with basic features like limited TTL or secret size, and charge for premium plans with extended retention, higher usage limits, or team management tools. Revenue comes from monthly subscriptions, targeting small to medium businesses needing enhanced security.
Provide on-premise or private cloud deployments with custom integrations, SLAs, and dedicated support for large organizations. Revenue is generated through annual licensing fees, consulting services, and maintenance contracts, focusing on industries with strict compliance needs like finance or healthcare.
Monetize the Cloak API by charging per API call or data volume, with tiered pricing for developers and businesses integrating it into their applications. Revenue streams include pay-as-you-go fees and bulk usage discounts, appealing to tech startups and SaaS platforms.
💬 Integration Tip
Use environment variables for API keys in scripts to avoid hardcoding, and automate secret retrieval in deployment pipelines with tools like curl and jq for seamless integration.
Scored Jun 17, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...