cloak-env-protectionProtect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
Install via ClawdBot CLI:
clawdbot install danieltamas/cloak-env-protectionGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://getcloak.dev/install.shAudited Apr 17, 2026 · audit v1.0
Generated Oct 2, 2026
Development teams using AI coding assistants (Claude, Cursor, Windsurf) need to provide real API keys for testing but don't want agents to access production credentials. Cloak lets agents see sandbox values while developers use real credentials via their editor extension.
DevOps teams running automated builds and deployments with AI agents need to ensure secrets are never exposed in logs or agent outputs. Cloak's sandbox values on disk allow safe agent interaction while real secrets are injected at runtime via `cloak run`.
Financial, healthcare, or government projects must demonstrate that secrets are never accessible to AI tools. Cloak provides a clear audit trail with authentication requirements (Touch ID/password) for any real secret access, satisfying compliance requirements.
Maintainers of open source projects want to protect contributor environments from accidental secret exposure when using AI agents to review or generate code. Cloak can be suggested as an optional security layer without disrupting normal contribution workflows.
Developers running multi-container applications locally with AI agents need real environment variables for services like databases and APIs. Cloak's `cloak run docker compose up` command injects secrets securely while agents only see sandbox values in the .env file.
Cloak is free for individual developers and small teams, with a paid Enterprise tier that includes priority support, advanced audit logging, and integration with enterprise identity providers (SSO, LDAP). Revenue comes from annual subscriptions for large organizations.
The Cloak VS Code/Cursor extension is free with basic functionality, but premium features like team sharing of vault configs, advanced secret rotation, and AI agent policies are unlocked via a paid subscription. Revenue is generated through in-app purchases and monthly plans.
A hosted version of Cloak that syncs vaults across team members and provides centralized management of secrets for distributed teams. The service handles key management, backup, and compliance reporting for a monthly per-user fee.
💬 Integration Tip
Add the SKILL.md content to your project's CLAUDE.md or .cursorrules file, and ensure Cloak is installed via the provided curl/PowerShell commands. The agent will automatically detect the .cloak marker and follow the protection rules.
Scored May 31, 2026
1Password Connect API skill. Use when working with 1Password Connect for activity, vaults, heartbeat. Covers 15 endpoints.
Complete guide for using pass, the standard Unix password manager. Use this skill whenever the user asks about pass, password-store, managing passwords from...
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/...
Rotate and update secrets in environment files, generate Vault commands, and manage secret rotation workflows.
Headless plugin for 1Password secrets using service accounts, resolving op:// references, reading/writing secrets, and listing vault items via JS SDK.
Secure credential exchange with auto-expiry for Pilot Protocol agents. Use this skill when: 1. You need to share API keys, tokens, or credentials securely be...