locker-vaultSecure credential and secrets management for OpenClaw agents using Locker Secrets Manager. Provides read-only and read-write vault access with in-memory cach...
Install via ClawdBot CLI:
clawdbot install moskoweb/locker-vaultGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
curl -fsSL https://locker.io/secrets/install.sh | bashCalls external URL not in known-safe list
https://locker.io/secrets/install.shUses known external API (expected, informational)
api.anthropic.comAI Analysis
The skill's core purpose is legitimate secrets management, and the external API (api.anthropic.com) is expected for an AI agent. However, the tool definition includes an unsafe shell command (piping curl to bash) to install an external service, which is a medium-risk security practice that could be exploited if the external URL were compromised.
Generated Apr 9, 2026
A customer-facing AI agent uses this skill to securely access API keys for third-party services like CRM systems or ticketing platforms. It retrieves credentials via vault references to authenticate API calls without exposing secrets in logs, ensuring sensitive data remains protected while providing real-time support.
An admin agent in a CI/CD pipeline uses read-write mode to rotate database passwords and update webhook secrets automatically. It caches credentials to reduce latency during deployments, ensuring secure and efficient management of infrastructure secrets without manual intervention.
An agent handling order fulfillment accesses payment gateway tokens and shipping API keys stored in the vault. By using cached reads, it speeds up transaction processing while adhering to strict security protocols, preventing credential leakage in transaction logs.
A monitoring agent securely retrieves database connection strings and API tokens for syncing patient records between systems. It operates in read-only mode to comply with regulatory standards like HIPAA, ensuring sensitive health data is accessed only through vault references.
An agent scheduled via cron jobs uses this skill to fetch credentials for banking APIs and generate financial reports. It leverages caching to handle frequent data pulls efficiently, maintaining security by storing only vault item IDs in job configurations.
Offer this skill as part of a premium tier for AI agent platforms, charging monthly fees based on the number of vault accesses or stored secrets. Revenue comes from enterprises needing secure, scalable credential management for their automated workflows.
Provide custom integration services to businesses adopting this skill, including setup, training, and ongoing support. Revenue is generated through project-based fees and retainer contracts for maintaining secure credential systems.
Offer a free version with basic read-only vault access and limited cache TTL, while charging for advanced features like read-write mode, longer TTLs, and priority support. Revenue streams from upgrades and enterprise licenses.
💬 Integration Tip
Ensure the Locker CLI is installed on the host and configure VAULT_MODE appropriately based on agent permissions to avoid errors during write operations.
Scored Apr 19, 2026
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...