Skip to content
Back to skills

Secretclaw

ASecurity

Securely input API keys and sensitive values into OpenClaw without typing them in chat. Uses a local HTTP server + Cloudflare Tunnel to serve an HTTPS form. Use when registering API keys, tokens, passwords, or any sensitive config values.

  • 33 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 30, 2026
securitypythonbashnodeapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned May 30, 2026

npx -y skills add dvcrn/openclaw-skills-marketplace --skill secretclaw --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Secretclaw?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Secretclaw
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dvcrn-secretclaw/badge)](https://www.skillsdirectory.com/skills/dvcrn-secretclaw)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: secretclaw
description: "Securely input API keys and sensitive values into OpenClaw without typing them in chat. Uses a local HTTP server + Cloudflare Tunnel to serve an HTTPS form. Use when registering API keys, tokens, passwords, or any sensitive config values."
---

# SecretClaw

A skill for securely inputting secret keys and sensitive values without passing them through Discord or any chat channel.

Uses a local HTTP server + Cloudflare Tunnel to serve an HTTPS form page,
then saves the submitted value via `openclaw config set`.

## When to Use

- When registering API keys, tokens, passwords, or other sensitive values
- To avoid typing secrets directly in chat
- Examples: FAL_KEY, Notion API key, OpenAI key, etc.

## Active Tunnels

→ See `workspace/TUNNELS.md` (managed automatically by the agent)

## Usage

```bash
python3 <skill_dir>/scripts/secret_server.py \
  --config-key "env.FAL_KEY" \
  --label "FAL_KEY"
```

### Parameters
- `--config-key`: openclaw config path (dot notation)
  - e.g.: `env.FAL_KEY`, `env.OPENAI_KEY`, `channels.discord.token`
- `--label`: Human-readable name displayed on the form
- `--service`: Service name recorded in TUNNELS.md (default: `secret-input`)

## Agent Execution Steps

1. Run the command below as a background exec
2. Extract the `SECRET_URL:` line from stdout → send the URL to the user
3. When `SECRET_SAVED:` appears, the value has been saved
4. Check if a gateway restart is needed (some keys require restart)

```python
# Example background exec
python3 /opt/homebrew/lib/node_modules/openclaw/skills/secret-input/scripts/secret_server.py \
  --config-key "env.FAL_KEY" \
  --label "FAL_KEY"
```

## TUNNELS.md Structure

Active tunnel info is recorded in `workspace/TUNNELS.md`.
The agent reads this file to check currently open tunnel URLs.
Entries are automatically removed when the server shuts down.

## Security

- No secret values are ever stored in chat history
- HTTPS via Cloudflare TLS (Quick Tunnel)
- One-time token embedded in URL (cryptographically random)
- Server self-destructs immediately after submission
- Uses Cloudflare Quick Tunnel (no account required; URL changes on every run)

## Notes

- If the machine reboots, the server shuts down and the Cloudflare URL becomes invalid
- To re-enter a value, simply run the skill again to generate a new URL
- TUNNELS.md only tracks currently active tunnels (not historical URLs)

Files in this skill

  • README.md1.9 KB
  • SKILL.md2.4 KB
  • scripts/secret_server.py8.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…