secrets-hygiene

Installation
SKILL.md

Secrets Hygiene

State file: ~/.openclaw/skill-state/secrets-hygiene/state.yaml

Credentials you forgot about are credentials that will leak.

When to Use

  • On Monday 9am cron wakeup
  • When adding or removing a skill that uses credentials
  • After any suspected security incident

The Audit Process

Step 1: Inventory

List all secrets currently configured in OpenClaw (env vars, config files, keychain entries referenced by installed skills). For each, record: name, which skills access it, when it was last rotated (if known).

Step 2: Flag Stale Secrets

A secret is stale if:

Related skills
Installs
16
GitHub Stars
61
First Seen
Mar 21, 2026