keychain-access
Installation
SKILL.md
Keychain Access Skill
Manage macOS Keychain items in a safe, scriptable way. Use the bundled keychain-access/keychain-access.sh helper for all operations: it wraps security calls, enforces confirmations for updates and deletions, masks secrets unless explicitly requested, and supports dry-run previews.
Safety Constraints
- Never print secrets unless the user explicitly asks to reveal them (
--raw). Routinegetcalls only report metadata with the password hidden. - Ask the user to confirm before modifying or deleting existing entries. The script prompts by default and accepts
--yesto skip the prompt for automation. - Support a
--dry-runmode so agents can preview thesecuritycommand without touching the Keychain. - Supply secrets via
--password-stdin,--password-env, or the hidden interactive prompt. The legacy--passwordoption leaves values in shell history and process listings (the helper warns when it's used), so prefer the safer inputs;--password-env VARreads the var and unsets it immediately to keep the secret out of the environment. - Operate on a specific keychain when provided (
--keychain); otherwise, the default search list is used. Avoid leaking system passwords by defaulting to explicit service/account filters.