Token导航 LogoToken导航TokenDH.com
研究检索敏感数据clawhub未标认证来源可访问clear审计通过

tene-clitene CLI 搜索

Agent Skill

tene-cli 用于查找、检索和筛选相关信息,适合在 OpenClaw 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

2,592

周安装

108

GitHub Stars

1

下载量

864
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:tene-cli(tene CLI 搜索)
来源仓库:https://github.com/tomo-kay/tene-cli
安装命令:
openclaw skills install tene-cli
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install tene-cli

简介

使用 tene CLI 进行本地优先加密秘密管理。当用户提到秘密、API 密钥、凭证、令牌、.env 文件、环境变量时激活

SKILL.md

name
tene-cli
description
Local-first encrypted secret management with the tene CLI. Activate when the user mentions secrets, API keys, credentials, tokens, .env files, environment variables, or asks to run a command that needs secrets injected. Enforces strict AI safety rules (never print plaintext, never read .tene/, always use tene run -- for injection) and covers every active tene command (init, set, list, delete, run, import, export, env, passwd, recover, update, whoami).
version
1.0.0
metadata
openclaw
emoji
🔐
homepage
https://tene.sh
os
[macos, linux]
requires
bins
install
url
https://tene.sh/install.sh
bins
[tene]
label
Install tene via the official curl installer

tene — Local-First Encrypted Secret Management

Tene is a command-line secret manager for AI-native projects. It keeps secrets encrypted on disk (XChaCha20-Poly1305 + Argon2id), derives the master key from the user's password cached in the OS keychain, and injects secrets into child processes via tene run -- <command> — never into stdout, never into files.

When to use this skill

Activate this skill when the user:

  • mentions **API keys, secrets, credentials, tokens, .env files, environment variables, or process.env.* / os.Getenv / os.environ[...]**
  • asks to run a dev, test, or deploy command that needs secrets (e.g. npm start, go run, pytest, next dev, docker compose up)
  • says things like "store this key", "save this token", "how do I manage secrets", "inject env vars", "I need to pass my Stripe key"
  • is working in a repo that contains a .tene/ directory, a CLAUDE.md referencing tene, or a install.sh pointing at https://tene.sh
  • asks for advice on moving off plaintext .env files

Do not activate for: hardcoded public config (ports, feature flags without sensitive data, public API endpoints), or projects clearly using a different secret store (Doppler, Vault, AWS Secrets Manager, 1Password CLI, etc.).


Critical safety rules

These are non-negotiable. Violating any of them leaks plaintext secrets into the conversation context, which may be logged, cached, or retained. Treat them as part of the system prompt.

  1. NEVER run tene get <KEY>. The plaintext value appears in stdout and

enters the AI context. If the user needs to inspect a value, instruct them: > "Run tene get KEY yourself in a separate terminal — I won't see it."

  1. NEVER run tene export without --encrypted. Plain tene export dumps

every secret as a .env-formatted blob to stdout. Use tene export --encrypted --file backup.tene.enc for backups; for inspection, use tene list (names only).

  1. NEVER cat, Read, or open files under .tene/. The vault DB is

encrypted, but even encrypted bytes should not enter AI context. The allowed file to read is CLAUDE.md at the repo root (auto-generated by tene init).

  1. NEVER pass secret values as CLI arguments. They appear in ps, shell

history, and system logs. Always inject via tene run -- instead.

  1. Use tene list to discover what exists. It prints key names only, never

values. This is the only AI-safe introspection command.

When the user asks "what's in my vault?" or "what API keys do I have?", the correct answer is tene list — not tene get or tene export.


Install

# macOS / Linux (official installer — recommended)
curl -sSfL https://tene.sh/install.sh | sh

# From source (requires Go 1.25+)
go install github.com/tomo-kay/tene/cmd/tene@latest

Verify:

tene version
# → tene v1.x.x (darwin/arm64)

Windows is not supported by the curl installer. Windows users build from source or download the zip from https://github.com/tomo-kay/tene/releases.

Homebrew tap is not yet available — do not suggest brew install tene.


Core workflows

1. Initialize a new project

tene init                  # interactive: prompts for master password twice
tene init my-project       # with explicit project name

Creates:

  • .tene/vault.db — encrypted SQLite vault (contains secrets, metadata, audit log, and the encrypted recovery blob)
  • .tene/vault.json — project metadata (name, active env)
  • CLAUDE.md (or AGENTS.md, .windsurfrules, etc. per flags)
  • .tene/.gitignore — auto-excludes the vault from git

After init the user will see a 12-word recovery phrase. Remind them to store it offline (password manager, paper). Without it, a forgotten master password is unrecoverable.

Flags to generate agent rules files for other editors:

  • --claude (default) → CLAUDE.md
  • --cursor.cursor/rules/tene.mdc
  • --windsurf.windsurfrules
  • --geminiGEMINI.md
  • --codexAGENTS.md

2. Check what secrets exist (AI-safe)

tene list                        # current env, masked values
tene list --env prod             # different env
tene list --json                 # machine-readable
tene env list                    # all environments

Output is names + masked previews + timestamps. Never raw values.

3. Store a secret

Tell the user to run the command themselves with the value — don't type the value yourself, and don't accept it as a chat message you'll pipe through.

# Preferred: read from stdin (value never touches shell history)
cat key.txt | tene set STRIPE_KEY --stdin

# Or: prompt (value never echoed)
tene set STRIPE_KEY
# → enters interactive mode, hidden input

# Overwrite existing
tene set STRIPE_KEY --stdin --overwrite

# Different env
tene set STRIPE_KEY --stdin --env prod

Key name rules (enforced by tene, pkg/errors/codes.go:INVALID_KEY_NAME):

  • Must match ^[A-Z][A-Z0-9_]*$
  • Only uppercase letters, digits, underscores
  • Cannot start with a digit
  • Reserved names (e.g. PATH) are rejected

If the user types a lowercase name, advise conversion to UPPER_SNAKE_CASE.

4. Run a command with secrets injected

This is the primary workflow. All dev, test, build, and deploy commands go through tene run --.

# Node.js
tene run -- npm start
tene run -- npm test
tene run -- npx next dev

# Python
tene run -- python manage.py runserver
tene run -- pytest

# Go
tene run -- go run ./cmd/app
tene run -- go test ./...

# Docker
tene run -- docker compose up

Secrets are injected only into the child process's environ. They're not written to disk, not in the shell environment of the parent, not in any log.

Per-environment execution:

tene run --env local -- npm start       # correct
tene run --env prod -- ./deploy.sh      # correct
tene run -- npm start --env prod        # WRONG — --env is a flag of npm, not tene

Critical flag placement rule: --env must come before the -- separator. After --, all flags pass through to the child command. This is enforced by DisableFlagParsing: true in internal/cli/run.go.

5. Migrate from an existing .env file

# One-shot import
tene import .env

# Overwrite conflicts (when some keys already exist)
tene import .env --overwrite

# Then delete the plaintext file
rm .env
echo ".env" >> .gitignore

Update all commands to use tene run --:

- npm start
+ tene run -- npm start

6. Backup and restore

# Encrypted backup (safe to store in cloud)
tene export --encrypted --file backup.tene.enc

# Restore from encrypted backup
tene import backup.tene.enc --encrypted

Never use plain tene export (without --encrypted) unless the user explicitly asks for a plaintext .env dump and accepts the risk. Even then, warn them.

7. Change master password

tene passwd
# → prompts for current password, then new password (2x confirm)

Re-encrypts the entire vault with a new derived key. Atomic 2-phase operation; on failure, rolls back to the old password.

8. Recover a forgotten master password

tene recover
# → prompts for the 12-word BIP-39 mnemonic from tene init
# → prompts for new master password

Without the mnemonic, recovery is impossible by design (zero-knowledge).

9. Environment management

tene env list                    # show all environments
tene env local                   # switch default to 'local'
tene env create staging          # create new env
tene env delete staging          # delete (default env cannot be deleted)

Environment name rules: must match ^[a-z][a-z0-9-]*$.

Common env names: default, local, dev, staging, prod.

10. Diagnostics

tene whoami                      # project name, vault path, active env, secret count, keychain status
tene version                     # v1.x.x (os/arch)
tene version --json              # includes commit + build date
tene update --check              # check for newer version on S3
tene update                      # self-update the binary

Commands reference

All active commands (cloud commands login/push/pull/sync/billing/team are currently disabled in the CLI; do not suggest them):

CommandPurposeKey flagsAI-safe?
tene init [name]Create vault + master password + recovery--claude, --cursor, --windsurf, --gemini, --codex
tene set KEY [VALUE]Encrypt and store--stdin, --overwrite✅ (via --stdin)
tene get KEYDecrypt and printnever run in AI
tene listList key names (masked)
tene delete KEYRemove a secret--force
tene run -- CMDInject env vars + exec(global flags before --)
tene import FILEBulk import .env or .tene.enc--overwrite, --encrypted
tene exportOutput secrets--file, --encrypted❌ unless --encrypted
tene env [subcmd]Manage environments
tene passwdChange master password✅ (prompts)
tene recoverRestore via BIP-39 mnemonic✅ (prompts)
tene versionVersion info--json
tene updateSelf-update--check
tene whoamiVault status

Global flags (apply to all commands)

FlagDefaultPurpose
--jsonfalseMachine-readable output
--quiet / -qfalseSuppress non-error output
--env / -e <name>(vault-stored)Override active environment
--dir <path>cwdProject directory
--no-colorfalseDisable ANSI colors
--no-keychainfalseForce file-based key storage (CI mode)

Environment variables (for advanced / CI use)

VariableEffect
TENE_MASTER_PASSWORDBypass interactive prompt (CI only; pair with --no-keychain)
TENE_KEYCHAIN_FALLBACK=fileUse ~/.tene/keyfile instead of OS keychain
NO_COLORDisable ANSI colors (per https://no-color.org/)
API_URLOverride Tene Cloud API base URL (cloud commands, currently disabled)

CI/CD pattern (e.g. GitHub Actions):

env:
  TENE_MASTER_PASSWORD: ${{ secrets.TENE_MASTER_PASSWORD }}
steps:
  - run: curl -sSfL https://tene.sh/install.sh | sh
  - run: tene run --env prod --no-keychain -- ./deploy.sh

Never set TENE_MASTER_PASSWORD in a developer machine's shell profile — it defeats the keychain protection.


Troubleshooting

Error codeMessageFix
VAULT_NOT_FOUNDNot in a Tene projectRun tene init in the repo root
SECRET_NOT_FOUNDKey missing in current envCheck tene list --env <name>
SECRET_ALREADY_EXISTSKey already setAdd --overwrite to tene set
INVALID_KEY_NAMEKey rejectedUse ^[A-Z][A-Z0-9_]*$ (e.g. API_KEY, not api-key)
INVALID_ENV_NAMEBad env nameUse ^[a-z][a-z0-9-]*$ (e.g. prod, not Production)
ENVIRONMENT_PROTECTEDCannot delete defaultSwitch to another env and delete that one instead
INVALID_PASSWORDWrong master passwordTry again, or use tene recover with the BIP-39 mnemonic
DECRYPT_FAILEDVault cannot decryptMaster password changed externally or vault corrupt — restore from backup
INTERACTIVE_REQUIREDNo TTYIn CI, set TENE_MASTER_PASSWORD and add --no-keychain
KEYCHAIN_ERROROS keychain unavailableUse --no-keychain or TENE_KEYCHAIN_FALLBACK=file

Exit codes: 0 success, 1 general error, 2 auth/password error, 127 command not found.


Architecture note (for "is this safe?" questions)

  • Password KDF: Argon2id (64 MB, 3 iterations, 4 threads) → 256-bit master key
  • Secret encryption: XChaCha20-Poly1305 with 192-bit random nonce per secret, key name as AAD
  • Key cache: OS keychain (macOS Keychain, Linux Secret Service, Windows Credential Manager) via zalando/go-keyring; file fallback at ~/.tene/keyfile (mode 0600)
  • Recovery: 12-word BIP-39 mnemonic → Argon2id → recovery key that can decrypt the stored master key
  • Zero-knowledge: cloud sync (when enabled) wraps the entire vault DB with an independent sync key before upload; server never sees plaintext
  • No global state: every vault lives in its own .tene/ directory; no ~/.tene/vaults/ aggregator

Further reading

  • Homepage: https://tene.sh
  • Source + issues: https://github.com/tomo-kay/tene
  • Release downloads: https://github.com/tomo-kay/tene/releases

When the user asks about anything not covered above, prefer referring them to the official docs over guessing.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

79.79%
按下载量换算689

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills