Token导航 LogoToken导航TokenDH.com
研究检索敏感数据clawhub未标认证来源可访问clear审计提醒

vaultwarden-skill金库看守技能

Agent Skill

vaultwarden-skill 用于查找、检索和筛选相关信息,适合在 OpenClaw 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

3,326

周安装

140

GitHub Stars

公开资料未说明

下载量

1,165
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:vaultwarden-skill(金库看守技能)
来源仓库:https://github.com/mbojer/vaultwarden-skill
安装命令:
openclaw skills install vaultwarden-skill
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install vaultwarden-skill

简介

使用包装器脚本管理 Vaultwarden 机密,用于集合或个人保管库中的会话处理、缓存、日志记录和范围读/写操作。

SKILL.md

Vaultwarden Skill

Manage secrets in Vaultwarden via wrapper scripts. All scripts handle session state, caching, logging, and error handling — do not call bw directly.

CLI Version Requirement — CRITICAL

Bitwarden CLI 2024.x+ breaks Vaultwarden authentication with User Decryption Options are required.

# Install the required version
npm install -g @bitwarden/cli@2023.10.0

# Verify
bw --version  # must show 2023.10.0

vw-unlock.sh will hard-exit if an incompatible version is detected.

Setup (run once)

bw config server https://vaultwarden.mbojer.dk

Required Environment Variables

Set in OpenClaw config, never stored in vault:

VariablePurpose
BW_CLIENTIDAPI key client ID
BW_CLIENTSECRETAPI key client secret
BW_PASSWORDMaster password for unlock
VW_COLLECTION_NAMECollection name to scope to (default: openclaw) — org accounts only
VW_COLLECTION_IDHardcode collection ID — use if name lookup fails (org accounts only)
VW_SESSION_DIRSession token dir (default: /run/openclaw/vw)
VW_LOG_FILEAudit log path (default: /var/log/openclaw/vaultwarden.log)
VW_CACHE_TTLRead cache TTL in seconds (default: 60, set 0 to disable)

Collection Scoping — Personal vs Org Vaults

Personal Vaultwarden accounts cannot access collections via API key — this is a Bitwarden limitation, not a bug in this skill. bw list collections returns [] on personal vaults.

The skill handles this automatically: if no collection is found, all operations fall back to unscoped (full vault) queries. For org accounts, set VW_COLLECTION_NAME or VW_COLLECTION_ID to scope operations to a specific collection.

Session Management

vw-unlock.sh    # authenticate and unlock — run before any vault operation
vw-lock.sh      # lock vault and clear all caches
vw-status.sh    # check connection and session state
vw-sync.sh      # sync local cache with server — run if vault modified externally

Session token stored in $VW_SESSION_DIR/.bw_session (chmod 600). Collection ID cached in $VW_SESSION_DIR/.collection_id — invalidated on lock and sync. Read cache stored in $VW_SESSION_DIR/cache/ — TTL controlled by VW_CACHE_TTL.

Read Operations

All reads are collection-scoped to $VW_COLLECTION_NAME. Frequently-read items are cached with a TTL to reduce API calls.

vw-list.sh [query]               # list items in openclaw collection, optional search
vw-get.sh <name|id>              # full item JSON
vw-get-pass.sh <n>               # password only (collection-scoped, cached)
vw-get-user.sh <n>               # username only (collection-scoped, cached)
vw-get-field.sh <n> <field>      # single custom field value
vw-get-totp.sh <n>               # current TOTP code (not cached — codes expire)

Write Operations

Write operations invalidate the read cache automatically.

echo <pass> | vw-create-login.sh <n> <user>     # create login item (password via stdin)
echo <content> | vw-create-note.sh <n>           # create secure note (content via stdin)
echo <value> | vw-update.sh <id> <field>         # update field: password|username|notes|custom:<n>
vw-delete.sh <id> <expected name>                # move to trash — requires both ID and name to match
vw-rotate-pass.sh <name|id> [length]             # generate new password and update atomically

Capture rotated password cleanly (status goes to stderr):

NEW_PASS=$(vw-rotate-pass.sh "MyService")

Rules

  • Always run vw-unlock.sh before vault operations, vw-lock.sh when done
  • Run vw-sync.sh before reads if vault was modified via web UI or another client
  • Always use item ID (not name) for vw-update.sh and vw-delete.sh
  • vw-delete.sh moves items to trash — not permanent. Empty trash via web UI if needed
  • All secret values must be passed via stdin — never as CLI arguments
  • Never log or output raw secret values — only names, IDs, and operation results
  • If any script exits non-zero, stop and report — do not retry silently
  • All operations are scoped to $VW_COLLECTION_NAME when a collection is available. Personal vaults (no org) fallback to full vault — no collection required

Error Reference

ErrorFix
bw CLI X.X.X is incompatiblenpm install -g @bitwarden/cli@2023.10.0
User Decryption Options are requiredSame as above — wrong CLI version
no active sessionRun vw-unlock.sh
session invalid or expiredRun vw-unlock.sh
collection not foundCheck VW_COLLECTION_NAME, run vw-sync.sh
name mismatchVerify item ID with vw-get.sh before deleting
custom field does not existCheck field name with vw-get.sh
server not configuredRun bw config server https://vaultwarden.mbojer.dk
API key login failedCheck BW_CLIENTID and BW_CLIENTSECRET

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

98.82%
按下载量换算1,151

安全审计

VirusTotal

未展示

ClawScan

可疑

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills