3.4k Downloads
Overview
Provide programmatic access to a Bitwarden/Vaultwarden vault via the `rbw` CLI so agents can list, search, retrieve, add, and sync vault items on a local machine.
Key Advantages
1.Leverages the mature `rbw` CLI rather than reimplementing Bitwarden APIs, benefiting from existing security and feature set.
2.Supports both Bitwarden’s cloud service and self‑hosted Vaultwarden instances via configurable base URL.
3.Enables end‑to‑end local execution using `exec`, avoiding direct exposure of secrets to external web services beyond the configured OpenClaw/runtime environment.
4.Covers core vault operations: listing items, targeted retrieval (including full JSON), search, add, and sync.
5.Designed to work with `pinentry-curses` and `tmux` to handle master password / 2FA unlock flows in a terminal-only environment.
Use Cases
- Automated retrieval of credentials (usernames, passwords, API keys) for development scripts or CLI workflows on a secure personal machine.
- Quick search and lookup of vault entries by name or query from within an automated agent flow.
- Keeping a local environment’s credentials up to date by running `rbw sync` before using secrets in scripts or deployments.
- Programmatically adding new credentials or rotating existing ones via `rbw add`, e.g., after a password rotation script runs.
- Interacting with a self-hosted Vaultwarden instance for privacy-focused, air-gapped, or internal-only infrastructure.
Evaluation Scores
7.1
/ 10
Reliability
7.0
Functionality
8.0
Usability
6.5
Safety
6.0
Performance
8.5
Compatibility
7.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
7.1/103/19/2026▼
OS: win32-x64LLM: moonshotai/kimi-k2.5
**Quick judgment**: Useful, powerful, and inherently high-risk. This skill makes your Bitwarden/Vaultwarden vault accessible to agents via the `rbw` CLI. It is suitable only for tightly controlled environments where you fully trust the agent workflows and understand how outputs are stored and used.
**What it does well**
- Provides solid coverage of everyday vault operations: list, search, get (including full JSON), add, and sync.
- Uses the well-established `rbw` CLI rather than ad‑hoc API calls, which is good for correctness and security posture.
- Works with both Bitwarden cloud and Vaultwarden, with configurable base URL.
**Key risks / cautions**
- **High impact of leakage**: Any credentials retrieved via this skill can be exposed to other tools, logs, or prompts if workflows are not carefully designed.
- **Exec-based command execution**: It runs `rbw` via `exec`; misconfiguration or overly broad tool access could allow commands or outputs you did not anticipate.
- **Interactive unlock complexity**: Unlocking via `pinentry-curses` and `tmux` can be fragile; failures or misconfiguration can break flows or encourage insecure workarounds.
- **Prompt / tool misuse**: Ambiguous prompts could cause the agent to retrieve more secrets than intended (e.g., listing large portions of the vault instead of just one item).
**Recommended scenarios**
- You’re on a **single-user, secure machine**, already using `rbw`, and want automated but controlled access to specific credentials for scripts or dev tooling.
- You operate a **self-hosted Vaultwarden** and prefer a local CLI-based integration rather than cloud API usage.
- You can enforce **narrow, audited workflows** (e.g., only retrieving a specific item and passing it directly into a known tool without logging or re-printing it).
Avoid using this skill in shared, poorly isolated, or heavily logged environments, and do not grant it to general-purpose agents that aren’t tightly constrained in how they handle and store secret outputs.
Comments (0)
No comments yet. Be the first!