Gateway Environment Injector for Openclaw

A secure automation tool for injecting 1Password secrets directly into macOS LaunchAgent environment variables.

nissan
v1.0.0
Mar 7, 2026
0
1.1k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install gateway-env-injector

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install gateway-env-injector using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Gateway Environment Injector?

The Gateway Environment Injector is a specialized utility designed to bridge the gap between secure secret management and macOS service configurations. By integrating 1Password directly into the macOS LaunchAgent lifecycle, this tool ensures that sensitive API keys are never stored in plaintext on the local disk. As a valuable addition to the ecosystem of Openclaw Skills, it utilizes the 1Password CLI to fetch secrets on demand and injects them into the EnvironmentVariables block of a plist file using the native PlistBuddy tool. This approach is essential for developers who need to maintain high security standards while running persistent background agents on macOS.

Gateway Environment Injector Use Cases

  • Securing API keys for background services managed via Openclaw Skills.
  • Automating the injection of secrets into macOS LaunchAgents without manual plist editing.
  • Preventing the exposure of sensitive credentials in shell profile files like .zshrc.
  • Streamlining secret rotation workflows for macOS-based development environments.

How Gateway Environment Injector Works

  1. The script initializes a connection to 1Password using an authorized Service Account Token.
  2. It references a configurable array of environment variables and their corresponding 1Password vault URIs.
  3. The 1Password CLI fetches the requested secrets securely from the vault.
  4. Using the PlistBuddy utility, the script modifies the target LaunchAgent plist to include the fetched secrets in its environment configuration.
  5. The service is automatically restarted to ensure the new environment variables are loaded and active.

Gateway Environment Injector Setup

To get started with this component of Openclaw Skills, follow these steps:

  1. Ensure the 1Password CLI (op) and bash are installed on your macOS system.
  2. Set your 1Password Service Account Token as an environment variable:
export OP_SERVICE_ACCOUNT_TOKEN='your_service_account_token'
  1. Define your secret mappings in the KEYS array within the script.
  2. Execute the injection script to update your configuration:
bash scripts/inject-gateway-env.sh

Gateway Environment Injector Data Schema & Taxonomy

Component Description
Plist File The macOS LaunchAgent .plist file targeted for modification.
EnvironmentVariables The specific dictionary key within the plist used for secret storage.
op:// URI The 1Password secret reference format (Vault/Item/Field) used for lookups.
OP_SERVICE_ACCOUNT_TOKEN The primary authentication credential required for secure vault access.

Gateway Environment Injector Advanced Features

  • Support for 1Password Service Accounts to enable automated, non-interactive secret retrieval.
  • Native PlistBuddy integration to avoid external dependencies for plist manipulation.
  • Strategic path stabilization logic to prevent macOS TCC permission issues common in Openclaw Skills setups.
  • Automated service lifecycle management including process restart after configuration changes.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Requires
Bins opbash
Github Stars: 0
forks: 0

Featured*