Bagman for Openclaw

Bagman is a comprehensive security framework for AI agents to manage private keys and API secrets without risking accidental exposure or theft.

zscole
v1.0.0
Feb 9, 2026
3
3.9k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install openclaw

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install openclaw using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Bagman?

Bagman provides a hardened architecture for AI agents that need to handle sensitive credentials, such as blockchain private keys or administrative API secrets. It addresses the inherent risks of autonomous agents, including key loss between sessions, accidental leakage in logs or GitHub commits, and malicious prompt injection attacks.

By leveraging the 1Password CLI and ERC-4337 session key patterns, Bagman ensures that raw private keys never reside in environment variables or on-disk configuration files. This skill is essential for developers utilizing Openclaw Skills to build production-ready agents that require controlled access to funds or protected data sources.

Bagman Use Cases

  • Managing blockchain wallets for autonomous trading bots or DAO participants.
  • Securing API credentials for LLMs and third-party services in multi-agent systems.
  • Implementing pre-commit hooks to prevent developers from accidentally pushing secrets to version control.
  • Sanitizing agent chat logs and outputs to ensure sensitive hex strings are never exposed to users.
  • Creating time-bound, permission-restricted session keys for temporary agent tasks.

How Bagman Works

  1. The operator establishes a secure 1Password vault specifically for agent credentials, ensuring a clear air gap from personal secrets.
  2. The AI agent retrieves session keys or secrets at runtime using the 1Password CLI, keeping the data strictly in volatile memory.
  3. Input validation filters are applied to all user prompts to detect and block attempts to exfiltrate secret data via injection.
  4. During execution, the agent uses bounded session keys (ERC-4337) that limit spending power and allowed contract interactions.
  5. An output sanitization layer scans every outgoing message or log entry for key-like patterns, redacting any sensitive information before it is persisted or displayed.

Bagman Setup

To implement Bagman, you must first install the 1Password CLI (op) and ensure your agent environment is configured for Openclaw Skills.

# Initialize a dedicated vault for your agent secrets
op vault create "Agent-Wallets"

# Create a session key entry with defined boundaries
op item create --vault "Agent-Wallets" --category "API Credential" --title "agent-session-01" --field "session-key[password]=0x..." --field "expires=2026-02-15T00:00:00Z"

# Use environment injection to run your agent without touching the disk
op run --env-file=.env.tpl -- node agent.js

Bagman Data Schema & Taxonomy

Bagman uses a structured approach to metadata to ensure agents remain within their security bounds. The following schema is used within the secret manager:

Field Description Format
session-key The restricted-access private key used by the agent Hex String
expires The timestamp when the current session key becomes invalid ISO 8601
spending-cap The maximum value the agent can move in a single transaction String (e.g., '100 USDC')
allowed-contracts A whitelist of smart contract addresses the agent can call CSV String

Bagman Advanced Features

  • ERC-4337 Smart Account support for programmable permissions and multi-sig recovery.
  • Regex-based output sanitization covering Ethereum keys, OpenAI, Anthropic, and Groq API formats.
  • Git pre-commit hooks that scan staged changes for potential private key patterns before they are committed.
  • Automatic session revocation and rotation workflows using the 1Password CLI for incident response.
  • Integration with Openclaw Skills logging to provide redacted identifiers instead of raw secret data in audit trails.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*