Bagman is a comprehensive security framework for AI agents to manage private keys and API secrets without risking accidental exposure or theft.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install openclaw
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install openclaw using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Bagman provides a hardened architecture for AI agents that need to handle sensitive credentials, such as blockchain private keys or administrative API secrets. It addresses the inherent risks of autonomous agents, including key loss between sessions, accidental leakage in logs or GitHub commits, and malicious prompt injection attacks.
By leveraging the 1Password CLI and ERC-4337 session key patterns, Bagman ensures that raw private keys never reside in environment variables or on-disk configuration files. This skill is essential for developers utilizing Openclaw Skills to build production-ready agents that require controlled access to funds or protected data sources.
To implement Bagman, you must first install the 1Password CLI (op) and ensure your agent environment is configured for Openclaw Skills.
# Initialize a dedicated vault for your agent secrets
op vault create "Agent-Wallets"
# Create a session key entry with defined boundaries
op item create --vault "Agent-Wallets" --category "API Credential" --title "agent-session-01" --field "session-key[password]=0x..." --field "expires=2026-02-15T00:00:00Z"
# Use environment injection to run your agent without touching the disk
op run --env-file=.env.tpl -- node agent.js
Bagman uses a structured approach to metadata to ensure agents remain within their security bounds. The following schema is used within the secret manager:
| Field | Description | Format |
|---|---|---|
| session-key | The restricted-access private key used by the agent | Hex String |
| expires | The timestamp when the current session key becomes invalid | ISO 8601 |
| spending-cap | The maximum value the agent can move in a single transaction | String (e.g., '100 USDC') |
| allowed-contracts | A whitelist of smart contract addresses the agent can call | CSV String |
Loading
Bagman is a secure key management framework for AI agents to handle wallets, API secrets, and private keys safely.

A decentralized protocol skill enabling AI agents to discover, hire, and receive payments for services via Ethereum-based escrow.

A cost-effective, decentralized AI toolkit for processing transcription, images, video, and audio through a unified API.

A sophisticated AI-driven browser automation skill that leverages Amazon Nova Act to execute complex web tasks via natural language commands.

RTFM Testing is a methodology that spawns fresh AI agents with zero context to validate whether documentation is actually usable for its intended tasks.

An intelligent multi-model routing manager that optimizes AI performance and reduces costs through automated model selection and failover logic.








































