SAFE Encryption Tool for Openclaw

A modern encryption skill for AI agents providing post-quantum protection, multi-recipient support, and seamless GitHub identity integration.

grittygrease
v0.1.0
Feb 21, 2026
0
1.8k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install safe-encryption-skill

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install safe-encryption-skill using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is SAFE Encryption Tool?

The SAFE Encryption Tool is a high-performance security skill designed for Openclaw Skills users who require a modern, developer-friendly alternative to GPG. It provides a robust command-line interface and a client-side web alternative for managing cryptographic operations. The skill specializes in modern AEAD encryption, offering post-quantum security via ML-KEM-768 alongside classical algorithms like X25519 and P-256.

Built for the era of autonomous agents, this skill simplifies complex workflows by automating key discovery and supporting composable authentication logic. Agents can easily manage identities, encrypt data for multiple recipients simultaneously, and even integrate with GitHub to fetch public keys for secure cross-agent communication. Whether running in a restricted shell or a full development environment, this tool ensures that sensitive data remains protected with industry-leading standards.

SAFE Encryption Tool Use Cases

  • Protecting sensitive environment variables and API keys within Openclaw Skills automation scripts.
  • Exchanging encrypted messages between AI agents using GitHub Gists as a secure transport layer.
  • Future-proofing data security by applying post-quantum hybrid encryption to long-lived archives.
  • Performing granular, in-place edits on large encrypted datasets without the overhead of full re-encryption.
  • Managing shared team secrets where multiple identities require independent decryption access.

How SAFE Encryption Tool Works

  1. The skill initializes by checking for the safe binary and automatically installing it if missing to maintain seamless Openclaw Skills workflows.
  2. It establishes a local keychain in the ~/.safe/ directory, segregating private keys, public keys, and known recipient files.
  3. When encrypting, the tool creates a SAFE file structure containing metadata, one or more UNLOCK blocks (defining recipients), and the encrypted payload.
  4. It supports composable paths, allowing developers to define complex access requirements using AND/OR logic for passwords and keys.
  5. During decryption, the tool performs automatic key discovery by scanning ~/.safe/keys/ and ~/.ssh/ for matching identities.
  6. For environments without CLI access, the skill can drive the browser-based interface at thesafe.dev using ARIA-labeled automation tools.

SAFE Encryption Tool Setup

To integrate this tool into your Openclaw Skills environment, use the following one-liner to install the SAFE CLI:

which safe || { OS=$(uname -s | tr '[:upper:]' '[:lower:]'); ARCH=$(uname -m); \
  [ "$ARCH" = "arm64" ] || [ "$ARCH" = "aarch64" ] && ARCH=arm64 || ARCH=amd64; \
  curl -sL "https://thesafe.dev/downloads/safe-${OS}-${ARCH}" -o safe && chmod +x safe && sudo mv safe /usr/local/bin/; }

Verify the installation and generate your agent's primary identity:

safe --help
safe keygen x25519 -n agent-identity

SAFE Encryption Tool Data Schema & Taxonomy

The SAFE Encryption Tool organizes cryptographic data and metadata as follows within the Openclaw Skills environment:

Component Location Description
Private Keys ~/.safe/keys/ Secret PEM-encoded keys used for decryption.
Public Keys ~/.safe/*.pub Your shareable public keys for identity exchange.
Recipients ~/.safe/recipients/ Imported public keys of other agents or collaborators.
Native Config ~/.safe/ Default home for all identity and recipient management.

Files generated with the .safe extension include a header defining the AEAD algorithm (e.g., AES-256-GCM), a list of UNLOCK blocks for various recipients, and the encrypted data chunks.

SAFE Encryption Tool Advanced Features

  • Post-Quantum Hybrid Encryption: Protects data against future quantum threats using ML-KEM-768.
  • GitHub Username Integration: Directly encrypt for any user using the github:username prefix to fetch public SSH keys.
  • Composable Authentication: Enforce multi-factor requirements by combining passwords and keys with logic operators.
  • In-Place Random-Access Editing: Modify or append to encrypted files without decrypting the entire document.
  • SSH Key Auto-Discovery: Automatically detects and utilizes existing OpenSSH keys from the ~/.ssh/ directory.
  • WebRTC Peer-to-Peer Transfer: Securely send encrypted files between browser sessions without intermediate servers.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*