Agent Skills
› LeoYeAI/openclaw-master-skills
› 1password
1password
GitHub用于配置和使用1Password CLI。涵盖安装、桌面集成、多账号登录及密钥读取注入。核心要求:必须在专用tmux会话中执行所有op命令,避免TTY问题;严禁将密钥泄露至日志或代码中。
触发场景
需要安装或配置1Password CLI
需要登录1Password账户
需要读取或注入安全密钥
涉及1Password桌面应用集成
安装
npx skills add LeoYeAI/openclaw-master-skills --skill 1password -g -y
SKILL.md
Frontmatter
{
"name": "1password",
"homepage": "https:\/\/developer.1password.com\/docs\/cli\/get-started\/",
"metadata": {
"clawdbot": {
"emoji": "🔐",
"install": [
{
"id": "brew",
"bins": [
"op"
],
"kind": "brew",
"label": "Install 1Password CLI (brew)",
"formula": "1password-cli"
}
],
"requires": {
"bins": [
"op"
]
}
}
},
"description": "Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading\/injecting\/running secrets via op."
}
1Password CLI
Follow the official CLI get-started steps. Don't guess install commands.
References
references/get-started.md(install + app integration + sign-in flow)references/cli-examples.md(realopexamples)
Workflow
- Check OS + shell.
- Verify CLI present:
op --version. - Confirm desktop app integration is enabled (per get-started) and the app is unlocked.
- REQUIRED: create a fresh tmux session for all
opcommands (no directopcalls outside tmux). - Sign in / authorize inside tmux:
op signin(expect app prompt). - Verify access inside tmux:
op whoami(must succeed before any secret read). - If multiple accounts: use
--accountorOP_ACCOUNT.
REQUIRED tmux session (T-Max)
The shell tool uses a fresh TTY per command. To avoid re-prompts and failures, always run op inside a dedicated tmux session with a fresh socket/session name.
Example (see tmux skill for socket conventions, do not reuse old session names):
SOCKET_DIR="${CLAWDBOT_TMUX_SOCKET_DIR:-${TMPDIR:-/tmp}/clawdbot-tmux-sockets}"
mkdir -p "$SOCKET_DIR"
SOCKET="$SOCKET_DIR/clawdbot-op.sock"
SESSION="op-auth-$(date +%Y%m%d-%H%M%S)"
tmux -S "$SOCKET" new -d -s "$SESSION" -n shell
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op signin --account my.1password.com" Enter
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op whoami" Enter
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op vault list" Enter
tmux -S "$SOCKET" capture-pane -p -J -t "$SESSION":0.0 -S -200
tmux -S "$SOCKET" kill-session -t "$SESSION"
Guardrails
- Never paste secrets into logs, chat, or code.
- Prefer
op run/op injectover writing secrets to disk. - If sign-in without app integration is needed, use
op account add. - If a command returns "account is not signed in", re-run
op signininside tmux and authorize in the app. - Do not run
opoutside tmux; stop and ask if tmux is unavailable.
版本历史
- e5199b5 当前 2026-07-25 11:57


