macos-keychain
Keychain: security CLI, API key storage, certificates, codesigning, Secure Enclave
What this skill does
# macos-keychain ## Purpose This skill provides tools for managing macOS Keychain via the `security` CLI, handling secure storage of secrets like API keys, passwords, certificates, and codesigning, while interacting with the Secure Enclave for enhanced security. ## When to Use Use this skill when your application needs to store or retrieve sensitive data on macOS, such as API keys in scripts, manage certificates for app signing, or handle hardware-backed secrets via Secure Enclave. Apply it in automation, CI/CD pipelines, or apps requiring macOS-specific security. ## Key Capabilities - Store and retrieve generic passwords using Keychain services. - Manage certificates and identities for codesigning apps or verifying connections. - Interact with Secure Enclave for storing keys that require hardware protection. - Add, delete, or search items in Keychain with fine-grained access controls. - Handle API key storage with encryption, ensuring data is isolated per user or app. ## Usage Patterns Always run `security` commands via subprocess in scripts, prefixing with `security` and using flags for operations. For programmatic access, use the Security framework in Swift/Objective-C. Check for Keychain access prompts and handle user interactions. Use environment variables like `$KEYCHAIN_ITEM_NAME` for dynamic inputs to avoid hardcoding secrets. ## Common Commands/API Use the `security` CLI for most tasks; for apps, leverage Security framework APIs like SecItemAdd and SecItemCopyMatching. - Add a generic password: `security add-generic-password -a username -s service -w password -T ""` This stores a password for a service; use `$SERVICE_NAME` for the service string. - Find a generic password: `security find-generic-password -a username -s service -w` Output the password; pipe to a variable, e.g., in Bash: `pass=$(security find-generic-password -s myapp -w)`. - Delete an item: `security delete-generic-password -a username -s service` Removes the entry; confirm with `-h` for help on flags. - Add a certificate: `security add-certificate -k login.keychain cert.pem` Imports a PEM certificate; specify keychain with `-k`. - For Secure Enclave, generate a key: `security create-key -t secp256r1 -a -p` Creates a key pair; use in apps via SecKeyGeneratePair. - API example in Swift (Security framework): `let query: [String: Any] = [kSecClass as String: kSecClassGenericPassword]` `let status = SecItemCopyMatching(query as CFDictionary, nil)` This queries for a generic password item. - Export a certificate: `security export -k login.keychain -t identities -o cert.p12 -P passphrase` Exports to P12 format; use for codesigning. Config formats: Keychain items use a dictionary-based query (e.g., in APIs, as [String: Any]), with keys like kSecAttrAccount for usernames. CLI outputs are plain text or plist; parse with `plutil` for structured data. ## Integration Notes Integrate by calling `security` commands from scripts using subprocess (e.g., in Python: `subprocess.run(['security', 'add-generic-password', ...])`). For apps, import Security.h and use functions like SecItemAdd; ensure entitlements include "keychain-access-groups". Use env vars for secrets, like `$API_KEY` passed to commands. Avoid storing keys in code; fetch from Keychain at runtime. For cross-app access, set the same access group in entitlements. ## Error Handling Check command exit codes; e.g., in Bash, use `if [ $? -ne 0 ]; then echo "Error: Keychain operation failed"; fi`. For CLI, parse stderr for messages like "SecKeychainItem not found". In Swift APIs, handle OSStatus errors (e.g., if SecItemAdd returns errSecDuplicateItem, log and retry). Use try-catch in Objective-C for framework calls. Common issues: permission denied (prompt user via UI) or item not found (return default value). Always sanitize outputs to prevent exposure of secrets. ## Concrete Usage Examples 1. Store an API key in Keychain: In a Bash script, use: `security add-generic-password -a myapp-user -s myapi -w $API_KEY -T ""` Then retrieve it: `apiKey=$(security find-generic-password -a myapp-user -s myapi -w)` Use `$API_KEY` from env vars to avoid plaintext in scripts. 2. Manage a certificate for codesigning: Import a cert: `security add-certificate -k login.keychain mycert.pem` Verify: `security find-certificate -c "My Cert Name"` In a build script, export for signing: `security export -k login.keychain -t identities -o signing.p12`. ## Graph Relationships - Related to: macos-filesystem (for certificate file handling), security-tools (for broader security operations), encryption-services (via Secure Enclave integration). - Clusters: macos (direct), secrets-management (via tags). - Tags connections: keychain (core), secrets (overlaps with vault tools), security (links to authentication skills).
Related in Backend & APIs
jfrog
IncludedInteract with the JFrog Platform via the JFrog CLI and REST/GraphQL APIs. Use this skill when the user wants to manage Artifactory repositories, upload or download artifacts, manage builds, configure permissions, manage users and groups, work with access tokens, configure JFrog CLI servers, search artifacts, manage properties, set up replication, manage JFrog Projects, run security audits or scans, look up CVE details, query exposures scan results from JFrog Advanced Security, manage release bundles and lifecycle operations, aggregate or export platform data, or perform any JFrog Platform administration task. Also use when the user mentions jf, jfrog, artifactory, xray, distribution, evidence, apptrust, onemodel, graphql, workers, mission control, curation, advanced security, exposures, or any JFrog product name.
cupynumeric-migration-readiness
IncludedPre-migration readiness assessor for porting NumPy to cuPyNumeric. Use BEFORE substantial porting work begins when the user asks whether code will scale on GPU, whether they should migrate to cuPyNumeric, which NumPy patterns transfer cleanly, what must be refactored before porting, or mentions pre-port assessment, scaling analysis, or refactor planning. Inspect the user's source code, look up NumPy usage, cross-reference the cuPyNumeric API support manifest, and distinguish distributed-scaling-friendly patterns from blockers such as unsupported APIs, scalar synchronization, host round-trips, Python/object-heavy control flow, shape/data-dependent branching, and in-place mutation hazards. Produce a verdict of READY, LIGHT REFACTOR, SIGNIFICANT REFACTOR, or NOT RECOMMENDED, with concrete refactor pointers.
alibabacloud-data-agent-skill
IncludedInvoke Alibaba Cloud Apsara Data Agent for Analytics via CLI to perform natural language-driven data analysis on enterprise databases. Data Agent for Analytics is an intelligent data analysis agent developed by Alibaba Cloud Database team for enterprise users. It automatically completes requirement analysis, data understanding, analysis insights, and report generation based on natural language descriptions. This tool supports: discovering data resources (instances/databases/tables) managed in DMS, initiating query or deep analysis sessions, real-time progress tracking, and retrieving analysis conclusions and generated reports. Use this Skill when users need to query databases, analyze data trends, generate data reports, ask questions in natural language, or mention "Data Agent", "data analysis", "database query", "SQL analysis", "data insights".
token-optimizer
IncludedReduce OpenClaw token usage and API costs through smart model routing, heartbeat optimization, budget tracking, and native 2026.2.15 features (session pruning, bootstrap size limits, cache TTL alignment). Use when token costs are high, API rate limits are being hit, or hosting multiple agents at scale. The 4 executable scripts (context_optimizer, model_router, heartbeat_optimizer, token_tracker) are local-only — no network requests, no subprocess calls, no system modifications. Reference files (PROVIDERS.md, config-patches.json) document optional multi-provider strategies that require external API keys and network access if you choose to use them. See SECURITY.md for full breakdown.
resend-cli
IncludedUse this skill when the task is specifically about operating Resend from an AI agent, terminal session, or CI job via the official resend CLI: installing/authenticating the CLI, sending/listing/updating/cancelling emails, batch sends, domains and DNS, webhooks and local listeners, inbound receiving, contacts, topics, segments, broadcasts, templates, API keys, profiles, or debugging Resend CLI/API failures. Trigger on mentions of Resend CLI, `resend`, `resend doctor`, `resend emails send`, `resend domains`, `resend webhooks listen`, `resend emails receiving`, or agent-friendly terminal automation.
alibabacloud-odps-maxframe-coding
IncludedUse this skill for MaxFrame SDK development and documentation navigation on Alibaba Cloud MaxCompute (ODPS). Helps answer MaxFrame API, concept, official example, and supported pandas API questions; create data processing programs; read/write MaxCompute tables; debug jobs (remote or local); and build custom DPE runtime images. Trigger when users mention MaxFrame, MaxCompute with MaxFrame, ODPS table processing, DPE runtime, MaxFrame docs/examples, DataFrame/Tensor operations, or GPU runtime setup. Works for both English and Chinese queries about Alibaba Cloud data processing with MaxFrame.