by notinferred
A KeePass-compatible password and secrets manager for people who work with AI agents.
# Add to your Claude Code skills
git clone https://github.com/notinferred/keypasteLast scanned: 10/6/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-10-06T11:02:31.336Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}keypaste is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by notinferred. A KeePass-compatible password and secrets manager for people who work with AI agents. It has 159 GitHub stars.
Yes. keypaste passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/notinferred/keypaste" and add it to your Claude Code skills directory (see the Installation section above).
keypaste is primarily written in C#. It is open-source under notinferred on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh keypaste against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The published v0.3.0 CLI stores logins and environment variables in a local KDBX vault, runs commands with them, and asks you before an agent receives one. Everything else below is in source until the next release, and the desktop app has no public release; FEATURES records what exists where.
As a password manager
keepassxc-cli on Linux, macOS and Windows.keypaste rotate replaces a password with a generated one and never prints it.keypaste import copies another KDBX file in, or keeps editing it in place.For developers and their agents
keypaste run puts values in a command's environment and nothing on disk. With --allow-run, an agent can run a command you approve and gets back its output with each value replaced, though a command it can edit can still reveal a value (T-35). PRODUCT §2 bounds it: no shell, and you approve the exact command..env.keypaste: KEY=kp://project/profile/KEY references and no values, safe to commit.read:acme-api/staging/*: inject-only, and expiring after 30 days by default.
Rendered from the current source's output, for the next release, with a scripted MCP client in place of the agent; the published v0.3.0 asks Approve? [y/N] and allows up to 300 seconds. The prompt as text:
────────────────────────────────────────────────────────────
keypaste: an agent is asking for a credential.
client claude-code
entry env/demo/STRIPE_KEY
field password
the agent says it needs this because:
deploy the billing service to staging
That sentence was written by the agent, not by keypaste. Treat it as a claim.
[d] deny [o] once [h] 1 hour 45s ›
The demo shows a credential request, approval and deploy in about sixty seconds.
You can transport the encrypted file with your existing file-sync service; keypaste has no merge or managed-sync workflow. KDBX compatibility does not mean complete KeePassXC feature coverage. The code is open source under AGPL-3.0.
The published download is pre-1.0 CLI/MCP v0.3.0. Replace v0.2.0: a save racing another program's save could undo it without keeping the lost change in history. Replace v0.1.0: it could also delete a vault through env export, modify the wrong entry through env rm, and return the wrong password through get. CHANGELOG lists what v0.3.0 repairs. Published versions are immutable, so both remain available with those defects.
The desktop app holds the vault unlocked for one session: it answers agents in its own prompt window, launches projects with their variables and locks everything at once. RELEASE defines distribution status, ROADMAP what comes next, and PRODUCT product commitments. Broader ideas are in BACKLOG.
Download the archive and its checksum, verify the hash, then extract it. Each binary is a native executable with no .NET runtime dependency. The Unix instructions move both binaries into ~/.local/bin.
curl -fLO https://dl.keypaste.com/v0.3.0/keypaste-0.3.0-osx-arm64.tar.gz
curl -fLO https://dl.keypaste.com/v0.3.0/keypaste-0.3.0-osx-arm64.tar.gz.sha256
shasum -a 256 -c keypaste-0.3.0-osx-arm64.tar.gz.sha256
tar -xzf keypaste-0.3.0-osx-arm64.tar.gz
mkdir -p ~/.local/bin && mv keypaste keypaste-mcp ~/.local/bin/
macOS 14 or later. This floor follows .NET 10 support; no run backs this floor. Intel Macs have no published binary and require a source build. GitHub offers native Intel runners, but this release matrix does not yet build or test that target.
curl -fLO https://dl.keypaste.com/v0.3.0/keypaste-0.3.0-linux-x64.tar.gz
curl -fLO https://dl.keypaste.com/v0.3.0/keypaste-0.3.0-linux-x64.tar.gz.sha256
sha256sum -c keypaste-0.3.0-linux-x64.tar.gz.sha256
tar -xzf keypaste-0.3.0-linux-x64.tar.gz
mkdir -p ~/.local/bin && mv keypaste keypaste-mcp ~/.local/bin/
For arm64, substitute linux-arm64 in all three filenames. Both are built against glibc 2.35. The release workflow checks the x64 binary on a clean Debian 12 container and checks that it fails on Alpine; the equivalent container check is not implemented for arm64. Alpine and other musl distributions have no published binary; build from source there.
$a = "keypaste-0.3.0-win-x64.zip"
Invoke-WebRequest -OutFile $a "https://dl.keypaste.com/v0.3.0/$a"
Invoke-WebRequest -OutFile "$a.sha256" "https://dl.keypaste.com/v0.3.0/$a.sha256"
$want = (Get-Content "$a.sha256" -Raw).Split()[0]
if ((Get-FileHash $a -Algorithm SHA256).Hash -ne $want) { throw "checksum mismatch" }
Expand-Archive $a -DestinationPath .
Windows 10 1809 or later. This floor follows .NET 10 support; no run backs this floor.
On Windows, put the extracted binaries in a directory you add to PATH. On macOS and Linux, check that ~/.local/bin is on PATH with command -v keypaste.
Keep the absolute path of keypaste-mcp for your MCP client configuration.
The checksum detects a corrupted or incomplete download. It does not authenticate the publisher. The checksum is served from the same origin as the archive, so anyone able to replace one can replace both. The published binaries are unsigned and un-notarized. v0.3.0 also publishes a build attestation that GitHub CLI can check without an account, covering every asset and the release manifest; v0.2.0 and earlier have none. THREATS.md T-21 describes the download trust boundary, and SECURITY.md has the verification steps in one place.
The installation instructions keep downloaded commands visible for review before execution.
Browser downloads set com.apple.quarantine; these command-line download and extraction steps should avoid it. The release runner executed the binary with quarantine deliberately set, but that observation does not establish behavior on every Mac. If macOS blocks the unsigned binary, xattr -d com.apple.quarantine ~/.local/bin/keypaste removes the attribute.
Building from source lets you inspect the code you compile with