My agents are building a secure fork of OpenClaw
Details
- External ID
- 47005607
- Source
- HN
- Company
- —
- Product
- My agents are building a secure fork of OpenClaw
- Website domain
- seksbot.com
- Launched
- Feb. 13, 2026
- Cohort
- —
- Upvotes
- 9
- Upvotes percentile
- 0.4865229110512129
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
Show HN: SEKSBot – AI agents that can't see your secretsSEKSBot is a fork of OpenClaw where agents have zero access to API keys, tokens, or credentials — ever.The core insight is borrowed from SQL prepared statements: separate the instructions from the sensitive data. Agents write requests using named secret references. A broker intercepts and injects the real credentials at execution time. The agent never sees them.How it works:seksh (our nushell fork) has secure built-in commands (seksh-http, seksh-git) that route through the broker. Agents can make authenticated API calls and git operations without the keys ever entering shell memory.seks-broker stores secrets and acts as a proxy. It can inject bearer tokens, API keys, and even handle asymmetric key signing — all without exposing anything to the agent process.Three layers of defense: (1) Agents never have secrets in env vars or memory. (2) The broker validates and scopes every request. (3) Skills use sandboxing on top of broker-mediated access.The problem we kept seeing: every AI agent framework puts API keys in environment variables. One prompt injection, one malicious webpage, one bad skill — and your keys are exfiltrated. We decided the only real fix is making it physically impossible for the agent to access them.
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Horizontal
- Function
- Agent / copilot
- Audience
- Developer
- AI stance
- AI-native
- Project type
- Hobby / open-source project
- Normalized one-liner
- secure fork of openclaw
- Manually corrected
- False
Could you build this?
Yes It is an agent orchestration proxy fork that parameterizes agent requests and injects API credentials server-side via templated parameters before forwarding to upstream APIs.
Discussion
No comments on this launch.
Competitors
Other products that read as similar to this one — 368 launches clear the similarity bar, closest 8 shown.
Attention rank: #199 of 369 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 104 days after the earliest competitor.
- OneCLI · hn · 2026-03-12 · 161 upvotes · similarity 0.57
- FireClaw · hn · 2026-03-17 · 5 upvotes · similarity 0.53
- Latchkey · hn · 2026-02-03 · 12 upvotes · similarity 0.52
- PrivateClaw · hn · 2026-04-24 · 6 upvotes · similarity 0.51
- ClawShell, Process-Level Isolation for OpenClaw Credentials · hn · 2026-02-19 · 10 upvotes · similarity 0.51
- Agent Vault · hn · 2026-04-22 · 156 upvotes · similarity 0.48
- OneCLI · hn · 2026-07-23 · 110 upvotes · similarity 0.48
- AgentPort · hn · 2026-04-29 · 8 upvotes · similarity 0.48
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a agent / copilot tool for Agriculture yet.