skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
keeper-security/keeper-agent-kit96 installs

keeper-setup

Install and configure Keeper CLI tools (KSM CLI and Commander) for the Keeper Security agent kit. Use when the user needs to install keeper-secrets-manager-cli (ksm) or keepercommander (keeper), set up authentication, initialize profiles, configure persistent login, or troubleshoot Keeper CLI connectivity. Also use when the user says 'install keeper', 'setup keeper', 'configure keeper cli', or asks how to get started with Keeper's command line tools.

How do I install this agent skill?

npx skills add https://github.com/keeper-security/keeper-agent-kit --skill keeper-setup
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill provides official instructions for installing and configuring Keeper Security's command-line tools. It follows security best practices by advising the use of environment variables for tokens instead of command-line arguments and explicitly warning against sharing sensitive data in the chat environment.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Keeper CLI Setup & Configuration

Official documentation

Keeper provides two CLI tools. Install what you need:

ToolPackagePurpose
KSM CLI (ksm)keeper-secrets-manager-cliMachine secrets retrieval & injection
Commander (keeper)keepercommanderAdmin, vault management, PAM, sessions

Installation security

  • Prefer PyPI (pip install …) so you consume the published packages with version pins in your own dependency files. That is the default path for these tools.
  • Official sources only: release binaries and source live under the Keeper-Security organization on GitHub. Before running any installer or pip install from a clone, confirm the remote URL and publisher match Keeper’s official documentation; use release tags or checksums published on the release page when you need extra assurance.
  • Agents must not fabricate or echo one-time tokens, master passwords, or vault field values in chat or generated scripts. Direct the user to paste or inject secrets only in their own secure terminal or secret store.

Quick Install

KSM CLI

# With OS-native keyring (recommended for workstations)
pip install keeper-secrets-manager-cli[keyring]

# Without keyring (for containers, CI/CD, headless)
pip install keeper-secrets-manager-cli

# Verify
ksm version

Binary installers (no Python required) are published for Windows, macOS, and Linux on the official Keeper-Security/secrets-manager GitHub Releases page linked from Secrets Manager CLI documentation. Download only from that release page; verify checksums or signatures when the release provides them.

Commander

pip install keepercommander

# Optional: install from a local clone of the official repository (verify remote and use a tagged release)
git clone https://github.com/Keeper-Security/Commander.git
cd Commander
git checkout <release-tag>
python -m venv venv && source venv/bin/activate
pip install -r requirements.txt && pip install -e .

# Verify
keeper version

First-Time Setup

KSM CLI Setup

You need a One-Time Access Token from a KSM Application. If you don't have one, your Keeper admin can create it via the Vault UI or Commander (see keeper-admin skill).

Provide the token via environment variable so it is not passed as a --token argument (which can show up in shell history and process listings). Official docs: Profile command / init.

# Prerequisite: export KSM_CLI_TOKEN in this shell from Vault or Commander output (see Keeper profile docs). Never paste token values into chat or committed files.
ksm profile init
# Optional: unset KSM_CLI_TOKEN when finished in this shell.

ksm secret list  # Verify access

In CI or secret managers, inject the same variable without placing the value on the command line. For containers, see also KSM_TOKEN / KSM_INI_DIR behavior in the Keeper Secrets Manager CLI documentation.

Commander Setup

keeper shell
# Enter your email, master password, and 2FA code
# Then enable persistent login:
My Vault> this-device register
My Vault> this-device persistent-login ON

Keeper Regions

RegionHostToken Prefix
USkeepersecurity.comUS:
EUkeepersecurity.euEU:
AUkeepersecurity.com.auAU:
JPkeepersecurity.jpJP:
CAkeepersecurity.caCA:
US Govgovcloud.keepersecurity.usGOV:

Troubleshooting

IssueFix
"Not authenticated"Re-run ksm profile init after setting KSM_CLI_TOKEN from a new Client Device token
"Token expired"Generate a new Client Device in Commander or Vault UI
IP lock errorsUse --unlock-ip when creating the client, or init from the locked IP
Keyring not availableInstall with [keyring] extra or use --ini-file flag
Python version errorKSM CLI requires Python 3.10+, Commander requires 3.10+
Permission denied on keeper.iniFile should be 0600; check with ls -la keeper.ini

What's Next

  • To retrieve and inject secrets (including Keeper notation): see the keeper-secrets skill
  • To manage enterprise, users, PAM: see the keeper-admin skill

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/keeper-security/keeper-agent-kit/keeper-setup">View keeper-setup on skillZs</a>