Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Password Manager

ASecurity

Use a password manager correctly: setup, strong unique passwords, 2FA, passkeys, sharing, and emergency access. Use when securing accounts or helping others adopt a password manager.

2 stars
0 votes
0 copies
2 views
Added 9/29/2026
ai-agentsrustgosecurity

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill password-manager --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Password Manager?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Password Manager
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-password-manager/badge)](https://www.skillsdirectory.com/skills/aicodedecode-password-manager)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: password-manager
description: Use a password manager correctly: setup, strong unique passwords, 2FA, passkeys, sharing, and emergency access. Use when securing accounts or helping others adopt a password manager.
category: productivity
---

# Password Manager

## Overview

A password manager is the single highest-ROI security tool: unique random passwords everywhere, one strong master password to remember.

It solves the real problem — password reuse across breaches — not the imaginary one of 'hackers guessing.'

Correct usage: generator for every password, 2FA codes inside, passkeys where offered, secure sharing, emergency access configured.

## When to use

- Setting up a password manager for the first time
- Cleaning up password reuse across accounts
- Adding two-factor authentication to important accounts
- Adopting passkeys alongside passwords
- Setting up family or team password sharing
- Planning emergency access to your accounts

## Core concepts

- **Unique passwords everywhere.**
  Every site gets its own random 20+ character password. Breach of one site can't cascade to others. Non-negotiable.
- **The master password.**
  One long, memorable passphrase (4-6 random words). This is the only password you memorize. Make it strong; it's the keys to the kingdom.
- **Generator defaults.**
  Max length, all character types, per-site. Never hand-craft passwords — humans are predictable, generators aren't.
- **2FA in the manager.**
  Store TOTP codes in the manager for convenience, but keep critical accounts (email, manager itself) on a separate authenticator.
- **Passkeys.**
  Adopt where offered: phishing-resistant, no password to steal. Manager-stored passkeys sync across devices.
- **Breach monitoring.**
  Enable breach alerts. When a service you use is breached: change that password immediately (it's unique, so damage is contained).
- **Secure sharing.**
  Share credentials through the manager's sharing — never email, chat, or sticky notes. Revoke when access ends.
- **Emergency access.**
  Designate a trusted person with delayed-access recovery. Without this, your accounts die with your memory.

## Practical workflow

1. **Choose a reputable manager.**
   Open-source audited or well-established commercial. Criteria: zero-knowledge encryption, cross-platform, passkey support.
2. **Create the master passphrase.**
   Long, random-word passphrase, written down and stored physically secure until memorized. Enable biometrics for daily unlock.
3. **Import and audit.**
   Import browser-saved passwords, then run the security audit: reused, weak, and breached passwords flagged.
4. **Fix the critical ten.**
   Email, bank, password manager, cloud, social: unique passwords + 2FA first. These ten accounts are 90% of your risk.
5. **Roll through the rest.**
   Change remaining passwords as you log in naturally. Aim for full coverage in 1-2 months, not one exhausting weekend.
6. **Enable 2FA everywhere offered.**
   Authenticator app or manager TOTP; prefer passkeys/security keys for high-value accounts.
7. **Set up sharing.**
   Family vault for shared accounts (streaming, utilities); team vaults for work with least-privilege access.
8. **Configure emergency access.**
   Trusted contact with time-delayed access. Document the plan where they'll find it.

## Common pitfalls

- **Reusing passwords.**
  The #1 real-world risk. One breach + reuse = every account compromised. Unique everywhere, no exceptions.
- **Weak master password.**
  'Password123!' protecting 300 accounts. The master passphrase must be long — it's the single point of failure.
- **Storing 2FA with passwords.**
  TOTP in the same manager as passwords removes the 'second factor' for a manager breach. Separate critical ones.
- **Browser-only saving.**
  Browser password stores lack the generator discipline, auditing, and cross-browser portability. Use a real manager.
- **Sharing via email/chat.**
  Credentials in plaintext chat logs live forever. Always share through the manager's encrypted sharing.
- **No emergency plan.**
  Sole keeper of family accounts with no recovery path. Emergency access isn't morbid; it's responsible.
- **Ignoring breach alerts.**
  Alerts without action are theater. Breach on a unique password = 5-minute fix. That's the payoff of the system.
- **Same password + 2FA complacency.**
  'I have 2FA so reuse is fine.' 2FA helps; unique passwords are still required. Defense in depth, not either/or.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →