wyre-technology/msp-claude-plugins/msp-claude-plugins/hudu/hudu/skills/passwords/SKILL.md
Hudu Passwords
Hudu secure credential storage: the /api/v1/asset_passwords endpoint (the UI calls these "Passwords"), company scoping and password folders, TOTP secrets, per-API-key password permissions, activity-log auditing, rotation workflows, and output-safety rules for handling plaintext credential values.
- Source repository stars
- 39
- Declared platforms
- 0
- Static risk flags
- 2
- Last source update
- 2026-08-06
- Source checked
- 2026-08-06
Decision brief
What it does—and where it fits
Hudu secure credential storage: the /api/v1/asset_passwords endpoint (the UI calls these "Passwords"), company scoping and password folders, TOTP secrets, per-API-key password permissions, activity-log auditing, rotation workflows, and output-safety rules for handling plaintext credential values.
Not for
- Tasks that require unconfirmed production actions or broad system permissions.
- Environments where the pinned source and install steps cannot be inspected.
Compatibility matrix
Platform support, with evidence labels
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
Inspect first. Install second.
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill "msp-claude-plugins/hudu/hudu/skills/passwords"Inspect the Agent Skill "Hudu Passwords" from https://github.com/wyre-technology/msp-claude-plugins/blob/c1011303bfd2a65abc9b260884d9858d1a482a6f/msp-claude-plugins/hudu/hudu/skills/passwords/SKILL.md at commit c1011303bfd2a65abc9b260884d9858d1a482a6f. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
What the source asks the agent to do
- 01
Password Rotation Workflow
Hudu keeps no rotation history of its own — append rotation dates to description so the audit trail survives.
Hudu keeps no rotation history of its own — append rotation dates to description so the audit trail survives. - 02
Anti-triggers
A credential needed to authenticate a tool call — Hudu passwords
A credential needed to authenticate a tool call — Hudu passwordsA credential stored on an asset rather than as a password record —The same credential in IT Glue — the other documentation platform in - 03
Key Concepts
Passwords are organized by:
Company - Each password belongs to a specific companyPassword Folders - Hierarchical folder structure within a companyName - Descriptive name identifying the credential - 04
Password Organization
Passwords are organized by:
Company - Each password belongs to a specific companyPassword Folders - Hierarchical folder structure within a companyName - Descriptive name identifying the credential - 05
API Key Password Permission
API keys in Hudu can be configured to allow or deny password access:
API keys in Hudu can be configured to allow or deny password access:This is configured per API key in Admin API Keys.
Permission review
Static risk signals and limitations
Network access
The documentation includes network, browsing, or remote request actions.
URL: https://dc01.acme.localWrites files
The documentation asks the agent to create, modify, or delete local files.
**Organize with folders** - Create a logical folder hierarchy per companyEvidence record
Why each signal appears
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 94/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 39 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Provenance and original SKILL.md
- Repository
- wyre-technology/msp-claude-plugins
- Skill path
- msp-claude-plugins/hudu/hudu/skills/passwords/SKILL.md
- Commit
- c1011303bfd2a65abc9b260884d9858d1a482a6f
- License
- Apache-2.0
- Collected
- 2026-08-06
- Default branch
- main
View the original SKILL.md
Hudu Passwords Management
Overview
Passwords in Hudu (called "asset passwords" in the API) provide secure credential storage scoped to companies. They allow MSP technicians to store, organize, and retrieve credentials for client infrastructure, applications, and services. Password access can be restricted at the API key level, and all access is logged in Hudu's activity logs.
Critical API naming note: The Hudu UI calls these "Passwords," but the API endpoint is /api/v1/asset_passwords. Always use asset_passwords in API calls.
Anti-triggers
- A credential needed to authenticate a tool call — Hudu passwords document the customer's credentials. They are never the connector's own auth: gateway credentials are brokered centrally and are not readable from anywhere in this plugin. An agent that reaches here to "find the API key" has taken a wrong turn.
- A credential stored on an asset rather than as a password record —
many MSPs put licence keys and service accounts in asset custom fields.
Those are not
asset_passwords; usehudu-assets. - The same credential in IT Glue — the other documentation platform in
this marketplace stores passwords too, with its own permission model.
Start from
it-glue-api-patterns. - Resetting or rotating the credential on the actual system — this
skill updates the documented value only. Changing the real password is a
tenant or directory operation; use
cipp-usersorm365-users. Editing the record without changing the system leaves documentation that is confidently wrong.
Key Concepts
Password Organization
Passwords are organized by:
- Company - Each password belongs to a specific company
- Password Folders - Hierarchical folder structure within a company
- Name - Descriptive name identifying the credential
Company: Acme Corporation
+-- Passwords
+-- Infrastructure
| +-- Domain Admin - ACME
| +-- Local Admin - Servers
| +-- vCenter Admin
+-- Network
| +-- Firewall Admin
| +-- Switch Admin
| +-- WiFi Controller
+-- Applications
| +-- ERP Admin
| +-- CRM Admin
+-- Cloud Services
+-- Microsoft 365 Global Admin
+-- AWS Root Account
API Key Password Permission
API keys in Hudu can be configured to allow or deny password access:
| Permission | Effect |
|---|---|
| Enabled | API key can read/write password values |
| Disabled | API key cannot access password values (403 Forbidden) |
This is configured per API key in Admin > API Keys.
Security Audit Trail
Hudu logs all password access in the activity logs (/api/v1/activity_logs) — who accessed it, when, and what action (view, create, update, delete):
GET /api/v1/activity_logs?resource_type=AssetPassword&resource_id=789
Fields
Core fields: company_id (required), name (required), username, password, url, description, password_type, otp_secret, password_folder_id.
See references/fields.md for the complete field reference.
API Patterns
| Operation | Request |
|---|---|
| List / filter | GET /api/v1/asset_passwords?company_id=123&name=Domain Admin&page=1 |
| Get one | GET /api/v1/asset_passwords/789 |
| Create | POST /api/v1/asset_passwords with { "asset_password": { ... } } |
| Update | PUT /api/v1/asset_passwords/789 |
| Delete | DELETE /api/v1/asset_passwords/789 (requires DELETE permission) |
GET on a single password returns the plaintext password value in the response body. Treat every response from this endpoint as sensitive.
See references/api.md for the complete endpoint catalog with request/response examples.
Output Safety
Never include actual password values in:
- Correlation summaries or reports
- Log files
- Chat output or conversation history
- Error messages
- Any output that may be visible to unauthorized users
When displaying password information, always mask the actual value:
Password: Domain Admin - ACME
Username: [email protected]
Password: **************
URL: https://dc01.acme.local
Common Workflows
Secure Password Creation
async function createSecurePassword(companyId, data) {
const password = await createAssetPassword({
company_id: companyId,
name: data.name,
username: data.username,
password: data.password,
url: data.url,
description: `Created: ${new Date().toLocaleDateString()}\nPurpose: ${data.purpose}`,
password_type: data.type,
password_folder_id: data.folderId
});
return password;
}
Password Rotation Workflow
Hudu keeps no rotation history of its own — append rotation dates to description so the audit trail survives.
async function rotatePassword(passwordId, newPassword, reason) {
// Get current password info (for logging, not the value)
const current = await getAssetPassword(passwordId);
// Update with new password
const updated = await updateAssetPassword(passwordId, {
password: newPassword,
description: `${current.description || ''}\nRotated: ${new Date().toLocaleDateString()} - ${reason}`
});
return updated;
}
Password Search by Context
The API filters only on name and company_id; matching against description or URL requires a client-side pass.
async function findPasswordsForServer(companyId, serverName) {
const passwords = await fetchAssetPasswords({ company_id: companyId });
return passwords.filter(p =>
p.name.toLowerCase().includes(serverName.toLowerCase()) ||
p.description?.toLowerCase().includes(serverName.toLowerCase()) ||
p.url?.toLowerCase().includes(serverName.toLowerCase())
);
}
Find Stale Passwords
async function findStalePasswords(companyId, daysOld = 90) {
const cutoffDate = new Date();
cutoffDate.setDate(cutoffDate.getDate() - daysOld);
const passwords = await fetchAssetPasswords({ company_id: companyId });
return passwords
.filter(p => new Date(p.updated_at) < cutoffDate)
.map(p => ({
id: p.id,
name: p.name,
username: p.username,
lastUpdated: p.updated_at,
daysSinceUpdate: Math.floor(
(new Date() - new Date(p.updated_at)) / (1000 * 60 * 60 * 24)
)
}));
}
Password Inventory Report
async function generatePasswordReport(companyId) {
const passwords = await fetchAssetPasswords({ company_id: companyId });
const byType = {};
passwords.forEach(p => {
const type = p.password_type || 'Uncategorized';
if (!byType[type]) byType[type] = [];
byType[type].push({
name: p.name,
username: p.username,
url: p.url,
lastUpdated: p.updated_at
// NEVER include actual password values in reports
});
});
return byType;
}
Gotchas
- Endpoint is
asset_passwords, notpasswords. The UI name and the API name differ;/api/v1/passwordsdoes not exist. - 403 on this endpoint is a key-permission problem, not a bad key. Password access is a per-API-key toggle in Admin > API Keys — a key that works everywhere else can still 403 here.
urlappears twice in responses with different meanings: the credential's login URL on create/update, and the Hudu record URL in the read payload's metadata. Do not round-trip it blindly.- Every read is logged. Bulk enumeration of passwords generates a visible audit trail; scope by
company_idrather than sweeping the tenant. - Deletion is unrecoverable and drops the audit context. Prefer keeping stale credentials with a rotation note.
See references/errors.md for the complete error and validation table plus a secure error-handling pattern.
Security Best Practices
Access Control
- Restrict API key permissions - Only enable password access on keys that need it
- Use company-scoped keys - Limit API keys to specific companies when possible
- IP whitelist - Restrict API key usage to known IPs
- Regular access reviews - Audit who has API keys with password access
Password Hygiene
- Regular rotation - Rotate passwords on schedule (90 days recommended)
- Unique passwords - Never reuse passwords across systems
- Track changes - Update description when passwords are rotated
- Monitor stale passwords - Alert on passwords not updated recently
Documentation Hygiene
- Use descriptive names - Include system name and account type (e.g., "Domain Admin - ACME")
- Set password type - Classify passwords (Administrative, Network, Application, etc.)
- Organize with folders - Create a logical folder hierarchy per company
- Document purpose - Use the description field to explain what the password is for
- Track URLs - Always include the login URL when applicable
- Include 2FA - Store TOTP secrets with the
otp_secretfield
Related Skills
- Hudu Companies - Password company scope
- Hudu Assets - Device-related credentials
- Hudu Articles - Embedding passwords in articles
- Hudu Websites - Website credentials
- Hudu API Patterns - API reference
Alternatives
Compare before choosing
mgiovani/cc-arsenal
team-review
Multi-agent review team: architecture, security, performance, testing, style, docs/UX, plus an adversary that cross-examines the other 6, for security-sensitive, architectural, or large PRs (15+ files) where a single-agent pass risks missing cross-cutting issues. Use for auth/payments/PII changes, schema/pattern changes, compliance sign-off, or when asked to 'get the review team on this' / 'multi-agent review' / 'thorough review before merge'. For a standard PR or a quick pre-merge check, use /r
Borda/AI-Rig
review
Multi-agent code review of local Python files, directories, or the current git diff covering architecture, tests, performance, docs, lint, security, and API design. Scope: Python source files in local working tree. Python-file-free targets (pure JS/TS/Go/Rust projects) are out of scope. TRIGGER when: user asks to review local Python files, a directory, or the current git diff/working-tree changes, with no GitHub PR number involved; phrases: "review this", "review my changes", "code review this d
bytedance/deer-flow
code-documentation
Use this skill when the user requests to generate, create, or improve documentation for code, APIs, libraries, repositories, or software projects. Supports README generation, API reference documentation, inline code comments, architecture documentation, changelog generation, and developer guides. Trigger on requests like "document this code", "create a README", "generate API docs", "write developer guide", or when analyzing codebases for documentation purposes.
Borda/AI-Rig
review
Multi-agent code review of GitHub Pull Requests (Python source, documentation (Markdown/RST), and CI/CD config PRs) covering architecture, tests, performance, docs, lint, security, and API design. TRIGGER when: user provides a GitHub PR number (e.g. 42, #42) and asks to review/audit/check it, or provides a saved review-report path with --reply to draft a contributor-facing comment; phrases: 'review PR 123', 'audit this pull request', 'look at PR #42', 'draft a reply for this review report'. SKIP