SSL Certificate Manager

Auto-renew and monitor SSL certificates on your VPS with PicoClaw

Security✓ SafeBeginnerv1.0.0
Last verified:2026-06-01

About

Manages SSL certificates on your VPS automatically. Checks expiry dates, renews via Let's Encrypt, reloads nginx or Apache after renewal and alerts you if renewal fails. Never let a certificate expire again.

Use Cases

  • Auto-renew Let's Encrypt certificates before they expire
  • Alert 30 days before a manually installed certificate expires
  • Reload nginx automatically after a successful renewal

What SSL Certificate Manager can access

Broad access

Read this skill's SKILL.md in full before installing it. Run it against a disposable host or test account first, and give it the narrowest credentials that still work.

  • Runs commands on the host

    This skill executes commands on the machine running the agent. That is the broadest permission you can grant: anything the agent user can do, this skill can do.

    This skill's own description refers to "nginx"

  • Changes system or network configuration

    It modifies host-level configuration such as firewall rules, certificates or service definitions. A mistake here can lock you out of the machine.

    This skill's own description refers to "ssl"

These permissions are inferred from this listing — the credentials it declares, any maintainer warning, and the operations its own description mentions. ClawVault has not audited this skill's source code. Treat it as a starting point for your own review, not a substitute for one.

Installing SSL Certificate Manager on PicoClaw

PicoClaw does not have a skill-install command. Capabilities come from two places: skill packages, which are SKILL.md directories under workspace/skills/, and built-in tool groups configured in config.json under the tools field, which covers web, mcp, exec, cron and skills. MCP servers are managed through the mcp CLI command group.

  1. 1

    Create the skill directory

    mkdir -p workspace/skills/ssl

    PicoClaw discovers skills as directories under workspace/skills/. Each one contains a SKILL.md describing the procedure, which the agent loads on demand.

  2. 2

    Write the SKILL.md

    $EDITOR workspace/skills/ssl/SKILL.md

    Keep it short. Sipeed's own skill-creator guidance is explicit that the context window is a shared resource: include only what the model does not already know, and make each paragraph justify its token cost.

  3. 3

    Enable the tool groups it needs

    $EDITOR config.json

    The tools field in config.json controls the web, mcp, exec, cron and skills groups. A skill that shells out needs exec enabled; a scheduled one needs cron. Leave filter_sensitive_data on so API keys and tokens are stripped from tool output before it reaches the model.

  4. 4

    Or connect an MCP server instead

    picoclaw mcp

    For capabilities that already exist as an MCP server, the mcp command group manages those entries in your config rather than writing a skill by hand.

Commands follow the official PicoClaw documentation. Placeholders such as <owner> are filled in by the search step, because registry references are publisher-scoped.

Version & Updates

Current Version
1.0.0
Last Updated
2026-06-01

Safety & verification

Listed as safe
No known issues reported for this skill in the PicoClaw ecosystem.

How PicoClaw screens skills

PicoClaw filters sensitive values such as API keys and tokens out of tool results before they are sent to the model, controlled by filter_sensitive_data (on by default) and filter_min_length. Because exec grants shell access, enable it only when a skill genuinely needs it.

Recommended

Running on a VPS?

Deploy OpenClaw, Hermes, or PicoClaw on Bluehost with the right template for the job.

Related Skills in Security