Keepassxc Secrets · max-win-at bundle Fetches, generates, or stores credentials (passwords, usernames, TOTP) from a KeePassXC vault via the `kpxc-agent` CLI. Activate when a task needs a secret from KeePassXC — provisioning or commissioning a Linux box or SBC, wiring up a service that needs a DB/API/SSH password, saving a freshly generated credential, or reading a TOTP — locally or over SSH. Also activates when the user mentions "my vault" or "password manager", or asks to generate and save a password rather than inventing one.