namecheap
Manage DNS records for domains registered with Namecheap via their API. List domains, view/add/update/remove DNS host entries (A, AAAA, CNAME, MX, T…
它会碰到什么
逐条看命中(4 条严重或高危)
- 高
namecheap.py:80cred-envreadapi_user = os.environ.get("NAMECHEAP_API_USER") - 高
namecheap.py:81cred-envreadapi_key = os.environ.get("NAMECHEAP_API_KEY") - 高
namecheap.py:256cred-envreados.environ["NAMECHEAP_API_USER"] = api_user
- 高
namecheap.py:257cred-envreados.environ["NAMECHEAP_API_KEY"] = api_key
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Namecheap DNS Management
UTILITY SKILL — manages DNS records via the Namecheap API.
USE FOR: "add DNS record", "update A record", "manage Namecheap domains", "set CNAME", "add MX record", "add TXT record", "list my domains", "show DNS records", "namecheap setup", "configure namecheap API", "what is my public IP"
DO NOT USE FOR: domain registration/purchase, SSL certificate management, hosting configuration, non-Namecheap DNS providers
Workflow
First-time Setup
Before executing any API commands, verify credentials are configured:
- Check for existing config — look for
~/.namecheap-api - If not configured, guide the user through setup:
a. Show public IP — run python3 namecheap.py public-ip to display the user's public IP
b. Instruct IP whitelisting — tell the user to go to https://ap.www.namecheap.com/settings/tools/apiaccess/, enable API (select ON), and whitelist the displayed IP
c. Have the user run setup themselves — ask the user to run python3 namecheap.py setup directly in their own terminal. The script prompts for the username and reads the API key with a hidden prompt (getpass), writes ~/.namecheap-api with chmod 600, and validates the connection. Never ask the user to paste their API key into the chat, and never log, echo, or display the API key value. If you cannot run an interactive terminal for the user, instruct them to run setup themselves, or to export NAMECHEAP_API_USER and NAMECHEAP_API_KEY as environment variables in their own shell — rather than collecting the secret via ask_user.
d. Confirm — once the user reports setup succeeded, proceed with DNS operations.
DNS Operations
Use the namecheap.py script (bundled in this skill's directory) for all API interactions. It requires only Python 3 (standard library only — no pip install needed) and works the same on macOS, Linux, and Windows:
# Show public IP (for setup)
python3 namecheap.py public-ip
# Run setup flow
python3 namecheap.py setup
# List domains
python3 namecheap.py domains.getList
# Get nameservers for a domain (shows if using Namecheap DNS or custom)
python3 namecheap.py domains.dns.getList --domain example.com
# Get DNS records for a domain
python3 namecheap.py domains.dns.getHosts --domain example.com
# Add a single record (preserves existing records)
python3 namecheap.py dns.addHost --domain example.com --type A --name www --address 1.2.3.4 --ttl 1800
# Remove a single record
python3 namecheap.py dns.removeHost --domain example.com --type A --name www --address 1.2.3.4
# Replace all records from a JSON file
python3 namecheap.py domains.dns.setHosts --domain example.com --hosts records.json
# Switch to Namecheap default DNS
python3 namecheap.py domains.dns.setDefault --domain example.com
# Switch to custom nameservers
python3 namecheap.py domains.dns.setCustom --domain example.com --nameservers ns1.cloudflare.com,ns2.cloudflare.com
# Get email forwarding rules
python3 namecheap.py domains.dns.getEmailForwarding --domain example.com
# Set email forwarding (single rule)
python3 namecheap.py domains.dns.setEmailForwarding --domain example.com --mailbox info --forward-to user@gmail.com
# Set email forwarding (from JSON file)
python3 namecheap.py domains.dns.setEmailForwarding --domain example.com --forwards forwards.json
# Create a child nameserver (glue record)
python3 namecheap.py domains.ns.create --domain example.com --nameserver ns1.example.com --ip 1.2.3.4
# Delete a child nameserver
python3 namecheap.py domains.ns.delete --domain example.com --nameserver ns1.example.com
# Get nameserver info
python3 namecheap.py domains.ns.getInfo --domain example.com --nameserver ns1.example.com
# Update nameserver IP
python3 namecheap.py domains.ns.update --domain example.com --nameserver ns1.example.com --old-ip 1.2.3.4 --ip 5.6.7.8
JSON file formats
domains.dns.setHosts --hosts records.json expects an array of objects with Namecheap API field names:
[
{ "HostName": "@", "RecordType": "A", "Address": "1.2.3.4", "TTL": 1800 },
{ "HostName": "www", "RecordType": "CNAME", "Address": "@", "TTL": 1800 },
{ "HostName": "@", "RecordType": "MX", "Address": "mail.example.com.", "TTL": 1800, "MXPref": 10 }
]
domains.dns.setEmailForwarding --forwards forwards.json expects an array of mailbox rules:
[
{ "MailBox": "info", "ForwardTo": "team@example.net" },
{ "MailBox": "sales", "ForwardTo": "owner@example.net" }
]
Behavior
- Always check credentials first. Before any API operation, verify
~/.namecheap-apiexists and is readable. If not, run the setup flow. - Show current records before modifying. Before adding or removing records, always fetch and display the current DNS records so the user can confirm the change.
- Use
ask_userto confirm destructive changes. Before removing records or replacing all records withsetHosts, confirm with the user. - The Namecheap
setHostsAPI replaces ALL records. Never calldomains.dns.setHostsdirectly unless you have fetched all existing records first. Usedns.addHostanddns.removeHostfor safe single-record operations — they handle the fetch-modify-write cycle internally. - Explain TTL in human terms. When the user asks about TTL, explain that 1800 = 30 minutes, 3600 = 1 hour, etc.
- Handle multi-part TLDs. Domains like
example.co.ukhave SLD=example and TLD=co.uk. The script recognizes a built-in list of common second-level suffixes (e.g.co.uk,com.au,co.jp,com.br). This list is best-effort and not a full public-suffix database — if a domain with an unlisted multi-part suffix returns a2019166("Domain not found") error, the SLD/TLD split was likely wrong. In that case, confirm the registered domain with the user and report the limitation.
Credential Storage
Credentials are stored in ~/.namecheap-api:
NAMECHEAP_API_USER="username"
NAMECHEAP_API_KEY="api-key-here"
This file must have 600 permissions (owner read/write only). Alternatively, the script reads credentials from the NAMECHEAP_API_USER and NAMECHEAP_API_KEY environment variables, which take precedence over the file when both are set.
Supported Record Types
A, AAAA, CNAME, MX, MXE, TXT, URL, URL301, FRAME
References
See references/namecheap-api.md for full API documentation including request/response formats.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。