Agent skill

Change Opensecret API

by MaplePrivacyLabs in MaplePrivacyLabs/Maple

Change or review OpenSecret HTTP contracts and their SDK or Maple consumers.

MITAuto-check passedBackend & APIs

Install Change Opensecret API

skills CLI
$ npx skills add MaplePrivacyLabs/Maple --skill change-opensecret-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MaplePrivacyLabs/Maple change-opensecret-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/change-opensecret-api .claude/skills/change-opensecret-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
change-opensecret-api
GitHub stars
100
Token cost
~1.8k tokens
SKILL.md length
890 words
Files
2
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Change or review OpenSecret HTTP contracts and their SDK or Maple consumers.

  • Works in 5 steps: method, path, middleware order, and… → decryption and typed or extensible… → authorization, storage, provider, and… → …
  • Authentication context
  • SKILL.md covers Trace the live contract, Preserve transport and…, Preserve stateful Responses… and Coordinate pinned consumers, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Change Opensecret API is an agent skill from MaplePrivacyLabs/Maple. Change or review OpenSecret HTTP contracts and their SDK or Maple consumers. Use for routes, authentication context, attested encrypted requests or responses, OpenAI-shaped payloads, Responses or conversation persistence, errors, SSE streaming, cancellation, or cross-client compatibility.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs. It works with OpenAI. The repository describes itself as: Maple - Private AI Chat. The licence is MIT.

When your agent uses it

  • Authentication context
  • Attested encrypted requests
  • OpenAI-shaped payloads
  • Conversation persistence

Example prompts

  • “/change-opensecret-api”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. method, path, middleware order, and established auth context;
  2. decryption and typed or extensible request validation;
  3. authorization, storage, provider, and usage side effects;
  4. status, headers, body or SSE projection, and error mapping;
  5. focused tests, released SDK support, and pinned Maple consumers.

What it can do on your machine

Read from SKILL.md and the folder at commit f8ab3e5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Change Opensecret API loads about 1.8k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 890 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MaplePrivacyLabs/Maple at commit f8ab3e5, republished under its MIT licence (© MaplePrivacyLabs). 890 words, ~1,782 tokens.

Download SKILL.mdSave it as .claude/skills/change-opensecret-api/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
change-opensecret-api
description
Change or review OpenSecret HTTP contracts and their SDK or Maple consumers. Use for routes, authentication context, attested encrypted requests or responses, OpenAI-shaped payloads, Responses or conversation persistence, errors, SSE streaming, cancellation, or cross-client compatibility.

Change the OpenSecret API

Treat OpenSecret, released SDKs, and affected Maple paths as one versioned protocol. Preserve existing public behavior unless the task deliberately changes it.

Read the monorepo-root AGENTS.md and services/opensecret/AGENTS.md. Backend source paths below are relative to services/opensecret/; run backend commands there through its pinned Nix shell. Consumer paths in the coordination section are relative to the monorepo root.

Normative rules in this skill govern new or changed code; they do not certify untouched paths. Re-confirm current behavior from source and tests. If an unrelated path conflicts with a rule, keep that observation task-local and do not broaden the change without user approval.

Trace the live contract

Derive the route from current router assembly in src/main.rs and its module in src/web/; do not maintain a copied endpoint table. Trace one request through:

  1. method, path, middleware order, and established auth context;
  2. decryption and typed or extensible request validation;
  3. authorization, storage, provider, and usage side effects;
  4. status, headers, body or SSE projection, and error mapping;
  5. focused tests, released SDK support, and pinned Maple consumers.

Use router assembly as the authority for outer authentication and the route module as the authority for inner session/decryption middleware. Use src/web/openai.rs for OpenAI-shaped inference routes and src/web/responses/ for Responses, conversations, tools, persistence, and events.

For Transport V2, also trace src/transport_v2/gateway.rs and src/transport_v2/session.rs from the mounted routes in src/main.rs. V1 and V2 transport coexist; establish which path the actual SDK invokes. Transport V2 and Router V2 are separate mechanisms, so a transport version does not establish the selected inference router.

Preserve transport and identity boundaries

  • OpenAI-shaped describes the decrypted payload, not a plaintext wire API. Protected routes require the OpenSecret attestation/session protocol and a route-appropriate auth context.
  • A session protects transport; it does not establish user identity, project membership, or storage-key ownership. Bodyless protected routes still validate and touch the session.
  • JWT and API-key contexts are distinct. Preserve the auth method through authorization, persistence eligibility, quota, and usage attribution.
  • Hold the session lease for the complete response body or stream. Successful protected responses and ordinary stream events remain encrypted according to the established client protocol.
  • Validate provider-free input before writes. Pinned clients may recover from selected session or auth failures by retrying, so a side-effecting change needs explicit idempotency or proof that validation precedes the effect.

Inspect src/web/attestation_routes.rs, src/web/encryption_middleware.rs, session state in src/main.rs, src/web/openai_auth.rs, and src/jwt.rs when the change reaches those boundaries. Do not duplicate their policy inside a handler.

Derive errors from the response type actually returned by the route. Handlers returning ApiError use its mapping in src/main.rs; route-local error types may intentionally differ. For a new or intentionally revised contract, use stable HTTP semantics and sanitized public bodies. Once a changed stream has started, use its typed encrypted error event rather than introducing an unauthenticated plaintext data frame.

Show full SKILL.md (421 more words)Show less

Preserve stateful Responses behavior

Read src/web/responses/handlers.rs, constants.rs, events.rs, and context_builder.rs together with the response/conversation models and schema. Derive supported fields and event names from those files rather than from upstream API documentation.

Preserve these ordering rules unless the contract change explicitly replaces them:

  • authenticate, authorize ownership, validate payload/model limits, and build context before durable writes;
  • check ownership before decrypting or mutating user content;
  • keep user content in its established user-key encryption domain;
  • persist assistant, reasoning, tool, and output items in emitted order;
  • keep event names, decrypted type, sequence policy, terminal status, cancellation, and durable item ordering consistent.

Do not equate a dropped client stream with explicit cancellation. Define and test the disconnect points affected by the change, and claim background continuation only after source and tests establish independent task ownership at those points.

Coordinate pinned consumers

Use the same Maple checkout: SDK source lives under sdk/, Research consumers under apps/maple-research/frontend/, and the GPUI prototype under apps/maple-agent/. Search from the monorepo root without hiding errors and follow each component's guide and applicable skills. If an affected consumer cannot be exercised, report compatibility as unverified rather than falling back to the retired standalone SDK repository or claiming there are no consumers.

Maple's browser Research path uses Responses/Conversations through the TypeScript client, while native Agent Mode uses chat completions through the Rust client. A semantic change intended for both is two protocol integrations, not one shared wire-field edit. Trace request construction, provider handoff, persistence, and usage in each affected path.

Use the SDK source and application dependency resolutions recorded by the selected Maple revision. The frontend's package.json and bun.lock, and each Rust consumer's Cargo manifest and lockfile, select a published SDK or local source. Follow the SDK consumer version policy. Validate SDK source changes separately from consumers pinned to a published version; update only the consumers intended to adopt the changed contract. Update SDK types, custom-fetch adaptation, native transport allowlists, call sites, mocks, and fixtures only where the contract reaches them. Test old-client/new-server and new-client/old-server behavior. Prefer server-first rollout for compatible additions; use an explicit capability/version gate when either direction cannot interoperate.

Validate the changed boundary

Run focused owning-module tests while iterating, then load $validate-opensecret for the complete gate. Exercise protected contracts through a pinned encrypted client, not plaintext curl, and cover each auth mode the change affects. Include the applicable Maple browser or native path for a client-facing change.

Label evidence precisely: unit contract, encrypted SDK call, provider-backed stream, Maple browser, Maple native, or deployed environment. One layer does not prove the others.

© MaplePrivacyLabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/change-opensecret-api of MaplePrivacyLabs/Maple.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit f8ab3e5

Compare with similar skills

Change Opensecret API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Change Opensecret API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Change Opensecret API this skillMaplePrivacyLabs/Maple100—~1.8kAutomated safety check: PassMIT
Geoflowyaojingang/GEOFlow3.8k—~722Automated safety check: PassAGPL-3.0
Frontend API ContractsOpenHands/OpenHands90k—~390Automated safety check: PassMIT
FastapiOpen-TutorAi/open-tutor-ai-CE1082 repos~2.6kAutomated safety check: PassBSD-3-Clause
Stripe Best Practiceskanchengw/cnllm1753 repos~925Automated safety check: PassApache-2.0
Xquik MCPXquik-dev/x-twitter-scraper2091 repos~997Automated safety check: PassMIT

Similar skills

  • Geoflow

    yaojingang/GEOFlow

    Operate/develop GEOFlow CLI/Laravel/admin/API, topics/专题 and topic tasks, theme libraries/replication, sites/leads/Agent, channel sync and legacy yao-geoflow-cli/design/template migration.

    3.8k GitHub stars~722 tokensUpdated today
    Backend & APIsAuto-check passed
  • Frontend API Contracts

    OpenHands/OpenHands

    This skill should be used when the user asks to "add an API call", "change a backend", "update settings persistence", "change conversation events", "fix backend auth", "add Agent Server support", or…

    90k GitHub stars~390 tokensUpdated today
    Backend & APIsAuto-check passed
  • Fastapi

    Open-TutorAi/open-tutor-ai-CE

    FastAPI best practices and conventions. An agent skill from Open-TutorAi/open-tutor-ai-CE.

    108 GitHub starsUsed in 2 repos~2.6k tokens
    Backend & APIsAuto-check passed
  • Stripe Best Practices

    kanchengw/cnllm

    Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…

    175 GitHub starsUsed in 3 repos~925 tokens
    Backend & APIsAuto-check passed
  • Xquik MCP

    Xquik-dev/x-twitter-scraper

    Connect, verify, and troubleshoot Xquik's remote MCP server.

    209 GitHub starsUsed in 1 repo~997 tokens
    Backend & APIsAuto-check passed
  • Opensource Guide Coach

    calf-ai/calfkit-sdk

    A skill your agent uses when a user wants guidance on starting, contributing to, growing, governing, funding, securing, or sustaining an open source project, or asks about contributor onboarding…

    149 GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed

More from MaplePrivacyLabs/Maple

All 14 skills in this repo
  • Release Maple

    MaplePrivacyLabs/Maple

    Prepare, publish, monitor, and verify a Maple release from current master.

    100 GitHub stars~5.5k tokensUpdated today
    Auto-check passed
  • Develop Maple

    MaplePrivacyLabs/Maple

    Implement ordinary Research client features and fixes in React/Vite/Tauri, including its web, desktop, and mobile paths.

    100 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes
  • Develop Maple Proxy

    MaplePrivacyLabs/Maple

    Develop and review the maple-proxy Rust crate, binary, container, and OpenAI-compatible HTTP behavior under Maple's proxy directory.

    100 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Develop Opensecret SDK

    MaplePrivacyLabs/Maple

    Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory.

    100 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Review Opensecret Security

    MaplePrivacyLabs/Maple

    Review security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple.

    100 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Validate Maple

    MaplePrivacyLabs/Maple

    Select and run Maple component checks, platform builds, and exact-runtime smoke evidence for the changed behavior.

    100 GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Change Opensecret API

What does Change Opensecret API do?

Change or review OpenSecret HTTP contracts and their SDK or Maple consumers. Change Opensecret API is an agent skill from MaplePrivacyLabs/Maple. Change or review OpenSecret HTTP contracts and their SDK or Maple consumers.

When should I use Change Opensecret API?

Change Opensecret API fits situations like: authentication context; attested encrypted requests; openAI-shaped payloads; conversation persistence.

How do I install Change Opensecret API in Claude Code?

Run `npx skills add MaplePrivacyLabs/Maple --skill change-opensecret-api -a claude-code`. Or copy the skill folder (.agents/skills/change-opensecret-api in MaplePrivacyLabs/Maple) into .claude/skills/change-opensecret-api in your project. Claude Code loads it when a task matches its description.

How do I install Change Opensecret API in Codex?

Run `npx skills add MaplePrivacyLabs/Maple --skill change-opensecret-api -a codex`. Or copy the skill folder (.agents/skills/change-opensecret-api in MaplePrivacyLabs/Maple) into .agents/skills/change-opensecret-api in your project. Codex loads it when a task matches its description.

Can I use Change Opensecret API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MaplePrivacyLabs/Maple --skill change-opensecret-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/change-opensecret-api, .gemini/skills/change-opensecret-api, .github/skills/change-opensecret-api and .opencode/skills/change-opensecret-api in your project.

What does Change Opensecret API need to run?

SKILL.md names no scripts, command-line tools or credentials: Change Opensecret API is instructions for the agent only.

Does Change Opensecret API access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Change Opensecret API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Change Opensecret API use?

Change Opensecret API is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Change Opensecret API use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Change Opensecret API?

Skills that share tags, products or a category with Change Opensecret API: Geoflow (yaojingang/GEOFlow, 3.8k stars), Frontend API Contracts (OpenHands/OpenHands, 90k stars), Fastapi (Open-TutorAi/open-tutor-ai-CE, 108 stars) and Stripe Best Practices (kanchengw/cnllm, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Change Opensecret API?

MaplePrivacyLabs (a GitHub organization) maintains it in MaplePrivacyLabs/Maple, which has 100 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 8, 2026.

Source: MaplePrivacyLabs/Maple on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.