Agent skill

Change Opensecret Provider

by MaplePrivacyLabs in MaplePrivacyLabs/Maple

Change or review OpenSecret inference and web-provider integrations.

MITAuto-check passedAI & LLM Engineering

Install Change Opensecret Provider

skills CLI
$ npx skills add MaplePrivacyLabs/Maple --skill change-opensecret-provider -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MaplePrivacyLabs/Maple change-opensecret-provider --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/change-opensecret-provider .claude/skills/change-opensecret-provider && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
change-opensecret-provider
GitHub stars
102
Token cost
~2.4k tokens
SKILL.md length
1,171 words
Files
2
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Change or review OpenSecret inference and web-provider integrations.

  • Model catalog entries
  • SKILL.md covers Trace the live provider path, Preserve the public contract, Preserve routing context and Preserve transport and retry…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Provider routing

What it does

Change Opensecret Provider is an agent skill from MaplePrivacyLabs/Maple. Change or review OpenSecret inference and web-provider integrations. Use for model catalog entries or aliases, provider routing, Tinfoil or standard-provider transport, credentials, attestation, request or response canonicalization, retries, headers, cache namespaces, usage accounting, audio or embeddings, web search, or extraction.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in AI & LLM Engineering, covering Model routing and gateways, Embeddings and Accounting and bookkeeping. The repository describes itself as: Maple - Private AI Chat. The licence is MIT.

When your agent uses it

  • Model catalog entries
  • Provider routing
  • Standard-provider transport
  • Response canonicalization

Example prompts

  • “/change-opensecret-provider”

What it can do on your machine

Read from SKILL.md and the folder at commit b48eec6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Change Opensecret Provider loads about 2.4k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 1,171 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MaplePrivacyLabs/Maple at commit b48eec6, republished under its MIT licence (© MaplePrivacyLabs). 1,171 words, ~2,352 tokens.

Download SKILL.mdSave it as .claude/skills/change-opensecret-provider/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
change-opensecret-provider
description
Change or review OpenSecret inference and web-provider integrations. Use for model catalog entries or aliases, provider routing, Tinfoil or standard-provider transport, credentials, attestation, request or response canonicalization, retries, headers, cache namespaces, usage accounting, audio or embeddings, web search, or extraction.

Change an OpenSecret provider

Keep providers behind the backend boundary. Clients select public models and capabilities; OpenSecret owns provider selection, credentials, transport, provider-model translation, request policy, response normalization, and usage attribution.

Read the monorepo-root AGENTS.md and services/opensecret/AGENTS.md. Source and documentation paths below are relative to services/opensecret/; run backend commands there through its pinned Nix shell.

Trace the live provider path

Derive the current graph from source instead of copying provider or model inventories:

  • src/model_config.rs: canonical public IDs, aliases, capabilities, limits, visibility, and access.
  • src/provider_registry.rs and src/inference_planning.rs: V2 route topology, deterministic planning, and eligible same-model providers.
  • src/provider_routing.rs: provider selection using coherent health snapshots and accepted-route stickiness.
  • src/inference.rs and src/inference/health.rs: inference intent and IDs, typed outcomes, capacity/circuit state, snapshots, and probe leases.
  • src/proxy_config.rs: provider endpoints and credentials.
  • src/provider_client.rs: standard and attested transport, headers, streaming, and retry decisions.
  • src/web/openai.rs and src/web/responses/: route-specific request rewriting, shared preparation/execution, pinning, canonical response projection, tools, and usage. responses/image_describer.rs owns the image model candidates; its callers use the shared executor.
  • src/web/web_routes.rs and src/kagi.rs: public web contracts and the Kagi search/extract adapter.

Trace the changed public model or capability through every affected layer and its tests. Historical parity notes can explain intent, but current source and pinned consumers define the contract.

Preserve the public contract

  • Configure public model behavior centrally. Do not add an ID only in a route response or selector.
  • Keep public IDs provider-neutral and pinned. Resolve aliases before routing, translate immediately before send, and canonicalize provider IDs in both streaming and non-streaming responses.
  • Route from authenticated identity and backend policy. Never accept a caller-supplied provider, upstream model ID, routing flag, or another user's cache namespace.
  • Keep model capability, access, routing, endpoint/credential resolution, transport, and route orchestration in their owning layers.
  • Treat current-turn reasoning and replay of prior reasoning as separate model capabilities. Prove provider-specific behavior before encoding it as policy.
  • Take each catalog model's Responses sampling and reasoning-history rule from its creator's model card, generation config, or usage guide, and cite the source beside the entry in src/model_config.rs. Do not invent shared defaults. Chat Completions forwards the caller's own sampling.

When billing or feature flags affect the path, treat them only as configured external HTTP APIs. Keep their credentials backend-only and test the changed call site's unavailable, timeout, denial, fallback, and success semantics.

Preserve routing context

Completion requests use Router V2. Keep image and title helpers on the request's authenticated account and plan routing context. A helper candidate identifies a public model; resolve its provider through shared routing rather than pinning an independently guessed provider. Router retirement does not remove Transport V1 or change the public API versions.

Trace alias resolution separately from model selection and provider selection. Router V2 resolves an Auto alias to its tier's preferred model, then src/inference/auto_model.rs may choose another compiled candidate of that tier before context assembly, persistence, and route pinning when every route of the preferred model is unavailable under the shared route and capacity gates. Explicit selections never change public model, and the chosen model still goes through the same-model provider planner and first-send claim. Before any provider send, a chosen Auto model that cannot hold the request or loses its routes earns exactly one further decision with that model excluded; after the first send the logical response stays pinned. Router V2 also prefers the account's remembered route from src/inference/sticky_routes.rs (model and provider, per surface and selector, recorded once the provider accepts a request) while it stays eligible and the account has not been idle for the sticky window. Do not infer inactive behavior from historical Shadow type names: active V2 selection consumes health snapshots.

Capacity gates are keyed by provider and upstream model for every provider. A 429, 503, or 529 opens only that model's capacity gate; route-health state remains separate. Preserve atomic probe claims and lease-fenced recovery so ordinary in-flight successes cannot close a gate opened by another request.

Preserve first-send claim handling and later-turn pinning. A claim lost before the first send may select another same-model provider; later Responses tool turns remain pinned and may fail locally. Neither permits replaying an upstream attempt with an ambiguous outcome. Rebuild provider-specific request fields when a permitted pre-send selection changes the route.

Validate the affected combinations of explicit/Auto model, Free/Paid access, Responses/Chat Completions, and main/title/image execution. Keep live rollout percentages, account allocations, and operator procedures out of this public skill.

Show full SKILL.md (450 more words)Show less

Preserve transport and retry safety

Tinfoil and ordinary OpenAI-compatible providers are distinct trust boundaries. Preserve Tinfoil discovery, attestation, origin-bound TLS, bounded recovery, and the no-downgrade rule. A new standard provider needs an explicit endpoint, authentication, confidentiality, and error policy; an OpenAI-shaped API alone does not establish those properties.

Classify custom provider bases and credential forwarding from parsed current configuration, not string intuition. Cover exact approved hosts and adversarial hostnames when changing URL or credential behavior.

Retry only when the transport proves request bytes were not accepted. Do not replay an ambiguous completion POST after a timeout, response error, provider status, or partial stream without an explicit idempotency and accounting design. A refresh task must not retain a request body or inherit one caller's cancellation accidentally.

Own outbound data

  • Replace inbound authorization with the configured provider credential and keep secrets out of URLs, public responses, client configuration, evidence, and logs.
  • Review forwarded headers and Connection-named headers explicitly. The backend owns host, framing, content type, credentials, and provider-managed request fields.
  • Derive cache namespaces from authenticated backend identity. Strip or replace caller-controlled provider cache fields according to the selected provider policy.
  • Log only bounded, allowlisted metadata. Sanitize upstream errors before returning them publicly.

Add boundary tests for every changed header, credential, URL, cache, or request rewrite rule.

Preserve streams and usage

Parse complete frames, support the established line endings, preserve ordered JSON chunks, canonicalize model IDs, propagate cancellation, and emit exactly one terminal condition. Distinguish finish evidence from final usage frames.

Normalize usage once and retain the actual provider, canonical public model, and established JWT/API-key attribution. Do not publish successful usage for a partial or unterminated response unless the owning contract explicitly defines that outcome. Review Responses multi-turn aggregation so a tool loop does not duplicate usage.

Audio, transcription, and embeddings have independent payload, provider, limit, and retry policies in src/web/openai.rs and src/web/audio_utils.rs; do not generalize chat behavior to them.

Keep web content untrusted

Keep search and extraction separate. Normalize and authorize public HTTPS URLs under the current provenance and SSRF policy, and bound all provider results before placing them in model context. Do not grant URL authority from assistant text, snippets, diagnostics, or extracted page content. When continuation can resume tool history, reconstruct authority only from visible persisted inputs and trusted structured provider output.

Validate the changed layers

Run focused model, routing, transport, route, usage, or web-safety tests while iterating, then load $validate-opensecret. Live provider probes require explicit credential, egress, and cost authorization; keep raw evidence outside the repository and redact it.

Use docs/tinfoil-rust-sdk-parity.md for the named Tinfoil live boundary. A provider-direct probe, encrypted OpenSecret SDK smoke, and Maple smoke prove different layers; run and report each layer that the change claims.

© MaplePrivacyLabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/change-opensecret-provider of MaplePrivacyLabs/Maple.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit b48eec6

Compare with similar skills

Change Opensecret Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Change Opensecret Provider compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Change Opensecret Provider this skillMaplePrivacyLabs/Maple102—~2.4kAutomated safety check: PassMIT
Researchtaishi-i/awesome-japanese-nlp-resources1k—~3.5kAutomated safety check: NotesCC0-1.0
Agents And MiddlewareVectorSpaceLab/AREX-Skill331—~1.2kAutomated safety check: PassMIT
Agents WorkflowsVectorSpaceLab/AREX-Skill331—~500Automated safety check: PassApache-2.0
Datapack Builderw95/awesome-claude-corporate-skills2441 repos~6kAutomated safety check: PassMIT
Langchain Cost Tuningjeremylongshore/tons-of-skills-marketplace2.8k—~4.9kAutomated safety check: PassMIT

Similar skills

  • Research

    taishi-i/awesome-japanese-nlp-resources

    Analyze current trends and challenges in Japanese NLP for a topic.

    1k GitHub stars~3.5k tokensUpdated 4 days ago
    AI & LLM EngineeringAuto-check: notes
  • Agents And Middleware

    VectorSpaceLab/AREX-Skill

    Work on the actively maintained LangChain v1 agent package: initchatmodel, createagent, structured output, tools, middleware, embeddings initialization, provider routing, and agent runtime…

    331 GitHub stars~1.2k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Agents Workflows

    VectorSpaceLab/AREX-Skill

    A skill your agent uses for giskard.agents async chat workflows, tools, prompt templates, structured outputs, retries, rate limiting, embeddings, and optional LiteLLM backend.

    331 GitHub stars~500 tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Datapack Builder

    w95/awesome-claude-corporate-skills

    Build professional financial services data packs from various sources including CIMs, offering memorandums, SEC filings, web search, or MCP servers.

    244 GitHub starsUsed in 1 repo~6k tokens
    Business, Finance & HRAuto-check passed
  • Langchain Cost Tuning

    jeremylongshore/tons-of-skills-marketplace

    Control LangChain 1.0 AI spend with accurate streaming token accounting, model tiering, provider-specific cache hit tuning, per-tenant budgets, and retry dedup.

    2.8k GitHub stars~4.9k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Openrouter Cost Controls

    jeremylongshore/tons-of-skills-marketplace

    Implement cost controls for OpenRouter API usage. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2.4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed

More from MaplePrivacyLabs/Maple

All 14 skills in this repo
  • Release Maple

    MaplePrivacyLabs/Maple

    Prepare, publish, monitor, and verify a Maple release from current master.

    102 GitHub stars~5.5k tokensUpdated yesterday
    Auto-check passed
  • Develop Maple

    MaplePrivacyLabs/Maple

    Implement ordinary Research client features and fixes in React/Vite/Tauri, including its web, desktop, and mobile paths.

    102 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes
  • Develop Maple Proxy

    MaplePrivacyLabs/Maple

    Develop and review the maple-proxy Rust crate, binary, container, and OpenAI-compatible HTTP behavior under Maple's proxy directory.

    102 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Develop Opensecret SDK

    MaplePrivacyLabs/Maple

    Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory.

    102 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Review Opensecret Security

    MaplePrivacyLabs/Maple

    Review security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple.

    102 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Validate Maple

    MaplePrivacyLabs/Maple

    Select and run Maple component checks, platform builds, and exact-runtime smoke evidence for the changed behavior.

    102 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Change Opensecret Provider

What does Change Opensecret Provider do?

Change or review OpenSecret inference and web-provider integrations. Change Opensecret Provider is an agent skill from MaplePrivacyLabs/Maple. Change or review OpenSecret inference and web-provider integrations.

When should I use Change Opensecret Provider?

Change Opensecret Provider fits situations like: model catalog entries; provider routing; standard-provider transport; response canonicalization.

How do I install Change Opensecret Provider in Claude Code?

Run `npx skills add MaplePrivacyLabs/Maple --skill change-opensecret-provider -a claude-code`. Or copy the skill folder (.agents/skills/change-opensecret-provider in MaplePrivacyLabs/Maple) into .claude/skills/change-opensecret-provider in your project. Claude Code loads it when a task matches its description.

How do I install Change Opensecret Provider in Codex?

Run `npx skills add MaplePrivacyLabs/Maple --skill change-opensecret-provider -a codex`. Or copy the skill folder (.agents/skills/change-opensecret-provider in MaplePrivacyLabs/Maple) into .agents/skills/change-opensecret-provider in your project. Codex loads it when a task matches its description.

Can I use Change Opensecret Provider in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MaplePrivacyLabs/Maple --skill change-opensecret-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/change-opensecret-provider, .gemini/skills/change-opensecret-provider, .github/skills/change-opensecret-provider and .opencode/skills/change-opensecret-provider in your project.

What does Change Opensecret Provider need to run?

SKILL.md names no scripts, command-line tools or credentials: Change Opensecret Provider is instructions for the agent only.

Does Change Opensecret Provider access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Change Opensecret Provider safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Change Opensecret Provider use?

Change Opensecret Provider is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Change Opensecret Provider use?

About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Change Opensecret Provider?

Skills that share tags, products or a category with Change Opensecret Provider: Research (taishi-i/awesome-japanese-nlp-resources, 1k stars), Agents And Middleware (VectorSpaceLab/AREX-Skill, 331 stars), Agents Workflows (VectorSpaceLab/AREX-Skill, 331 stars) and Datapack Builder (w95/awesome-claude-corporate-skills, 244 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Change Opensecret Provider?

MaplePrivacyLabs (a GitHub organization) maintains it in MaplePrivacyLabs/Maple, which has 102 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.

Source: MaplePrivacyLabs/Maple on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.