Agent skill

Develop Opensecret SDK

by MaplePrivacyLabs in MaplePrivacyLabs/Maple

Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory.

MITAuto-check passedBackend & APIs

Install Develop Opensecret SDK

skills CLI
$ npx skills add MaplePrivacyLabs/Maple --skill develop-opensecret-sdk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MaplePrivacyLabs/Maple develop-opensecret-sdk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/develop-opensecret-sdk .claude/skills/develop-opensecret-sdk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
develop-opensecret-sdk
GitHub stars
100
Token cost
~1.8k tokens
SKILL.md length
769 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory.

  • Encrypted transport
  • SKILL.md covers Keep protocol ownership clear, Develop and validate, Publishing boundary and Report
  • Calls cargo, nix and bun
  • In-tree OpenSecret integration

What it does

Develop Opensecret SDK is an agent skill from MaplePrivacyLabs/Maple. Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory. Use for SDK API, authentication, attestation, encrypted transport, tests, in-tree OpenSecret integration, package contents, versions, or an explicitly authorized npm or crates.io publishing handoff; use develop-maple for application-only work.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Rust, TypeScript, npm and React. The repository describes itself as: Maple - Private AI Chat. The licence is MIT.

When your agent uses it

  • Encrypted transport
  • In-tree OpenSecret integration
  • Package contents
  • An explicitly authorized npm

Example prompts

  • “/develop-opensecret-sdk”

What it can do on your machine

Read from SKILL.md and the folder at commit f8ab3e5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • nix
    • bun
    • just
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Develop Opensecret SDK loads about 1.8k tokens when it runs. Until then it costs about 89 tokens; SKILL.md has 769 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MaplePrivacyLabs/Maple at commit f8ab3e5, republished under its MIT licence (© MaplePrivacyLabs). 769 words, ~1,762 tokens.

Download SKILL.mdSave it as .claude/skills/develop-opensecret-sdk/SKILL.md (or your agent's skills folder).
name
develop-opensecret-sdk
description
Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory. Use for SDK API, authentication, attestation, encrypted transport, tests, in-tree OpenSecret integration, package contents, versions, or an explicitly authorized npm or crates.io publishing handoff; use develop-maple for application-only work.

Develop the Maple SDK

Work from MaplePrivacyLabs/Maple/sdk. Read the repository-root AGENTS.md, sdk/README.md, the affected implementation and tests, and the root .github/workflows/sdk-*.yml files relevant to the change.

The SDK source is part of the Maple repository, but its TypeScript and Rust package boundaries remain independently versioned and publishable:

  • src/ builds @mapleai/sdk for browser and React consumers.
  • rust/ builds the maple-sdk crate (imported as maple_sdk) for native consumers.
  • apps/maple-research/frontend/package.json is authoritative for whether Maple's browser client consumes a published TypeScript version or the in-tree file:../../../sdk package.
  • Research native clients, Maple Agent, and proxy/ select their Rust SDK through their own manifests and lockfiles. Research iOS and Android use the Rust SDK for native OAuth; the embedded proxy and Goose remain desktop-only.

Follow the consumer version policy. To ship an SDK change to clients, follow the rollout order: SDK PR with version bump, publish, consumer pins, isolated app bump, release. Prefer published pins without upgrading unrelated consumers. Local links are allowed during active development, including on master; a registry-pinned client build does not exercise an SDK source edit. Test an affected consumer with the local SDK when that integration is part of the change.

Do not commit, push, open a PR, publish, or alter Maple's application dependency wiring unless the user authorizes that action.

Keep protocol ownership clear

OpenSecret owns authentication and authorization truth, public HTTP semantics, provider policy, persistence, and usage accounting. The SDKs own client-side attestation, encrypted sessions, typed contracts, authentication state, and safe transport adaptation. Maple owns application presentation and local device behavior.

For a public contract change, inspect services/opensecret/ at the same monorepo revision and both SDK implementations when they expose the affected behavior. Preserve old-client/new-server and new-client/old-server compatibility where clients can update independently. Do not weaken HTTPS, PCR validation, attestation, key exchange, randomness, retry safety, or sanitized errors to accommodate a caller.

Develop and validate

Use the SDK's pinned Nix shell. For TypeScript/React work:

sh
nix develop --no-update-lock-file -c bun install --frozen-lockfile --ignore-scripts
nix develop --no-update-lock-file -c bun run format:check
nix develop --no-update-lock-file -c bun run build

For tests without service fixtures, use the credential-free selection in .github/workflows/sdk-typescript.yml. An unfiltered bun test also collects integration tests that require a configured backend and test identities; use sdk-integration.yml for that complete local-stack setup.

For Rust work:

sh
nix develop --no-update-lock-file -c bash -lc '
  set -euo pipefail
  cd rust
  cargo fmt --all -- --check
  cargo clippy --locked --all-targets --all-features -- -D warnings
  cargo test --locked --all-features --lib
  cargo doc --locked --no-deps --all-features
'

Run focused tests while iterating, then match the root path-scoped workflows: sdk-typescript.yml, sdk-rust.yml, and sdk-supply-chain.yml as applicable. The repository pre-commit hook runs sdk/.githooks/pre-commit in this shell when SDK files are staged: the Rust format, Clippy, --lib tests, and docs, and the TypeScript format, build, and top-level unit tests. It never runs the integration suites or cargo-deny. When the change reaches backend behavior, authentication, or the encrypted wire contract, also match sdk-integration.yml. It starts disposable PostgreSQL and the in-tree services/opensecret/ backend from the same checkout, then tests both SDK implementations without a hosted development server. Inspect backend changes and run its component validation when the compatibility contract reaches them; there is no separate integration revision to advance.

Provider-spending tests remain opt-in through RUN_LIVE_AI=1 and require explicit credential, egress, and cost authorization. Both SDKs use signed-PCR histories under MaplePrivacyLabs/Maple/master/services/opensecret/, with the existing verification key and separate development/production policies. Keep the legacy OpenSecretCloud/opensecret histories available for older clients through the backend's manual compatibility procedure. Source changes do not publish SDKs or update installed clients.

Before handoff, inspect package boundaries as applicable:

sh
bun run pack
cargo package --locked --manifest-path rust/Cargo.toml

These commands validate package contents; they do not publish them. For Rust SDK changes, also run the root scripts/ci/verify-local-rust-deps.sh check and the applicable desktop/proxy validation. Check its selected SDK source before claiming Maple consumes the result.

Show full SKILL.md (202 more words)Show less

Publishing boundary

SDK publishing is separate from the Maple application release workflow. Follow docs/sdk-publishing.md. Use the separate manual sdk-publish-npm.yml and sdk-publish-rust.yml workflows on protected master; each publishes the stable version already committed for that SDK. Neither workflow creates GitHub Releases or tags, or changes the Maple application release version.

just publish-npm VERSION and just publish-cargo VERSION dispatch validation in GitHub Actions with mode=trusted and dry_run=true. They do not publish locally. Initial publication also runs in Actions under the guide's restricted bootstrap mode; registry credentials and environment administration are separately operator-owned. Normal publication uses registry trusted publishing and the protected sdk-npm or sdk-crates environment.

Setting dry_run=false authorizes an external production mutation; do that only with explicit authority for the exact package, version, registry, and source commit. Review the workflow's validated package and source commit before approving its environment. Report the immutable registry result and the run URL. Never use local npm publish or cargo publish, and never create a Maple GitHub Release merely to publish an SDK.

Report

State which SDK changed, the backend/API compatibility boundary, exact commands and results, package inspection performed, the Maple dependency pins left unchanged or deliberately updated, and every client, platform, live provider, or publishing boundary not exercised.

© MaplePrivacyLabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/develop-opensecret-sdk of MaplePrivacyLabs/Maple.

Open the folder on GitHubat commit f8ab3e5

Compare with similar skills

Develop Opensecret SDK next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Develop Opensecret SDK compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Develop Opensecret SDK this skillMaplePrivacyLabs/Maple100—~1.8kAutomated safety check: PassMIT
React Emailviclafouch/meme-studio1102 repos~3.6kAutomated safety check: PassMIT
Developing Softwaretelagod/code-abyss243—~410Automated safety check: PassMIT
Javascript SDKaiskillstore/marketplace4301 repos~3.3kAutomated safety check: PassNone
Pnpm Engineteambit/bit18k—~1.9kAutomated safety check: PassCustom licence
Testing Changespnpm/pnpm37k—~1.1kAutomated safety check: PassMIT

Similar skills

  • React Email

    viclafouch/meme-studio

    A skill your agent uses when creating HTML email templates with React components - welcome emails, password resets, notifications, order confirmations, newsletters, or transactional emails.

    110 GitHub starsUsed in 2 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Developing Software

    telagod/code-abyss

    Software development knowledge reference covering Python, Go, Rust, TypeScript, Java, C++, and Shell.

    243 GitHub stars~410 tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Javascript SDK

    aiskillstore/marketplace

    JavaScript/TypeScript SDK for inference.sh - run AI apps, build agents, integrate with all models.

    430 GitHub starsUsed in 1 repo~3.3k tokens
    Backend & APIsAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Run the tests that cover a change in the pnpm repository, in the Rust workspace (pnpm/, pnpr/) or the TypeScript CLI (pnpm11/), and recognize the cases where a scoped run passes without testing…

    37k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Create Release Checklist

    software-mansion/smelter

    Generate a GitHub release-checklist issue for a full (non-RC) release of the Smelter server and/or the TypeScript SDK.

    732 GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check: notes

More from MaplePrivacyLabs/Maple

All 14 skills in this repo
  • Release Maple

    MaplePrivacyLabs/Maple

    Prepare, publish, monitor, and verify a Maple release from current master.

    100 GitHub stars~5.5k tokensUpdated today
    Auto-check passed
  • Develop Maple

    MaplePrivacyLabs/Maple

    Implement ordinary Research client features and fixes in React/Vite/Tauri, including its web, desktop, and mobile paths.

    100 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes
  • Develop Maple Proxy

    MaplePrivacyLabs/Maple

    Develop and review the maple-proxy Rust crate, binary, container, and OpenAI-compatible HTTP behavior under Maple's proxy directory.

    100 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Review Opensecret Security

    MaplePrivacyLabs/Maple

    Review security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple.

    100 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Validate Maple

    MaplePrivacyLabs/Maple

    Select and run Maple component checks, platform builds, and exact-runtime smoke evidence for the changed behavior.

    100 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Validate Opensecret

    MaplePrivacyLabs/Maple

    Select and run backend Rust, disposable database, encrypted client, provider, Nix, and EIF/PCR evidence matching an OpenSecret change.

    100 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Develop Opensecret SDK

What does Develop Opensecret SDK do?

Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory. Develop Opensecret SDK is an agent skill from MaplePrivacyLabs/Maple. Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory.

When should I use Develop Opensecret SDK?

Develop Opensecret SDK fits situations like: encrypted transport; in-tree OpenSecret integration; package contents; an explicitly authorized npm.

How do I install Develop Opensecret SDK in Claude Code?

Run `npx skills add MaplePrivacyLabs/Maple --skill develop-opensecret-sdk -a claude-code`. Or copy the skill folder (.agents/skills/develop-opensecret-sdk in MaplePrivacyLabs/Maple) into .claude/skills/develop-opensecret-sdk in your project. Claude Code loads it when a task matches its description.

How do I install Develop Opensecret SDK in Codex?

Run `npx skills add MaplePrivacyLabs/Maple --skill develop-opensecret-sdk -a codex`. Or copy the skill folder (.agents/skills/develop-opensecret-sdk in MaplePrivacyLabs/Maple) into .agents/skills/develop-opensecret-sdk in your project. Codex loads it when a task matches its description.

Can I use Develop Opensecret SDK in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MaplePrivacyLabs/Maple --skill develop-opensecret-sdk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/develop-opensecret-sdk, .gemini/skills/develop-opensecret-sdk, .github/skills/develop-opensecret-sdk and .opencode/skills/develop-opensecret-sdk in your project.

What does Develop Opensecret SDK need to run?

Going by SKILL.md and its folder, Develop Opensecret SDK needs the command-line tools its instructions call (cargo, nix, bun, just and npm).

Does Develop Opensecret SDK access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Develop Opensecret SDK safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Develop Opensecret SDK use?

Develop Opensecret SDK is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Develop Opensecret SDK use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Develop Opensecret SDK?

Skills that share tags, products or a category with Develop Opensecret SDK: React Email (viclafouch/meme-studio, 110 stars), Developing Software (telagod/code-abyss, 243 stars), Javascript SDK (aiskillstore/marketplace, 430 stars) and Pnpm Engine (teambit/bit, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Develop Opensecret SDK?

MaplePrivacyLabs (a GitHub organization) maintains it in MaplePrivacyLabs/Maple, which has 100 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 8, 2026.

Source: MaplePrivacyLabs/Maple on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.