Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Review security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple.
$ npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install MaplePrivacyLabs/Maple review-opensecret-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-opensecret-security .claude/skills/review-opensecret-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review-opensecret-security" agent skill from https://github.com/MaplePrivacyLabs/Maple/tree/master/.agents/skills/review-opensecret-security into .claude/skills/review-opensecret-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-opensecret-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/MaplePrivacyLabs/Maple/tree/master/.agents/skills/review-opensecret-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install MaplePrivacyLabs/Maple review-opensecret-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/review-opensecret-security .agents/skills/review-opensecret-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review-opensecret-security" agent skill from https://github.com/MaplePrivacyLabs/Maple/tree/master/.agents/skills/review-opensecret-security into .agents/skills/review-opensecret-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-opensecret-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install MaplePrivacyLabs/Maple review-opensecret-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/review-opensecret-security .cursor/skills/review-opensecret-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review-opensecret-security" agent skill from https://github.com/MaplePrivacyLabs/Maple/tree/master/.agents/skills/review-opensecret-security into .cursor/skills/review-opensecret-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-opensecret-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/MaplePrivacyLabs/Maple.git --path .agents/skills/review-opensecret-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install MaplePrivacyLabs/Maple review-opensecret-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/review-opensecret-security .gemini/skills/review-opensecret-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review-opensecret-security" agent skill from https://github.com/MaplePrivacyLabs/Maple/tree/master/.agents/skills/review-opensecret-security into .gemini/skills/review-opensecret-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-opensecret-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install MaplePrivacyLabs/Maple review-opensecret-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/review-opensecret-security .github/skills/review-opensecret-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review-opensecret-security" agent skill from https://github.com/MaplePrivacyLabs/Maple/tree/master/.agents/skills/review-opensecret-security into .github/skills/review-opensecret-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-opensecret-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install MaplePrivacyLabs/Maple review-opensecret-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/review-opensecret-security .opencode/skills/review-opensecret-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review-opensecret-security" agent skill from https://github.com/MaplePrivacyLabs/Maple/tree/master/.agents/skills/review-opensecret-security into .opencode/skills/review-opensecret-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-opensecret-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
review-opensecret-securityReview security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple.
Review Opensecret Security is an agent skill from MaplePrivacyLabs/Maple. Review security-sensitive OpenSecret changes and claims. Use when a diff reaches attestation, encrypted sessions, authentication or OAuth, key ownership, encrypted persistence, provider or web trust, external billing or flag APIs, secrets, logs, Nitro/KMS/PCR evidence, or another boundary where source, artifact, and deployed-environment claims must be separated.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Backend & APIs. The repository describes itself as: Maple - Private AI Chat. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b48eec6. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review Opensecret Security loads about 2.2k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 1,048 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from MaplePrivacyLabs/Maple at commit b48eec6, republished under its MIT licence (© MaplePrivacyLabs). 1,048 words, ~2,164 tokens.
.claude/skills/review-opensecret-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Review the current source and diff as evidence. This skill defines a method; it does not catalogue current findings. Default to read-only review and implement changes only when the user asks.
Read both the monorepo-root guide and services/opensecret/AGENTS.md. Backend
source and documentation paths below are relative to services/opensecret/;
Git comparison commands apply to the whole monorepo. Run backend validation
commands from the component through its pinned Nix shell.
Read AGENTS.md, relevant source, tests, migrations, and public docs.
Confirm the revision, intended base, worktree state, and submodule revisions. Do not rewrite user work to manufacture a clean comparison.
Inspect committed, staged, unstaged, untracked, generated, lockfile,
workflow, Nix, environment, migration, and submodule changes. For an
origin/master comparison, include:
git status --short --branch
git diff origin/master...HEAD --
git diff --cached --
git diff --
git ls-files --others --exclude-standard
git submodule status
git diff --check origin/master...HEAD --
git diff --cached --check
git diff --checkTrace each changed value from input through authority, decryption, persistence, external calls, response encryption, errors, and logs.
Classify each observation as introduced, worsened or newly relied upon, pre-existing baseline, unrelated, or indeterminate. Only introduced or materially worsened/newly relied-upon behavior determines a scoped diff verdict. Mention baseline behavior only when needed to explain the change; keep it task-local and non-blocking unless the change depends on it, expands it, or the user requested a repository-wide audit. Mark a verdict provisional when the comparison base is uncertain.
Local source and tests do not establish live database transport, provider behavior, billing decisions, logging policy, IAM/KMS policy, PCR trust, artifact identity, or which revision serves an environment.
Identify every link the change crosses:
Client attestation of OpenSecret and OpenSecret’s attested connection to an upstream enclave prove different links. Local mock attestation proves protocol shape, not Nitro or production trust.
For the changed boundary, answer:
Apply these OpenSecret-specific invariants:
sdk/ source and the dependency actually resolved by each affected Maple
application path. Its manifest and lockfile select a published SDK or local
source; do not treat in-tree SDK validation as proof for a consumer pinned
to different source. Follow the SDK consumer version policy
when reviewing the selected versions and compatibility boundaries.Use $change-opensecret-api or $change-opensecret-provider for the detailed
contract procedure rather than duplicating it here.
Keep the evidence ladder separate:
Load $validate-opensecret and run the tiers reached by the diff. Report local,
database, provider, client, build/artifact, and live evidence separately.
Local artifact builds and read-only PCR comparison are validation when in
scope. Root backend CI validates Rust, Nix checks/default binary, and SDK
compatibility. A separate ARM64 workflow compares dev/prod EIF
measurements on explicit approved-PCR JSON edits in PRs, relevant master
changes, and manual runs. Do not require ordinary backend PRs to update
approvals, and do not suppress meaningful master mismatches. Master push/manual
runs and same-repository PR comparisons receive OIDC for FlakeHub caching;
fork PRs and non-master manual refs use GitHub's branch-scoped cache without
OIDC. Review event/ref guards and the PR head-repository equality check,
including missing metadata, cache provenance, and default-branch versus PR
cache scope. Same-repository PR code is intentionally trusted to write FlakeHub.
Cache writes never authorize approval changes, signing, EIF releases, or
deployment. A passing comparison is not live
deployment evidence or proof that both public PCR locations are synchronized.
Use docs/pcr-compatibility.md for manual signed-PCR validation and legacy
publication. Require explicit authorization for PCR
reference/history mutation, signing, KMS/IAM changes, shared or remote
migrations, artifact transfer, enclave or remote-service lifecycle, secret
writes, staging, deployment, or release actions. Inspect recipes before
deciding whether they are read-only.
Lead with the verdict and prioritized diff findings. For each finding, state:
Then list commands run, omitted or unavailable checks, and residual uncertainty. If there are no findings, name the boundaries reviewed without implying that uninspected systems are secure. Keep revision-specific observations in the review output; promote only durable methods back into repository guidance.
© MaplePrivacyLabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/review-opensecret-security of MaplePrivacyLabs/Maple.
Open the folder on GitHubat commit b48eec6
Review Opensecret Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review Opensecret Security this skillMaplePrivacyLabs/Maple | 102 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Nestjs Best Practicesrolling-scopes/rsschool-app | 10k | 6 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Sub2API AdminWei-Shaw/sub2api | 44k | 1 repos | ~717 | Automated safety check: Pass | LGPL-3.0 | |
| Firecrawl Build Onboardingfirecrawl/firecrawl | 190k | 1 repos | ~1.4k | Automated safety check: Notes | ISC | |
| Obsidian BasesAtmosphere/atmosphere | 3.8k | 22 repos | ~3.2k | Automated safety check: Pass | Apache-2.0 |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
rolling-scopes/rsschool-app
NestJS best practices and architecture patterns for building production-ready applications.
Wei-Shaw/sub2api
Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.
firecrawl/firecrawl
Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.
Atmosphere/atmosphere
Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
MaplePrivacyLabs/Maple
Prepare, publish, monitor, and verify a Maple release from current master.
MaplePrivacyLabs/Maple
Implement ordinary Research client features and fixes in React/Vite/Tauri, including its web, desktop, and mobile paths.
MaplePrivacyLabs/Maple
Develop and review the maple-proxy Rust crate, binary, container, and OpenAI-compatible HTTP behavior under Maple's proxy directory.
MaplePrivacyLabs/Maple
Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory.
MaplePrivacyLabs/Maple
Select and run Maple component checks, platform builds, and exact-runtime smoke evidence for the changed behavior.
MaplePrivacyLabs/Maple
Select and run backend Rust, disposable database, encrypted client, provider, Nix, and EIF/PCR evidence matching an OpenSecret change.
Categories
Review security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple. Review Opensecret Security is an agent skill from MaplePrivacyLabs/Maple. Review security-sensitive OpenSecret changes and claims.
Review Opensecret Security fits situations like: A diff reaches attestation; encrypted sessions; encrypted persistence; external billing.
Run `npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a claude-code`. Or copy the skill folder (.agents/skills/review-opensecret-security in MaplePrivacyLabs/Maple) into .claude/skills/review-opensecret-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a codex`. Or copy the skill folder (.agents/skills/review-opensecret-security in MaplePrivacyLabs/Maple) into .agents/skills/review-opensecret-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-opensecret-security, .gemini/skills/review-opensecret-security, .github/skills/review-opensecret-security and .opencode/skills/review-opensecret-security in your project.
Going by SKILL.md and its folder, Review Opensecret Security needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Review Opensecret Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review Opensecret Security: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
MaplePrivacyLabs (a GitHub organization) maintains it in MaplePrivacyLabs/Maple, which has 102 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.
Source: MaplePrivacyLabs/Maple on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.