Agent skill

Review Opensecret Security

by MaplePrivacyLabs in MaplePrivacyLabs/Maple

Review security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple.

MITAuto-check passedBackend & APIs

Install Review Opensecret Security

skills CLI
$ npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MaplePrivacyLabs/Maple review-opensecret-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-opensecret-security .claude/skills/review-opensecret-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-opensecret-security
GitHub stars
102
Token cost
~2.2k tokens
SKILL.md length
1,048 words
Files
2
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Review security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple.

  • Works in 4 steps: Read AGENTS.md, relevant source, tests,… → Confirm the revision, intended base,… → Inspect committed, staged, unstaged,… → …
  • A diff reaches attestation
  • SKILL.md covers Establish the comparison, Label the evidence, Map the boundary and Review end to end, plus 2 more sections
  • Calls git

What it does

Review Opensecret Security is an agent skill from MaplePrivacyLabs/Maple. Review security-sensitive OpenSecret changes and claims. Use when a diff reaches attestation, encrypted sessions, authentication or OAuth, key ownership, encrypted persistence, provider or web trust, external billing or flag APIs, secrets, logs, Nitro/KMS/PCR evidence, or another boundary where source, artifact, and deployed-environment claims must be separated.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs. The repository describes itself as: Maple - Private AI Chat. The licence is MIT.

When your agent uses it

  • A diff reaches attestation
  • Encrypted sessions
  • Encrypted persistence
  • External billing

Example prompts

  • “/review-opensecret-security”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read AGENTS.md, relevant source, tests, migrations, and public docs.
  2. Confirm the revision, intended base, worktree state, and submodule revisions.
  3. Inspect committed, staged, unstaged, untracked, generated, lockfile,
  4. Trace each changed value from input through authority, decryption,

What it can do on your machine

Read from SKILL.md and the folder at commit b48eec6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Opensecret Security loads about 2.2k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 1,048 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MaplePrivacyLabs/Maple at commit b48eec6, republished under its MIT licence (© MaplePrivacyLabs). 1,048 words, ~2,164 tokens.

Download SKILL.mdSave it as .claude/skills/review-opensecret-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
review-opensecret-security
description
Review security-sensitive OpenSecret changes and claims. Use when a diff reaches attestation, encrypted sessions, authentication or OAuth, key ownership, encrypted persistence, provider or web trust, external billing or flag APIs, secrets, logs, Nitro/KMS/PCR evidence, or another boundary where source, artifact, and deployed-environment claims must be separated.

Review OpenSecret security

Review the current source and diff as evidence. This skill defines a method; it does not catalogue current findings. Default to read-only review and implement changes only when the user asks.

Read both the monorepo-root guide and services/opensecret/AGENTS.md. Backend source and documentation paths below are relative to services/opensecret/; Git comparison commands apply to the whole monorepo. Run backend validation commands from the component through its pinned Nix shell.

Establish the comparison

  1. Read AGENTS.md, relevant source, tests, migrations, and public docs.

  2. Confirm the revision, intended base, worktree state, and submodule revisions. Do not rewrite user work to manufacture a clean comparison.

  3. Inspect committed, staged, unstaged, untracked, generated, lockfile, workflow, Nix, environment, migration, and submodule changes. For an origin/master comparison, include:

    sh
    git status --short --branch
    git diff origin/master...HEAD --
    git diff --cached --
    git diff --
    git ls-files --others --exclude-standard
    git submodule status
    git diff --check origin/master...HEAD --
    git diff --cached --check
    git diff --check
  4. Trace each changed value from input through authority, decryption, persistence, external calls, response encryption, errors, and logs.

Classify each observation as introduced, worsened or newly relied upon, pre-existing baseline, unrelated, or indeterminate. Only introduced or materially worsened/newly relied-upon behavior determines a scoped diff verdict. Mention baseline behavior only when needed to explain the change; keep it task-local and non-blocking unless the change depends on it, expands it, or the user requested a repository-wide audit. Mark a verdict provisional when the comparison base is uncertain.

Label the evidence

  • source-confirmed: the reviewed revision directly establishes the claim.
  • test-confirmed: a named test exercised it in this run.
  • build-confirmed: a named reproducible build or artifact check passed.
  • live-confirmed: the named deployed or external environment was exercised.
  • inferred: the claim follows from stated evidence and assumptions.
  • unverified: the required source, system, or environment was not inspected.

Local source and tests do not establish live database transport, provider behavior, billing decisions, logging policy, IAM/KMS policy, PCR trust, artifact identity, or which revision serves an environment.

Map the boundary

Identify every link the change crosses:

  • client to the OpenSecret enclave and encrypted session;
  • router to user, API-key, OAuth, project, and record authority;
  • enclave plaintext to host-visible persistence, metadata, errors, or logs;
  • OpenSecret to external model, web, OAuth, email, billing, or flag APIs;
  • enclave to its parent over VSOCK for credentials, secrets, and logs;
  • source and Nix build to EIF/PCR evidence, KMS policy, and deployment.

Client attestation of OpenSecret and OpenSecret’s attested connection to an upstream enclave prove different links. Local mock attestation proves protocol shape, not Nitro or production trust.

Review end to end

For the changed boundary, answer:

  1. What authenticated identity or capability authorizes the operation, and where is project/record ownership enforced?
  2. Who owns each key, plaintext value, persisted row, provider credential, and policy decision? Is that authority ever taken from untrusted input?
  3. Where are size, count, time, concurrency, expiry, replay, cancellation, and cleanup bounds enforced on success and failure paths?
  4. What crosses into host-visible storage, metadata, logs, errors, parent services, or external APIs? Is it necessary, bounded, and sanitized?
  5. Can client, model, provider, database, or parent-instance data gain URL, identity, routing, key, or execution authority?
  6. Are ambiguous retries, partial streams, disconnects, and restarts safe for persistence, usage, and external side effects?
  7. Does the change alter a shared SDK/client protocol, persisted format, provider contract, or deployment trust claim? What compatibility and rollback path is required?

Apply these OpenSecret-specific invariants:

  • An encryption session is transport state, not identity or authorization.
  • JWT, API-key, OAuth, user-key, and enclave/system-key domains are not interchangeable.
  • Ownership checks precede decryption or mutation; query scoping is part of authorization.
  • Provider and model output is untrusted. Provider choice, credentials, cache namespaces, URL provenance, and SSRF policy remain backend-owned.
  • Sensitive or user-controlled plaintext must not enter logs or public errors. Safe metadata is bounded and allowlisted.
  • A changed ciphertext format needs explicit versioning, compatibility, rollback, and access to the owning key; ordinary startup lacks user keys.
  • Shared protocol changes require coordinated review of the monorepo-root sdk/ source and the dependency actually resolved by each affected Maple application path. Its manifest and lockfile select a published SDK or local source; do not treat in-tree SDK validation as proof for a consumer pinned to different source. Follow the SDK consumer version policy when reviewing the selected versions and compatibility boundaries.

Use $change-opensecret-api or $change-opensecret-provider for the detailed contract procedure rather than duplicating it here.

Show full SKILL.md (349 more words)Show less

Match claims to proof and authority

Keep the evidence ladder separate:

  1. Rust tests establish local implementation behavior.
  2. Nix checks establish reviewed source/build invariants.
  3. An EIF build plus comparison with a reviewed PCR reference establishes an artifact measurement.
  4. Inspection of live KMS/IAM, client trust policy, deployed EIF, parent services, and runtime smoke establishes deployment behavior.

Load $validate-opensecret and run the tiers reached by the diff. Report local, database, provider, client, build/artifact, and live evidence separately.

Local artifact builds and read-only PCR comparison are validation when in scope. Root backend CI validates Rust, Nix checks/default binary, and SDK compatibility. A separate ARM64 workflow compares dev/prod EIF measurements on explicit approved-PCR JSON edits in PRs, relevant master changes, and manual runs. Do not require ordinary backend PRs to update approvals, and do not suppress meaningful master mismatches. Master push/manual runs and same-repository PR comparisons receive OIDC for FlakeHub caching; fork PRs and non-master manual refs use GitHub's branch-scoped cache without OIDC. Review event/ref guards and the PR head-repository equality check, including missing metadata, cache provenance, and default-branch versus PR cache scope. Same-repository PR code is intentionally trusted to write FlakeHub. Cache writes never authorize approval changes, signing, EIF releases, or deployment. A passing comparison is not live deployment evidence or proof that both public PCR locations are synchronized. Use docs/pcr-compatibility.md for manual signed-PCR validation and legacy publication. Require explicit authorization for PCR reference/history mutation, signing, KMS/IAM changes, shared or remote migrations, artifact transfer, enclave or remote-service lifecycle, secret writes, staging, deployment, or release actions. Inspect recipes before deciding whether they are read-only.

Report the review

Lead with the verdict and prioritized diff findings. For each finding, state:

  • evidence class and exact file or symbol;
  • affected boundary and required preconditions;
  • concrete impact without incident language;
  • invariant or design change required;
  • regression proof and client/deployment coordination still needed.

Then list commands run, omitted or unavailable checks, and residual uncertainty. If there are no findings, name the boundaries reviewed without implying that uninspected systems are secure. Keep revision-specific observations in the review output; promote only durable methods back into repository guidance.

© MaplePrivacyLabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/review-opensecret-security of MaplePrivacyLabs/Maple.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit b48eec6

Compare with similar skills

Review Opensecret Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Opensecret Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Opensecret Security this skillMaplePrivacyLabs/Maple102—~2.2kAutomated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from MaplePrivacyLabs/Maple

All 14 skills in this repo
  • Release Maple

    MaplePrivacyLabs/Maple

    Prepare, publish, monitor, and verify a Maple release from current master.

    102 GitHub stars~5.5k tokensUpdated today
    Auto-check passed
  • Develop Maple

    MaplePrivacyLabs/Maple

    Implement ordinary Research client features and fixes in React/Vite/Tauri, including its web, desktop, and mobile paths.

    102 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes
  • Develop Maple Proxy

    MaplePrivacyLabs/Maple

    Develop and review the maple-proxy Rust crate, binary, container, and OpenAI-compatible HTTP behavior under Maple's proxy directory.

    102 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Develop Opensecret SDK

    MaplePrivacyLabs/Maple

    Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory.

    102 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Validate Maple

    MaplePrivacyLabs/Maple

    Select and run Maple component checks, platform builds, and exact-runtime smoke evidence for the changed behavior.

    102 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Validate Opensecret

    MaplePrivacyLabs/Maple

    Select and run backend Rust, disposable database, encrypted client, provider, Nix, and EIF/PCR evidence matching an OpenSecret change.

    102 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Review Opensecret Security

What does Review Opensecret Security do?

Review security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple. Review Opensecret Security is an agent skill from MaplePrivacyLabs/Maple. Review security-sensitive OpenSecret changes and claims.

When should I use Review Opensecret Security?

Review Opensecret Security fits situations like: A diff reaches attestation; encrypted sessions; encrypted persistence; external billing.

How do I install Review Opensecret Security in Claude Code?

Run `npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a claude-code`. Or copy the skill folder (.agents/skills/review-opensecret-security in MaplePrivacyLabs/Maple) into .claude/skills/review-opensecret-security in your project. Claude Code loads it when a task matches its description.

How do I install Review Opensecret Security in Codex?

Run `npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a codex`. Or copy the skill folder (.agents/skills/review-opensecret-security in MaplePrivacyLabs/Maple) into .agents/skills/review-opensecret-security in your project. Codex loads it when a task matches its description.

Can I use Review Opensecret Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MaplePrivacyLabs/Maple --skill review-opensecret-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-opensecret-security, .gemini/skills/review-opensecret-security, .github/skills/review-opensecret-security and .opencode/skills/review-opensecret-security in your project.

What does Review Opensecret Security need to run?

Going by SKILL.md and its folder, Review Opensecret Security needs the command-line tools its instructions call (git).

Does Review Opensecret Security access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Opensecret Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Opensecret Security use?

Review Opensecret Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Opensecret Security use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Opensecret Security?

Skills that share tags, products or a category with Review Opensecret Security: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Opensecret Security?

MaplePrivacyLabs (a GitHub organization) maintains it in MaplePrivacyLabs/Maple, which has 102 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.

Source: MaplePrivacyLabs/Maple on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.