Agent skill

Validate Opensecret

by MaplePrivacyLabs in MaplePrivacyLabs/Maple

Select and run backend Rust, disposable database, encrypted client, provider, Nix, and EIF/PCR evidence matching an OpenSecret change.

MITAuto-check passedDevOps & Cloud

Install Validate Opensecret

skills CLI
$ npx skills add MaplePrivacyLabs/Maple --skill validate-opensecret -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MaplePrivacyLabs/Maple validate-opensecret --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MaplePrivacyLabs/Maple.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/validate-opensecret .claude/skills/validate-opensecret && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-opensecret
GitHub stars
100
Token cost
~1.1k tokens
SKILL.md length
456 words
Files
4 (incl. scripts, references)
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Select and run backend Rust, disposable database, encrypted client, provider, Nix, and EIF/PCR evidence matching an OpenSecret change.

  • DevOps & Cloud work in your project
  • SKILL.md covers Select the relevant evidence, Preserve boundaries and Handoff
  • Runs Shell scripts from its folder; calls cargo

What it does

Validate Opensecret is an agent skill from MaplePrivacyLabs/Maple. Select and run backend Rust, disposable database, encrypted client, provider, Nix, and EIF/PCR evidence matching an OpenSecret change. Use before backend handoff or to assess API, provider, persistence, security, build, or deployment validation claims.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `agents/openai.yaml`, `references/checks.md` and `scripts/disposable_db_tests.sh`).

It sits in DevOps & Cloud. It works with Rust. The repository describes itself as: Maple - Private AI Chat. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/validate-opensecret”

Requirements

  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit f8ab3e5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate Opensecret loads about 1.1k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 456 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from MaplePrivacyLabs/Maple at commit f8ab3e5, republished under its MIT licence (© MaplePrivacyLabs). 456 words, ~1,080 tokens.

Download SKILL.mdSave it as .claude/skills/validate-opensecret/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
validate-opensecret
description
Select and run backend Rust, disposable database, encrypted client, provider, Nix, and EIF/PCR evidence matching an OpenSecret change. Use before backend handoff or to assess API, provider, persistence, security, build, or deployment validation claims.

Validate OpenSecret

Read root/component AGENTS.md, diff/source/tests, and the owning workflow. Commands use services/opensecret/ and its pinned Nix shell unless they explicitly enter the monorepo root. This is one package, not a Cargo workspace.

Any backend code change and client/backend/log/billing integration requires an isolated linked Local stack. Preserve externally generated environments, ports, database state, accounts, and process ownership. Read the shared environment/login contract.

Select the relevant evidence

ChangeChecks
DocumentationVerify changed paths, commands, variables, links, and claims
Rust behavior/dependencyFocused tests, then exact Rust CI (Tier 1)
Auth/encryption/persistence/migrationTier 1 plus disposable migrated DB/security suites (Tier 2) when state is involved
HTTP/middleware/SSE/Responses/client contractTier 1 plus encrypted client smoke (Tier 4), including affected SDK/app paths
Provider/model/routing/headers/usage/attestationTier 1 and focused tests; live provider/client proof only when that claim needs it
Nix/entrypoint/kernel/packagingAffected Rust gates plus current-host flake/build evidence (Tier 5)
Authorized publication/deploymentLinux/ARM64 release artifact and reviewed EIF/PCR evidence (Tier 5), followed by separately authorized operations

Load validation procedures only for the applicable tiers; higher-level proof supplements relevant lower-level checks. The default Rust CI has no DB service and does not run ignored tests. Never blanket-run cargo test --locked -- --ignored: it mixes disposable DB mutation and credentialed live-provider tests. Use the guarded disposable DB helper for the selected suites; read its procedure before invoking it.

For migrations, prove empty-database upgrade and the latest down/up when appropriate. Data conversions also need representative pre-change rows, restart/retry/rollback evidence, and the owning key. A synthetic database pass does not prove user-key data conversion or live OAuth providers.

Show full SKILL.md (203 more words)Show less

Preserve boundaries

  • Pure checks disable stateful shell hooks; migrations/test DBs target only identified disposable local state. Keep secrets and user content out of commands/logs/fixtures/tracked files.
  • Health is liveness only. Protected API proof uses the SDK/encrypted client with route-appropriate auth, not plaintext HTTP. Local baseline accounts use supported encrypted password/fixture paths.
  • Inspect each consumer manifest/lock for the actual SDK source/version. The root in-tree SDK integration tests both SDKs against this backend; it does not prove an application, published SDK, or live provider.
  • Live provider probes require explicit scope for credentials, network/cost, and named provider; default tests do not establish live availability.
  • Ordinary PRs do not require new PCR approvals. Distinguish EIF build failure from measurement mismatch. Never copy/sign approvals to clear a check. Read PCR compatibility and cache boundaries when those inputs change; local cache hits cannot prove fresh hosted caches.
  • Signing, PCR/history changes, KMS/IAM, shared/remote migrations, artifact transfer, enclave lifecycle, secrets writes, staging, and deployment require explicit authority. CI artifact/signing evidence is not deployment proof.

Handoff

Report commit/dirty state, host, exact commands/results and pass/ignored/skip counts, disposable DB lifecycle, selected API/account/integrations, runtime scenarios, and unverified boundaries. Label unit/static, disposable DB, encrypted full stack, provider, Linux/Nitro/PCR, and deployed evidence separately. Failed/skipped/interrupted/partial checks remain exactly that.

© MaplePrivacyLabs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in .agents/skills/validate-opensecret of MaplePrivacyLabs/Maple.

  • SKILL.md
  • agents/openai.yaml
  • references/checks.md
  • scripts/disposable_db_tests.sh

Open the folder on GitHubat commit f8ab3e5

Compare with similar skills

Validate Opensecret next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate Opensecret compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate Opensecret this skillMaplePrivacyLabs/Maple100—~1.1kAutomated safety check: PassMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Rocketmq Rust Local Clustermxsm/rocketmq-rust1.5k—~2kAutomated safety check: PassApache-2.0
GitHub Actions CreatorFNOSP/FlyNarwhal4951 repos~2.4kAutomated safety check: PassAGPL-3.0
Asupersync Mega SkillDicklesworthstone/asupersync281—~2.9kAutomated safety check: PassCustom licence
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Rocketmq Rust Local Cluster

    mxsm/rocketmq-rust

    Set up, start, verify, inspect, and stop local development clusters from the current rocketmq-rust checkout.

    1.5k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • GitHub Actions Creator

    FNOSP/FlyNarwhal

    A skill your agent uses when the user wants to create, generate, or set up a GitHub Actions workflow.

    495 GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Asupersync Mega Skill

    Dicklesworthstone/asupersync

    Build, migrate, debug, and maintain Asupersync. An agent skill from Dicklesworthstone/asupersync.

    281 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • Syncmeta

    pawurb/hotpath-rs

    Sync changes from the hotpath, hotpath-macros and hotpath-drain crates to their meta counterparts (hotpath-meta, hotpath-macros-meta and hotpath-drain-meta).

    1.9k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from MaplePrivacyLabs/Maple

All 14 skills in this repo
  • Release Maple

    MaplePrivacyLabs/Maple

    Prepare, publish, monitor, and verify a Maple release from current master.

    100 GitHub stars~5.5k tokensUpdated today
    Auto-check passed
  • Develop Maple

    MaplePrivacyLabs/Maple

    Implement ordinary Research client features and fixes in React/Vite/Tauri, including its web, desktop, and mobile paths.

    100 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes
  • Develop Maple Proxy

    MaplePrivacyLabs/Maple

    Develop and review the maple-proxy Rust crate, binary, container, and OpenAI-compatible HTTP behavior under Maple's proxy directory.

    100 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Develop Opensecret SDK

    MaplePrivacyLabs/Maple

    Develop and review the Maple TypeScript/React and Rust SDKs under Maple's sdk directory.

    100 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Review Opensecret Security

    MaplePrivacyLabs/Maple

    Review security-sensitive OpenSecret changes and claims. An agent skill from MaplePrivacyLabs/Maple.

    100 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Validate Maple

    MaplePrivacyLabs/Maple

    Select and run Maple component checks, platform builds, and exact-runtime smoke evidence for the changed behavior.

    100 GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Validate Opensecret

What does Validate Opensecret do?

Select and run backend Rust, disposable database, encrypted client, provider, Nix, and EIF/PCR evidence matching an OpenSecret change. Validate Opensecret is an agent skill from MaplePrivacyLabs/Maple. Select and run backend Rust, disposable database, encrypted client, provider, Nix, and EIF/PCR evidence matching an OpenSecret change.

When should I use Validate Opensecret?

Validate Opensecret fits situations like: devOps & Cloud work in your project.

How do I install Validate Opensecret in Claude Code?

Run `npx skills add MaplePrivacyLabs/Maple --skill validate-opensecret -a claude-code`. Or copy the skill folder (.agents/skills/validate-opensecret in MaplePrivacyLabs/Maple) into .claude/skills/validate-opensecret in your project. Claude Code loads it when a task matches its description.

How do I install Validate Opensecret in Codex?

Run `npx skills add MaplePrivacyLabs/Maple --skill validate-opensecret -a codex`. Or copy the skill folder (.agents/skills/validate-opensecret in MaplePrivacyLabs/Maple) into .agents/skills/validate-opensecret in your project. Codex loads it when a task matches its description.

Can I use Validate Opensecret in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MaplePrivacyLabs/Maple --skill validate-opensecret -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-opensecret, .gemini/skills/validate-opensecret, .github/skills/validate-opensecret and .opencode/skills/validate-opensecret in your project.

What does Validate Opensecret need to run?

Going by SKILL.md and its folder, Validate Opensecret needs a shell for the scripts in its folder and the command-line tools its instructions call (cargo). Our summary lists: A Bash shell.

Does Validate Opensecret access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Validate Opensecret safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Validate Opensecret use?

Validate Opensecret is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate Opensecret use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Validate Opensecret?

Skills that share tags, products or a category with Validate Opensecret: GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Rocketmq Rust Local Cluster (mxsm/rocketmq-rust, 1.5k stars), GitHub Actions Creator (FNOSP/FlyNarwhal, 495 stars) and Asupersync Mega Skill (Dicklesworthstone/asupersync, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate Opensecret?

MaplePrivacyLabs (a GitHub organization) maintains it in MaplePrivacyLabs/Maple, which has 100 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 8, 2026.

Source: MaplePrivacyLabs/Maple on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.