Skip to content
Back to skills

Changelog

ASecurity

A `custom-service` permission request may name the header a pasted token is sent as. Before, a custom service without a browser sign-in could only take `Authorization: Bearer <token>`, so an API keyed by `X-Api-Key` or any other header was out of reach even though `latchkey auth set` stores arbitrary headers. The request payload gains an optional `header`, a header line with `{token}` where the value goes, validated by the same rule as `token-capture`'s `header` plus what the gateway must nev...

  • 413 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 30, 2026
securitygoapi

Works with

  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 30, 2026

npx -y skills add imbue-ai/mngr --skill changelog --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Changelog?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Changelog
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/imbue-ai-changelog-0ebc1acb/badge)](https://www.skillsdirectory.com/skills/imbue-ai-changelog-0ebc1acb)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
A `custom-service` permission request may name the header a pasted token is sent as. Before, a custom service without a browser sign-in could only take `Authorization: Bearer <token>`, so an API keyed by `X-Api-Key` or any other header was out of reach even though `latchkey auth set` stores arbitrary headers. The request payload gains an optional `header`, a header line with `{token}` where the value goes, validated by the same rule as `token-capture`'s `header` plus what the gateway must never let a request set (`Host`, `X-Latchkey-*`), and refused alongside a `login` flow, which carries its own credential shape. The gateway extension and `custom_services.validate_credential_header` share one accept/reject corpus. The header is stored on the service's `registeredServices` entry under `mindsCredentialHeader`, read back by `registration_credential_header`, and `credential_commands.fallback_set_credentials_example` now takes the header. `custom_services.custom_service_credential_header` reads it off a `registeredServices` block by service name, and `credential_commands.set_credentials_example_for` is the one rule every credential form goes through -- the custom-service dialog's, the ordinary permission dialog's, and the Permissions tab's -- so a registration's own header beats the bearer command latchkey reports for every generic registered service, and a token typed into any of them is stored under the header the service actually takes. The payload also gains an optional `credential_instructions`: the agent's plain-text note, at most 500 characters, on where the user finds the credential, for the dialog to show beside the input; it is refused alongside `login` like `header`, and `custom_services.validate_credential_instructions` mirrors the gateway's check, counting characters the same way.

Files in this skill

  • danver-ban-ratchet-justification-comments.md533 B
  • danver-fix-host-connect-future.md705 B
  • fix-latchkey-tmp-race.md408 B
  • gabriel-beige-caiman.md1.2 KB
  • gabriel-brown-bullfinch.md260 B
  • gabriel-dashing-ringtail.md634 B
  • gabriel-external-service-fallback-skill.md1.8 KB
  • gabriel-gvisor-oom-headroom.md185 B
  • gabriel-inquisitive-ocelot.md442 B
  • gabriel-loose-salmon.md379 B
  • gabriel-peach-sparrow.md383 B
  • gabriel-porcelain-raptor.md2.1 KB
  • gabriel-recovery-verdict-policy.md535 B
  • gabriel-remarkable-lemur.md2.2 KB
  • hynek-alternate-desktops.md2.5 KB
  • hynek-atomic-file-write-fix.md1 KB
  • hynek-avoid-unnecessary-ssh-tunneling.md3.3 KB
  • hynek-bump-latchkey-to-3.10.0.md25 B
  • hynek-bump-latchkey-to-3.11.0.md25 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…