Skip to content
Back to skills

Changelog

ASecurity

The custom-service approval dialog shows, behind a collapsed "How this will be sent" disclosure, the header every request to the service will carry the pasted token in, so a user asked for an `X-Api-Key` can check it against the provider's docs. The desktop registers the header a request names (`payload.header`), shows the existing registration's header for a service this computer already has, and stores the token the user types under that header rather than as a bearer, whatever latchkey's g...

  • 413 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 30, 2026
documentationgoapi

Works with

  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 30, 2026

npx -y skills add imbue-ai/mngr --skill changelog --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Changelog?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Changelog
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/imbue-ai-changelog-90d64e47/badge)](https://www.skillsdirectory.com/skills/imbue-ai-changelog-90d64e47)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
The custom-service approval dialog shows, behind a collapsed "How this will be sent" disclosure, the header every request to the service will carry the pasted token in, so a user asked for an `X-Api-Key` can check it against the provider's docs. The desktop registers the header a request names (`payload.header`), shows the existing registration's header for a service this computer already has, and stores the token the user types under that header rather than as a bearer, whatever latchkey's generic credential example says. A request with no header keeps the bearer default; a browser sign-in shows no disclosure. The Permissions tab and the ordinary permission dialog (the one a re-auth or a service with no stored credential goes through) read the same header off the registration, so a token typed into either for such a service is stored under it too. The credential form also shows the agent's note on where to find the token (`payload.credential_instructions`), under "From the agent" and as plain text, between Mind's own instruction and the input, and keeps it up after a rejected attempt. And the form's first appearance, in answer to the Approve that registers the service, now reads as an instruction rather than a red error notice; only an attempt that sent a token and was rejected shows as a failure.

Files in this skill

  • big-kiwi.md281 B
  • danver-MIND-181-flake-fix.md1.1 KB
  • danver-MIND-189-master-password-revision-quiescence.md1.1 KB
  • danver-MIND-190-tampered-session-cookie-auth.md1.2 KB
  • danver-MIND-196-backup-gate-deterministic-running.md737 B
  • danver-MIND-205-chat-context-menu-copy-paste.md514 B
  • danver-MIND-324-sharing-icon-missing.md430 B
  • danver-ban-ratchet-justification-comments.md518 B
  • danver-behaviors-browser-authorization.md8 KB
  • danver-behaviors-readme-incipit.md217 B
  • danver-behaviors-tmr.md685 B
  • danver-behaviors-witness-tests.md1.6 KB
  • danver-crispy-comments-recovery-backend-unreachable.md539 B
  • danver-deflake-mind-197.md584 B
  • danver-deflake-mind-215.md706 B
  • danver-embed-git.md4.5 KB
  • danver-fix-mind-145-pending-record-race.md625 B
  • danver-glossary-environment-tier-entries.md672 B
  • danver-glossary-invitation-terms.md555 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…