Latchkey

REVIEW · 71
Community indexed

A command-line tool that injects credentials to curl requests to known public APIs.

Downloads0
Stars120
Version1.0.0
Quality93/100 · Excellent
Trust71/100 · Sandbox only
Audit87/100 · Needs review

Supply asset profile

Coding and developer agents

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Browse track

Scenario

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Agent fit

Browser agents + CLI + Codex

Codex, Claude Code, Cursor, CLI, or custom agents.

Install

Ready

npx skills add imbue-ai/latchkey

Maintenance

fresh

10d since push

Risk

Needs review

Dependency or permission surface needs review

GitHub quality

120

93/100 Quality · 79/100 Trust

Coverage tags

CodingGitHub automationutilityagent-credentialscurl

Review notes

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent adoption scorecard

Trust, audit, and install readiness at a glance

These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.

Quality

Excellent
93

High-confidence pick with strong adoption and healthy maintenance signals.

Trust

Sandbox only
71

Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.

Audit

Needs review
87

A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.

OpenAgentSkill Trust Score v5

Human review before install

Run only in a sandbox and compare close alternatives before using it for real work.

TypeScriptCodexClaude CodeCursorOpenAgentSkill CLI

Stars

120 GitHub stars

Repo activity

120 stars, 4 forks

Maintenance

10d since push

License

MIT

Install

npx skills add imbue-ai/latchkey

Install safety

standard package or runtime install path

Permission surface

secrets or environment access, shell or command execution

Agent outcomes

No agent outcome data yet

Docs

Strong README/SKILL.md context

Risk summary

Review before production

  • Permission surface needs review: secrets or environment access, shell or command execution
  • Stars/forks activity: 120 stars, 4 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

Install readiness

Install path available

  • Install path is available
  • Repository evidence is available
  • License is declared
  • No Agent Proven outcome evidence yet

Agent-readable metadata

Machine-readable decision data for this skill.

Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.

Open JSON

Suited tasks

  • GitHub automation workflows
  • Browser agents teams
  • builders willing to evaluate younger projects
  • Inspect repository metadata

Suited agents

TypeScriptCodexClaude CodeCursorOpenAgentSkill CLIBrowser agentsCLI

Install decision

Command
npx skills add imbue-ai/latchkey
Policy
review
Human review
yes

Trust and risk

Trust
71/100
Audit
87/100
Risk level
Needs review

Outcome loop

Endpoint
/api/agent/outcome
Event ID
resolve
Outcomes
5

Install command

npx skills add imbue-ai/latchkey

Do not use when

  • teams that need a vendor-supported SLA
  • high-compliance environments without internal security review
  • No major risk signals from current metadata
  • High-risk permission hints: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Agent safety v2

43/100 · Avoid automatic install

Experimentalreview

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Resolve via API

high

Shell or command execution

Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.

medium

Browser automation

Skill may drive a browser or interact with web pages.

medium

Network access

Skill likely fetches remote pages, APIs, repositories, or external services.

medium

Filesystem access

Skill may read or write project files, documents, generated artifacts, or local workspace state.

  • High-risk permission hints: Shell or command execution, Secrets or environment access
  • Dependency or permission surface needs review

Install targets

Install this skill in your agent workflow

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

skill install

OpenAgentSkill CLI

Use the registry command when your workflow supports the OpenAgentSkill installer.

$ npx skills add imbue-ai/latchkey

Agent resolve plan

Let an agent verify fit before installing.

The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.

Open text plan

Agent should check

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Copy prompt

Task: Use Latchkey in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Latchkey%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/imbue-ai-latchkey/install
Install command: npx skills add imbue-ai/latchkey
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent handoff

Give an agent the install path, not another directory page.

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

Open install API

Agent prompt

Use Latchkey for this task. Review https://www.openagentskill.com/api/skills/imbue-ai-latchkey/install, then install with: npx skills add imbue-ai/latchkey

Registry metadata

Agent-readable profile for automatic skill selection.

This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.

Open manifest

Agent fit

93/100

GitHub automation

Platforms

TypeScript, Browser agents

Audit report

Needs review · 87/100

A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.

View audit reportView eval report

Agent decision cockpit

Primary pick for GitHub automation

Use this as a leading candidate, then validate the README and install path in your own agent stack.

93
Readiness
Adopt
Stage

Role in stack

Primary pick

Primary fit

GitHub automation

Trust label

Production-ready

Install path

Command ready

Use when

  • GitHub automation workflows
  • Browser agents teams
  • builders willing to evaluate younger projects

Evidence

  • recent repository activity
  • install command or GitHub repo available
  • 93/100 quality profile
  • 3 OpenAgentSkill engagement events

review first

  • No major risk signals from current metadata

Implementation path

  1. 1Install it in a sandbox agent and run one GitHub automation task end to end.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Trust profile

Sandbox only

Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.

71
OpenAgentSkill Trust Score

GitHub adoption

INFO

120 GitHub stars

Stars/forks activity

CHECK

120 stars, 4 forks; issue activity unavailable in current metadata

Recent maintenance

PASS

10d since push

License clarity

PASS

MIT

Good signals

  • Manually verified listing
  • AI review approved
  • Install path is available
  • Repository evidence is available
  • Recently maintained repository
  • Install command has no obvious high-risk pattern
  • Outcome loop is ready but needs first real agent run

Review before install

  • Permission surface needs review: secrets or environment access, shell or command execution
  • Stars/forks activity: 120 stars, 4 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • No real agent outcome reports yet
  • Human review required before unattended installation

Recommended action

Run only in a sandbox and compare close alternatives before using it for real work.

Quality profile

Excellent candidate for agent workflows

High-confidence pick with strong adoption and healthy maintenance signals.

93
GitHub stars
120
Freshness
10d ago
Install ready
Yes
License
MIT

Workflow fit

Use this skill in these scenarios

Workflow fit

Add it to a complete workflow

Alternative shortlist

Compare before you install

Similar skills that may fit this task.

Compare all

Overview

# Latchkey

[![npm](https://img.shields.io/npm/v/latchkey?style=flat-square)](https://npmjs.com/package/latchkey) [![CI](https://img.shields.io/github/actions/workflow/status/imbue-ai/latchkey/test.yml?style=flat-square)](https://github.com/imbue-ai/latchkey/actions) [![license](https://img.shields.io/npm/l/latchkey?style=flat-square)](LICENSE) [![downloads](https://img.shields.io/npm/dm/latchkey?style=flat-square)](https://npmjs.com/package/latchkey)

Inject API credentials into local agent requests.

**[Full documentation](https://docs.imbue.com/latchkey)**

## Quick example

```bash # User stores the credentials. latchkey auth set slack -H "Authorization: Bearer xoxb-your-token"

# Agent makes http calls. latchkey curl -X POST 'https://slack.com/api/conversations.create' \ -H 'Content-Type: application/json' \ -d '{"name":"something-urgent"}' ```

## Overview

Latchkey is a command-line tool that injects credentials into curl commands.

- `latchkey services list` - List third-party services (Slack, Google Workspace, Linear, GitHub, etc.) that are supported out-of-the-box. - (In simple cases, `latchkey services register` can be used to add basic support for a new service at runtime.) - `latchkey curl <arguments>` - Automatically inject credentials into your otherwise standard curl calls to HTTP APIs. - Credentials must already exist (see below). - `latchkey auth set <service_name> <curl_arguments>` - Manually store credentials for a service as arbitrary curl arguments. - `latchkey auth browser <service_name>` - Open a browser login pop-up window and store the resulting API credentials. - This also allows agents to prompt users for credentials. - Only some services support this option.

Latchkey is primarily designed for AI agents. By invoking Latchkey, agents can utilize user-provided credentials or prompt the user to authenticate, then continue interacting with HTTP APIs using standard curl syntax. No custom integrations or embedded credentia

Platform compatibility

typescriptFULL

Technical details

Version
1.0.0
License
MIT
Last updated
Jul 23, 2026
Published
Jul 23, 2026

Frameworks & tools

TypeScript

Decision snapshot

Primary pick

93
Ready
Adopt
Stage

recent repository activity

Audit

Install review

Install and adoption review

87
Needs review
Security
77/100
Maintenance
100/100
Install
92/100
Open full auditView eval report

Agent-proven evidence

Agent-proven evidence

Outcome reports after resolve, review, install, and one narrow run.

0
Proven
Needs first agent runAuto-install: review firstLast: Unknown
Success rate
Recent failure
Outcomes
0
Output quality
Failed
0
Not relevant
0
Installs
0
Risk blocked
0
Setup needed
0
Production
0

No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.

Install

Add to agent workflow

Free and open source. Review the report before installing into production agents.

Growth loop

Share kit

X

Scenario-led draft for Latchkey, ready for a manual X post.

Curator note
For a real agent workflow, this is a skill worth shortlisting before another blank prompt.

Latchkey: CLI tool to inject stored credentials into curl requests for AI agents interacting with public APIs.

120 stars

https://www.openagentskill.com/skills/imbue-ai-latchkey?ref=x
Open X draft
Optional reply with install command
Listing + install path for Latchkey:
https://www.openagentskill.com/skills/imbue-ai-latchkey?ref=x

Install: npx skills add imbue-ai/latchkey

Listing source

Community indexed

Claimable

This listing was indexed from public sources and is not marked official until a maintainer claim is approved.

Creator
imbue-ai
Indexed by
OpenAgentSkill community index

Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.

Claim this skill

Owner claim

Claim this skill listing

This Community indexed listing is attributed to imbue-ai but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.

Creator backlink kit

Add the evidence badges to your README

Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/imbue-ai-latchkey?metric=listed&label=Listed)](https://www.openagentskill.com/skills/imbue-ai-latchkey)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/imbue-ai-latchkey?metric=trust&label=Trust)](https://www.openagentskill.com/skills/imbue-ai-latchkey)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/imbue-ai-latchkey?metric=audit&label=Audit)](https://www.openagentskill.com/skills/imbue-ai-latchkey/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/imbue-ai-latchkey?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/imbue-ai-latchkey)

Author

I

imbue-ai

@imbue-ai

Platform fit

Health signals

GitHub stars
120
Quality score
57/100
Last GitHub push
Jul 23, 2026
Framework hints
1
OpenAgentSkill views
3
Install copies
0
Outbound clicks
0

Community signal

Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.

Trust & safety

Sandbox only

71
  • GitHub adoption120 GitHub starsINFO
  • Stars/forks activity120 stars, 4 forks; issue activity unavailable in current metadataCHECK
  • Recent maintenance10d since pushPASS
  • License clarityMITPASS
  • README/SKILL.md completenessMetadata includes enough usage and workflow contextPASS
  • Dependency/runtime riskcommand execution surface, credential or environment accessCHECK