All authors

Claude Skills by apache
github.com/apache88 skills0 installs14 views
- Cve AllocateWalk a governance-authorised member through allocating a CVE for a tracker: allocate it through the `<cve-tool>` API when the tool supports it, else print the allocation link and title and take the allocated ID, then update the tracker (field, label, rollup, CVE JSON) and hand off to `security-issue-sync`.Votes: 0GitHub stars: 108
- Issue DeduplicateMerge two <tracker> tracking issues that describe the same root-cause vulnerability, preserving every reporter's credit, every mailing-list thread reference, and every independent attack-vector description. Updates the kept issue's body in place, closes the duplicate with the `duplicate` label, and regenerates the CVE JSON attachment so both finders land in `credits[]`.Votes: 0GitHub stars: 108
- Issue FixFix a tracked security issue in a public `<upstream>` PR: sync the tracker, propose a plan, and on confirmation write the change, open the PR from the user's fork, and update the tracker. Public content never reveals the CVE or the security nature of the change.Votes: 0GitHub stars: 108
- Issue Import From MdOpen one or more `<tracker>` tracking issues from a markdown file containing a batch of security findings. Each finding becomes one tracker landing in the `Needs triage` board column. The file itself is the full report — there is no inbound reporter to reply to and no PR to inspect.Votes: 0GitHub stars: 108
- Issue Import From PrOpen a tracker for a security-relevant fix that already exists as a public `<upstream>` PR, with no `<security-list>` report. The tracker lands in `Assessed` with scope, PR-state and remediation fields filled from the PR; pairs with `security-cve-allocate`.Votes: 0GitHub stars: 108
- Issue Import From ScanTriage a security scanner's multi-finding output (via a scan-format adapter; ASVS is the reference), bucket each finding, and apply only the operator's confirmed decisions. Publishes the report as a gist and can open a report-back PR.Votes: 0GitHub stars: 108
- Issue Import Via ForwarderSub-skill for reports relayed onto `<security-list>` by a broker (the ASF security team, a disclosure platform, a SOC) rather than sent by the reporter. Detects the relay, extracts the credit and the reporter-addressing rules through the adapters in `forwarders.enabled`, and hands the routing back. Never mutates the tracker.Votes: 0GitHub stars: 108
- Issue ImportImport new `<security-list>` reports into `<tracker>`: find threads not yet tracked, propose the imports (default: import unless rejected), create each tracker in `Needs triage`, and draft a receipt reply to the reporter. First step of the handling process.Votes: 0GitHub stars: 108
- Issue InvalidateClose a tracker as invalid: label, closing comment, board archive, and — for `<security-list>` imports — a polite-but-firm reply draft to the reporter with the team's reasoning. No reporter outreach for trackers imported from a public PR.Votes: 0GitHub stars: 108
- Issue SyncSynchronize a security issue in <tracker> with the state of its GitHub discussion, the <security-list> mailing thread, and any <upstream> PRs that fix it. The skill gathers all relevant signals and proposes label / milestone / assignee / field / draft-email updates — applying only what the user has explicitly confirmed. Suggests the next step in the handling process and prints the CVE allocation link when a CVE is needed.Votes: 0GitHub stars: 108
- Issue TriageClassify each `needs triage` tracker as VALID / DEFENSE-IN-DEPTH / INFO-ONLY / INVALID / PROBABLE-DUP / FIX-ALREADY-PUBLIC and, on confirmation, post a triage-proposal comment for the team. Read-only on tracker state. `--retriage` reopens a decided case after new activity.Votes: 0GitHub stars: 108
- Model PrepareProduce a first security model for a project that has none: draft it with `<governance-body>` (draft-first, provenance-tagged), then land the model and its `AGENTS.md` → `SECURITY.md` chain as one PR per repository. Proposes; the maintainers decide.Votes: 0GitHub stars: 108
- Model UpdateRefresh a published security model from the project's decision history (tracker dispositions, advisories, canned responses). Proposes new known-non-finding entries (§1.15) and a model-gap list, regression-checked against past valid reports. Read-only on the tracker.Votes: 0GitHub stars: 108
- Model VerifyCheck a published security model per repository: is it reachable via `AGENTS.md` → `SECURITY.md` at a named commit, and does it cover the minimum-bar sections? Proposes one fix per failing check (a PR for mechanical gaps, mail to `<governance-body>` for substantive ones).Votes: 0GitHub stars: 108
- Tracker Stats DashboardGenerate a self-contained HTML dashboard of `<tracker>` repository statistics for security-team review.Votes: 0GitHub stars: 108
- Isolated Setup DoctorProbe the secure-agent setup for restrictions that block legitimate work — SSH agent reachability, port binding, containers, the scratch directory, the signing key, `gh` outside the sandbox, `prek` and `uv` inside it, the global git hook dir. Names the troubleshooting entry and settings fix for each. Read-only.Votes: 0GitHub stars: 108
- Isolated Setup InstallWalk an adopter through the first-time install of the secure agent setup (sandbox, approval and clean-environment layers) for Claude Code, Codex or Gemini CLI. Interactive throughout; never runs sudo, edits a shell rc, or overwrites settings on its own.Votes: 0GitHub stars: 108
- Isolated Setup UpdateReport drift between the installed secure setup and the framework's current one — checkout, pinned tools, user-scope script copies, denial commands, MCP checkouts. Read-only: it surfaces diffs and the user decides.Votes: 0GitHub stars: 108
- Isolated Setup VerifyCheck the secure agent setup against its checklist and report done, missing or partial for each item, with the evidence — paths, command output, versions. Covers Claude Code, Codex and Gemini CLI. Read-only.Votes: 0GitHub stars: 108
- Override UpstreamPromote a local `.apache-magpie-overrides/<skill>.md` into a PR against `apache/magpie`. Once it merges and the adopter upgrades, the override is redundant and the skill offers to remove it.Votes: 0GitHub stars: 108
- Privacy LlmDecide which LLMs this project's skills may send private foundation content to, then prove it. Detects the stack in use, writes <project-config>/privacy-llm.md, and runs the approved-model gate and the PII redactor end to end so the result is demonstrated rather than declared.Votes: 0GitHub stars: 108
- SetupInstall Magpie, configure it for yourself, or adopt it for a repo. Installing touches only this machine; configuring writes gitignored local files; adopting commits a floor and the project's configuration for every contributor. Marketplace by default, pinned snapshot as fallback.Votes: 0GitHub stars: 108
- Shared Config SyncCommit and push the user's shared Claude config to the `~/.claude-config` sync repo, rebasing first so a push never buries work from another machine. Bootstraps the repo when it is missing. Never force-pushes, never rewrites pushed history, never creates a public remote, and touches nothing outside `~/.claude-config/`.Votes: 0GitHub stars: 108
- StatusShow how Magpie is adopted in this repo — install method and pin, drift, wired agent targets, installed skill families, symlink health — and change that wiring from the same view. The change itself runs through the setup skill.Votes: 0GitHub stars: 108
- Upstream FixTurn a framework defect the agent hit while running a Magpie skill into a fix PR against `apache/magpie`, one PR per defect. Confirms it is a framework bug rather than local misconfiguration or a stale snapshot, then searches for an existing issue or PR and points at that instead of opening a duplicate.Votes: 0GitHub stars: 108
- List SkillsPrint a human-readable index of every skill installed for this repository, grouped by the family each one declares, with the name to invoke it by and the first sentence of its `description`. Discovery is installation-aware: it covers a pinned snapshot install, the framework checkout, and marketplace plugin installs, so the index matches what the agent can actually run. Generated on every run from live `SKILL.md` frontmatter, so it never goes stale when skills are added, removed, or rewritten.Votes: 0GitHub stars: 108
- Optimize SkillMake an existing framework skill leaner without changing its behavior. Diagnose context-cost smells, propose the applicable optimization passes, and validate before and after every approved change.Votes: 0GitHub stars: 108
- Report Framework IssueHelp an adopter or framework developer file a clean, redacted GitHub issue against the Apache Magpie framework repo when a skill, tool, or doc misbehaves. It gathers the problem from the user — never from the raw session transcript — then runs a mandatory public-disclosure scrub before rendering the report into the framework's `bug_report` / `change_proposal` issue template, checking for duplicates, and filing via `gh issue create --web` only on explicit confirmation. The scrub is the point: ...Votes: 0GitHub stars: 108
- Skill ReconcilerCompare two near-duplicate skills — typically an ASF variant and a non-ASF or multi-project variant — and classify every difference as ALLOWED, DRIFT, or SAFETY-BASELINE. Produces a structured diff and a reconciliation proposal. Read-only: it never rewrites either skill; convergence is a separate confirmed authoring step. A safety-baseline divergence is always a must-fix, never silently merged into allowed-divergence noise.Votes: 0GitHub stars: 108
- Write SkillWrite a new skill for the Apache Magpie framework, or bring an existing one up to current conventions. Scaffolds the directory, walks the house style and the prompt-injection defences, and validates before it ships.Votes: 0GitHub stars: 108
- Generate Cve JsonGenerate a CVE 5.x JSON document from an <tracker> tracking issue, ready to paste into the Vulnogram `#source` tab of the ASF CVE tool at https://cveprocess.apache.org/cve5/<CVE-ID>#source. The conversion is deterministic: same issue in, same JSON bytes out. Handles multiple credits (one per line) and multiple references (URLs extracted from the issue's "Public advisory URL" and "PR with the fix" fields; the "Security mailing list thread" field is treated as internal-only and never exported).Votes: 0GitHub stars: 108
- CalibrateDerive committer and <governance-body> reference levels from the project's own past nomination decisions on <private-list>, deliberately relaxed below what was elected, and propose them as a numbers-only config diff.Votes: 0GitHub stars: 108
- Candidate ScreenSurface details about likely committer and <governance-body> candidates — deliberately more people than would be picked — as an alphabetical list with a short summary, in a verified-private repository. Never a ranking or a readiness verdict.Votes: 0GitHub stars: 108
- Identity MapMap a contributor's GitHub handle to their Slack, Discord, Matrix, mailing-list, and social-media identities. Infers each mapping from the sources the session can reach, grades the evidence, and records only what the maintainer confirms, in a project-wide identity file shared by the contributor-growth skills.Votes: 0GitHub stars: 108
- AptAdd released versions of Apache SkyWalking AI Sessionizer to its apt repository, static/apt in apache/skywalking-website, which the website serves at https://skywalking.apache.org/apt. Verifies the voted .deb packages, adds them to the index with apt-ftparchive, signs the index with the release manager's key, writes the .htaccess redirects, installs through them with apt, and opens a pull request to apache/skywalking-website. Use after a version is published.Votes: 0GitHub stars: 6
- CollectCollect this machine's local Claude Code conversation data with the asz collector. Resolves the local Claude data directory (honouring CLAUDE_CONFIG_DIR and XDG_CONFIG_HOME), builds the binary, lists what is discoverable, and lands everything into the storage root. Use when asked to collect, backfill, re-collect, or inspect local Claude Code sessions, or to check what the collector can see.Votes: 0GitHub stars: 6
- HomebrewAdd released versions of Apache SkyWalking AI Sessionizer to its Homebrew tap, Formula/ on main in apache/skywalking-ai-sessionizer. Writes asz@VERSION from the voted packages, moves asz to the newest version, checks every formula with brew, and opens a pull request to main in this repository. Use after a version is published, or to add older released versions.Votes: 0GitHub stars: 6
- PypiPublish a released version of the Apache SkyWalking AI Sessionizer LangChain plugin, apache-skywalking-asz-langchain, to PyPI. Says what a release manager sets up before the first upload, downloads the voted source package, verifies it, builds the source distribution and the wheel from plugins/langchain inside it, checks and installs them, and uploads them with twine. Use after a version is published.Votes: 0GitHub stars: 6