Magpie Security Model Prepare
apache/magpieFront door for a project that has no published security model yet. Opens the conversation with `<governance-body>` on the private list, drives production of a first draft — delegating the model-writing itself to the Alpha-Omega threat-model skill set — in **draft-first** mode so maintainers react to concrete prose instead of composing from a blank page, then lands the model and its `AGENTS.md` → `SECURITY.md` discoverability chain as one reviewable PR per repository. Every claim carries a provenance tag; every inferred claim carries a matching open question. Drafts and proposes; the maintainer...
At a glance
/plugin marketplace add apache/magpie
/plugin install magpie-security-model-prepare
Setup, runtime and requirements describe apache/magpie, the repo this skill ships in.
Also in apache/magpie
View the repoFor a batch of findings from a non-security audit tool (`<audit-tool>` — ruff / flake8 / mypy / pylint / CodeQL / Apache Verum / Apache Caer...
Read-only audit of GitHub Actions workflow runner compatibility for one repository, an explicit repository set, one Apache project with mult...
Post-vote committer and PMC onboarding for Apache projects. Walks the nominator through every step from ICLA check to welcome announcement f...
Read-only GitHub activity card for a named contributor on <upstream>. Fetches PR authorship, code-review activity, issues, and PR/issue comm...
Read-only nomination brief for a named GitHub contributor on <upstream>. Aggregates GitHub activity across all contribution tracks plus main...
Measures contributor-sentiment signals on <upstream> over a configurable window: thread tone (first-response classification), time-to-first-...
Read-only readiness tracker that maps a contributor's GitHub activity against the adopter's PMC-declared committer or PMC thresholds and sur...
Read-only dependency vulnerability audit for one repository or a local checkout. Detects the project's dependency manager(s), runs the appro...
Read-only license audit of a project's direct and transitive dependency tree. Detects the dependency manager(s), resolves each dependency's...
Read-only flaky-test detection from GitHub Actions CI run history for one repository. Parses workflow run outcomes over a configurable windo...
Draft a single net-new *good first issue* on the configured `<upstream>` repo from one supplied candidate such as a known gap or a small mai...
Sweep the open `<issue-tracker>` backlog for existing issues that could be labelled as good first issues. Classifies each candidate as READY...