Magpie Security Model Update
apache/magpieRefresh an existing security model from what has actually happened since it was written. Mines the decision history — `<tracker>` dispositions with their stated reasons, reporter correspondence on `<security-list>`, published advisories and the project's canned responses — then maps each outcome onto the model's own disposition set and proposes a diff. Two products: **new known-non-finding entries** (§1.15) for patterns rejected repeatedly for the same documented reason, and a **model-gap list** naming decisions the model cannot derive. Regression-checks the proposal against past valid reports...
At a glance
/plugin marketplace add apache/magpie
/plugin install magpie-security-model-update
Setup, runtime and requirements describe apache/magpie, the repo this skill ships in.
Also in apache/magpie
View the repoFor a batch of findings from a non-security audit tool (`<audit-tool>` — ruff / flake8 / mypy / pylint / CodeQL / Apache Verum / Apache Caer...
Read-only audit of GitHub Actions workflow runner compatibility for one repository, an explicit repository set, one Apache project with mult...
Post-vote committer and PMC onboarding for Apache projects. Walks the nominator through every step from ICLA check to welcome announcement f...
Read-only GitHub activity card for a named contributor on <upstream>. Fetches PR authorship, code-review activity, issues, and PR/issue comm...
Read-only nomination brief for a named GitHub contributor on <upstream>. Aggregates GitHub activity across all contribution tracks plus main...
Measures contributor-sentiment signals on <upstream> over a configurable window: thread tone (first-response classification), time-to-first-...
Read-only readiness tracker that maps a contributor's GitHub activity against the adopter's PMC-declared committer or PMC thresholds and sur...
Read-only dependency vulnerability audit for one repository or a local checkout. Detects the project's dependency manager(s), runs the appro...
Read-only license audit of a project's direct and transitive dependency tree. Detects the dependency manager(s), resolves each dependency's...
Read-only flaky-test detection from GitHub Actions CI run history for one repository. Parses workflow run outcomes over a configurable windo...
Draft a single net-new *good first issue* on the configured `<upstream>` repo from one supplied candidate such as a known gap or a small mai...
Sweep the open `<issue-tracker>` backlog for existing issues that could be labelled as good first issues. Classifies each candidate as READY...