Privacy Policy
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing whether a website has a visible, accessible privacy policy link, particularly in the footer navigation.
Decide which LLMs this project's skills may send private foundation content to, then prove it.
$ npx skills add apache/magpie --skill privacy-llm -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install apache/magpie privacy-llm --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/magpie-setup/skills/privacy-llm .claude/skills/privacy-llm && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "privacy-llm" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-setup/skills/privacy-llm into .claude/skills/privacy-llm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-llm", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/apache/magpie/tree/main/plugins/magpie-setup/skills/privacy-llmType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add apache/magpie --skill privacy-llm -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install apache/magpie privacy-llm --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/magpie-setup/skills/privacy-llm .agents/skills/privacy-llm && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "privacy-llm" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-setup/skills/privacy-llm into .agents/skills/privacy-llm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-llm", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add apache/magpie --skill privacy-llm -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install apache/magpie privacy-llm --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/magpie-setup/skills/privacy-llm .cursor/skills/privacy-llm && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "privacy-llm" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-setup/skills/privacy-llm into .cursor/skills/privacy-llm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-llm", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/apache/magpie.git --path plugins/magpie-setup/skills/privacy-llm--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add apache/magpie --skill privacy-llm -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install apache/magpie privacy-llm --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/magpie-setup/skills/privacy-llm .gemini/skills/privacy-llm && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "privacy-llm" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-setup/skills/privacy-llm into .gemini/skills/privacy-llm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-llm", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install apache/magpie privacy-llmInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add apache/magpie --skill privacy-llm -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/magpie-setup/skills/privacy-llm .github/skills/privacy-llm && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "privacy-llm" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-setup/skills/privacy-llm into .github/skills/privacy-llm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-llm", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add apache/magpie --skill privacy-llm -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install apache/magpie privacy-llm --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/magpie-setup/skills/privacy-llm .opencode/skills/privacy-llm && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "privacy-llm" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-setup/skills/privacy-llm into .opencode/skills/privacy-llm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "privacy-llm", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
privacy-llmDecide which LLMs this project's skills may send private foundation content to, then prove it.
Privacy LLM is an agent skill from apache/magpie. Decide which LLMs this project's skills may send private foundation content to, then prove it. Detects the stack in use, writes <project-config/privacy-llm.md, and runs the approved-model gate and the PII redactor end to end so the result is demonstrated rather than declared.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Agent-assisted maintainership and development framework for Apache projects — Triage, Mentoring, Drafting (agent-authored fixes with human review), and Pairing (developer-side… The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d1f8f2c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvpython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
apache.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Privacy LLM loads about 2.2k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 1,023 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from apache/magpie at commit d1f8f2c, republished under its Apache-2.0 licence (© apache). 1,023 words, ~2,245 tokens.
.claude/skills/privacy-llm/SKILL.md (or your agent's skills folder).<!-- SPDX-License-Identifier: Apache-2.0
https://www.apache.org/licenses/LICENSE-2.0 -->
<!-- Placeholder convention (see ../../AGENTS.md#placeholder-convention-used-in-skill-files):
<project-config> → resolved per file: the personal layer first
(`.apache-magpie-local/` when adopted, falling back to the main
checkout's in a linked worktree; `<git-common-dir>/apache-magpie/`
when only installed), then `.apache-magpie-overrides/` (committed)
<framework> → the framework checkout or plugin root
<private-list> → the project's private PMC list
<security-list> → the project's security-report list -->
Decide which LLMs this project's skills may send private foundation content to, record that decision where the skills look for it, and prove it holds.
Two mechanisms, and this skill configures one of them:
<private-list> mail
and any other private foundation list. A skill refuses to
fetch unless every LLM in the active stack is approved. This
is what the skill configures, by picking a variant.<security-list> mail. Third
parties the reporter names are replaced with hash-prefixed
identifiers before any LLM sees them. It runs under every
variant and needs no per-variant configuration; this skill
only verifies it works.The recipes are docs/setup/privacy-llm.md;
the contract behind them is
tools/privacy-llm/tool.md.
This skill walks the recipe rather than restating it — read the
variant you land on before writing anything.
[!IMPORTANT] This is a project decision, not a personal preference. What goes in the committed copy says what the project permits for everyone's sessions. Configure locally for yourself freely; see Step 5 before promoting anything to the committed half.
Resolve privacy-llm.md through the lookup chain, per file,
local first:
privacy-llm.md in the personal layer — yours, never committed:
.apache-magpie-local/ when the project adopted Magpie (the main
checkout's, from a linked worktree that has none), else
<git-common-dir>/apache-magpie/;.apache-magpie-overrides/privacy-llm.md — committed, the
project's.Both present → say so and name which one wins here (the local one does), because a local file silently shadowing the project's answer is exactly the case an operator needs told. Offer to show the difference, then go to Step 4 and verify rather than rewrite.
Only one present → read it, report the stack it declares, and go to Step 4. Do not rewrite a working configuration because this skill happened to be invoked.
Neither → continue to Step 2. This is the first run.
Ask the user nothing you can determine. Establish what is actually in the stack:
<private-list> still wants the file, because the
redactor and the gate both read it — but the variant is the
simple one and the interview is one question shorter.Report what you found as a list before proposing anything. A detection the user can see is a detection they can correct.
Map what Step 2 found onto a variant in
docs/setup/privacy-llm.md:
| What the stack is | Variant |
|---|---|
| The agent and nothing else | 1 — agent only (the default) |
| A local Ollama model beside it | 2 — local inference (Ollama) |
| A local vLLM endpoint beside it | 3 — local inference (vLLM) |
| An Apache-hosted endpoint | 4 — Apache-hosted endpoint |
| AWS Bedrock | 5 — Bedrock |
| The Anthropic API directly | 6 — direct API (opt-in) |
Propose the variant your detection implies, say what it means in one sentence — this permits the private list to be read by X and nothing else — and let the user correct it.
Then write privacy-llm.md from that variant's block, substituting
the project's real list addresses, into the personal layer — the
personal_dir that python3 -m setup_preflight.layers prints
(<git-common-dir>/apache-magpie/ on a project that has not adopted
Magpie, so nothing lands in its working tree).
Local, always, on this step. Writing the personal copy
needs nobody's permission, is invisible to every other clone, and
is undone by deleting a directory. Write
.apache-magpie-overrides/privacy-llm.md instead only when the project
has adopted Magpie and the user says the answer should bind every
contributor — and then stage it, never commit.
Two things this step may not do: invent an endpoint — if the detection is ambiguous, ask rather than assume — and widen the stack to make the gate pass. The gate failing is information.
Run all three. A privacy configuration nobody has exercised is a comment.
# 1. The gate: is every LLM in the active stack approved?
uv run --project <framework>/tools/privacy-llm/checker \
privacy-llm-check --reads-private-list
# 2. The redactor, end to end. "Other Researcher" is a third party
# the reporter named — never the reporter themselves.
echo "I worked with Other Researcher (other@example.com) on this" | \
uv run --project <framework>/tools/privacy-llm/redactor \
pii-redact --field name:"Other Researcher" \
--field email:"other@example.com"
# 3. The resulting local map.
uv run --project <framework>/tools/privacy-llm/redactor pii-listExpected: exit 0 from the gate; the two values in step 2 replaced
by N-… and E-… identifiers; step 3 listing them.
A non-zero gate is the finding, not a failure of this skill. Report which member of the stack is unapproved and what the options are — drop it from the stack, or take the opt-in recipe for it — and stop. Do not edit the file until the user picks.
Everything so far is local and yours. If the project should
commit this answer so every contributor's session is bound by
it, that is adopt, which promotes
the personal layer into the committed
.apache-magpie-overrides/ and stages it for review.
Say that in one line and name the command. Do not run it, do not offer to run it, and do not repeat it on later invocations. Deciding what the project permits its agents to do with private foundation mail is a maintainer decision taken with the other maintainers — and unlike the rest of this skill, it is the one part that is not undone by deleting a directory.
What counts as default-approved can narrow between framework
versions. After /magpie-setup upgrade, re-run Step 4: if an
entry that used to pass is now opt-in, the gate surfaces it and
the user takes the matching variant's opt-in recipe.
Say this once, at the end of a first run. It is the reason this skill is worth invoking a second time.
The registry this skill checks against is provisional: it
reflects the framework maintainers' working position in the
absence of a ratified ASF Legal Affairs policy for AI-assisted
handling of foundation private data. Say so when a user asks
whether a variant is "allowed" — the honest answer is that the
framework enforces a list nobody has yet ratified, and
docs/setup/privacy-llm.md
carries the full caveat.
© apache, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/magpie-setup/skills/privacy-llm of apache/magpie.
Open the folder on GitHubat commit d1f8f2c
Privacy LLM next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Privacy LLM this skillapache/magpie | 110 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Privacy Policythedaviddias/Front-End-Checklist | 74k | — | ~617 | Automated safety check: Pass | MIT | |
| Decidealirezarezvani/claude-skills | 28k | — | ~871 | Automated safety check: Pass | MIT | |
| Sendyc-software/qm | 15k | — | ~1.5k | Automated safety check: Pass | MIT | |
| Privacy Policyphuryn/pm-skills | 27k | — | ~2.7k | Automated safety check: Pass | MIT | |
| Data Privacy Controlssickn33/agentic-awesome-skills | 47k | 1 repos | ~3.4k | Automated safety check: Pass | MIT |
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing whether a website has a visible, accessible privacy policy link, particularly in the footer navigation.
alirezarezvani/claude-skills
/cs:decide <memo — Log a decision to two-layer memory via decision-logger.
yc-software/qm
Make a PR, wait for CI with bounded transport retries, independently review, and merge only when all gates pass.
phuryn/pm-skills
Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review.
sickn33/agentic-awesome-skills
Data privacy control register: data category, lawful basis, retention period, access roles, encryption and consent requirement per module.
mukul975/Anthropic-Cybersecurity-Skills
Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging, and…
apache/magpie
Scan the release distribution area (dist/release/<project/ when releasedistbackend = svnpubsub, or the configured distribution location), identify releases past the project's retention rule, and…
apache/magpie
Read-only audit of GitHub Actions runner compatibility for one repository, a repository set, one Apache project, or the full Apache org.
apache/magpie
Add the Release Manager's public key to the project KEYS file: check it meets the ASF strength floor, draft the KEYS diff, and emit the svn (or backend) commands and keyserver reminder for the RM to…
apache/magpie
Print a human-readable index of every skill installed for this repository, grouped by the family each one declares, with the name to invoke it by and the first sentence of its description.
apache/magpie
Draft a teaching-register comment on a GitHub issue or PR thread on the configured <upstream repo, aimed at a contributor missing context the maintainer would spell out.
apache/magpie
Show how Magpie is adopted in this repo — install method and pin, drift, wired agent targets, installed skill families, symlink health — and change that wiring from the same view.
Decide which LLMs this project's skills may send private foundation content to, then prove it. Privacy LLM is an agent skill from apache/magpie. Decide which LLMs this project's skills may send private foundation content to, then prove it.
Run `npx skills add apache/magpie --skill privacy-llm -a claude-code`. Or copy the skill folder (plugins/magpie-setup/skills/privacy-llm in apache/magpie) into .claude/skills/privacy-llm in your project. Claude Code loads it when a task matches its description.
Run `npx skills add apache/magpie --skill privacy-llm -a codex`. Or copy the skill folder (plugins/magpie-setup/skills/privacy-llm in apache/magpie) into .agents/skills/privacy-llm in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add apache/magpie --skill privacy-llm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-llm, .gemini/skills/privacy-llm, .github/skills/privacy-llm and .opencode/skills/privacy-llm in your project.
Going by SKILL.md and its folder, Privacy LLM needs the command-line tools its instructions call (uv and python3). Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: apache.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Privacy LLM is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Privacy LLM: Privacy Policy (thedaviddias/Front-End-Checklist, 74k stars), Decide (alirezarezvani/claude-skills, 28k stars), Send (yc-software/qm, 15k stars) and Privacy Policy (phuryn/pm-skills, 27k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
apache (a GitHub organization) maintains it in apache/magpie, which has 110 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on October 6, 2026.
Source: apache/magpie on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.