Agent skill

Privacy LLM

by apache in apache/magpie

Decide which LLMs this project's skills may send private foundation content to, then prove it.

Apache-2.0Auto-check passed

Install Privacy LLM

skills CLI
$ npx skills add apache/magpie --skill privacy-llm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install apache/magpie privacy-llm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/magpie-setup/skills/privacy-llm .claude/skills/privacy-llm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
privacy-llm
GitHub stars
110
Token cost
~2.2k tokens
SKILL.md length
1,023 words
Files
1
Skills in repo
47
Repo updated
First seen
Licence
Apache-2.0

At a glance

Decide which LLMs this project's skills may send private foundation content to, then prove it.

  • Works in 6 steps: Does it already resolve? → Detect the stack, do not ask for it → Pick the variant and write it → …
  • SKILL.md covers Step 1 — Does it already…, Step 2 — Detect the stack, do…, Step 3 — Pick the variant and… and Step 4 — Prove it, do not…, plus 3 more sections
  • Calls uv and python3

What it does

Privacy LLM is an agent skill from apache/magpie. Decide which LLMs this project's skills may send private foundation content to, then prove it. Detects the stack in use, writes <project-config/privacy-llm.md, and runs the approved-model gate and the PII redactor end to end so the result is demonstrated rather than declared.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Agent-assisted maintainership and development framework for Apache projects — Triage, Mentoring, Drafting (agent-authored fixes with human review), and Pairing (developer-side… The licence is Apache-2.0.

Example prompts

  • “/privacy-llm”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Does it already resolve?
  2. Detect the stack, do not ask for it
  3. Pick the variant and write it
  4. Prove it, do not declare it
  5. Say that adopting exists, then stop
  6. Re-run after an upgrade

What it can do on your machine

Read from SKILL.md and the folder at commit d1f8f2c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • apache.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Privacy LLM loads about 2.2k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 1,023 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from apache/magpie at commit d1f8f2c, republished under its Apache-2.0 licence (© apache). 1,023 words, ~2,245 tokens.

Download SKILL.mdSave it as .claude/skills/privacy-llm/SKILL.md (or your agent's skills folder).
name
privacy-llm
description
Decide which LLMs this project's skills may send private foundation content to, then prove it. Detects the stack in use, writes <project-config>/privacy-llm.md, and runs the approved-model gate and the PII redactor end to end so the result is demonstrated rather than declared.
family
setup
mode
Meta
when_to_use
Before any skill reads a private mailing list or a pre-disclosure report, and whenever a pre-flight says privacy-llm.md does not resolve. Also when the LLM…
capability
capability:platform
surface_hash
sha256:49a65c36a0dc49ab
license
Apache-2.0
measured_tokens
2218
<!-- SPDX-License-Identifier: Apache-2.0
     https://www.apache.org/licenses/LICENSE-2.0 -->
<!-- Placeholder convention (see ../../AGENTS.md#placeholder-convention-used-in-skill-files):
     <project-config>  → resolved per file: the personal layer first
                         (`.apache-magpie-local/` when adopted, falling back to the main
                         checkout's in a linked worktree; `<git-common-dir>/apache-magpie/`
                         when only installed), then `.apache-magpie-overrides/` (committed)
     <framework>       → the framework checkout or plugin root
     <private-list>    → the project's private PMC list
     <security-list>   → the project's security-report list -->

setup-privacy-llm

Decide which LLMs this project's skills may send private foundation content to, record that decision where the skills look for it, and prove it holds.

Two mechanisms, and this skill configures one of them:

  1. The approved-LLM gate — applies to <private-list> mail and any other private foundation list. A skill refuses to fetch unless every LLM in the active stack is approved. This is what the skill configures, by picking a variant.
  2. PII redaction — applies to <security-list> mail. Third parties the reporter names are replaced with hash-prefixed identifiers before any LLM sees them. It runs under every variant and needs no per-variant configuration; this skill only verifies it works.

The recipes are docs/setup/privacy-llm.md; the contract behind them is tools/privacy-llm/tool.md. This skill walks the recipe rather than restating it — read the variant you land on before writing anything.

[!IMPORTANT] This is a project decision, not a personal preference. What goes in the committed copy says what the project permits for everyone's sessions. Configure locally for yourself freely; see Step 5 before promoting anything to the committed half.


Step 1 — Does it already resolve?

Resolve privacy-llm.md through the lookup chain, per file, local first:

  1. privacy-llm.md in the personal layer — yours, never committed: .apache-magpie-local/ when the project adopted Magpie (the main checkout's, from a linked worktree that has none), else <git-common-dir>/apache-magpie/;
  2. .apache-magpie-overrides/privacy-llm.md — committed, the project's.

Both present → say so and name which one wins here (the local one does), because a local file silently shadowing the project's answer is exactly the case an operator needs told. Offer to show the difference, then go to Step 4 and verify rather than rewrite.

Only one present → read it, report the stack it declares, and go to Step 4. Do not rewrite a working configuration because this skill happened to be invoked.

Neither → continue to Step 2. This is the first run.

Step 2 — Detect the stack, do not ask for it

Ask the user nothing you can determine. Establish what is actually in the stack:

  • The agent itself — which harness is running this skill (Claude Code, Codex, Gemini CLI, …). Always in the stack.
  • Local inference — is an Ollama, llama.cpp or vLLM endpoint reachable and configured for this project? Check the adapter configuration and the environment, not a guess.
  • Third-party endpoints — anything in the project's existing configuration naming a model endpoint the framework does not ship.
  • Whether this project has private lists at all. A project with no <private-list> still wants the file, because the redactor and the gate both read it — but the variant is the simple one and the interview is one question shorter.

Report what you found as a list before proposing anything. A detection the user can see is a detection they can correct.

Step 3 — Pick the variant and write it

Map what Step 2 found onto a variant in docs/setup/privacy-llm.md:

What the stack isVariant
The agent and nothing else1 — agent only (the default)
A local Ollama model beside it2 — local inference (Ollama)
A local vLLM endpoint beside it3 — local inference (vLLM)
An Apache-hosted endpoint4 — Apache-hosted endpoint
AWS Bedrock5 — Bedrock
The Anthropic API directly6 — direct API (opt-in)

Propose the variant your detection implies, say what it means in one sentence — this permits the private list to be read by X and nothing else — and let the user correct it.

Then write privacy-llm.md from that variant's block, substituting the project's real list addresses, into the personal layer — the personal_dir that python3 -m setup_preflight.layers prints (<git-common-dir>/apache-magpie/ on a project that has not adopted Magpie, so nothing lands in its working tree). Local, always, on this step. Writing the personal copy needs nobody's permission, is invisible to every other clone, and is undone by deleting a directory. Write .apache-magpie-overrides/privacy-llm.md instead only when the project has adopted Magpie and the user says the answer should bind every contributor — and then stage it, never commit.

Two things this step may not do: invent an endpoint — if the detection is ambiguous, ask rather than assume — and widen the stack to make the gate pass. The gate failing is information.

Show full SKILL.md (340 more words)Show less

Step 4 — Prove it, do not declare it

Run all three. A privacy configuration nobody has exercised is a comment.

bash
# 1. The gate: is every LLM in the active stack approved?
uv run --project <framework>/tools/privacy-llm/checker \
  privacy-llm-check --reads-private-list

# 2. The redactor, end to end. "Other Researcher" is a third party
#    the reporter named — never the reporter themselves.
echo "I worked with Other Researcher (other@example.com) on this" | \
  uv run --project <framework>/tools/privacy-llm/redactor \
  pii-redact --field name:"Other Researcher" \
             --field email:"other@example.com"

# 3. The resulting local map.
uv run --project <framework>/tools/privacy-llm/redactor pii-list

Expected: exit 0 from the gate; the two values in step 2 replaced by N-… and E-… identifiers; step 3 listing them.

A non-zero gate is the finding, not a failure of this skill. Report which member of the stack is unapproved and what the options are — drop it from the stack, or take the opt-in recipe for it — and stop. Do not edit the file until the user picks.

Step 5 — Say that adopting exists, then stop

Everything so far is local and yours. If the project should commit this answer so every contributor's session is bound by it, that is adopt, which promotes the personal layer into the committed .apache-magpie-overrides/ and stages it for review.

Say that in one line and name the command. Do not run it, do not offer to run it, and do not repeat it on later invocations. Deciding what the project permits its agents to do with private foundation mail is a maintainer decision taken with the other maintainers — and unlike the rest of this skill, it is the one part that is not undone by deleting a directory.

Step 6 — Re-run after an upgrade

What counts as default-approved can narrow between framework versions. After /magpie-setup upgrade, re-run Step 4: if an entry that used to pass is now opt-in, the gate surfaces it and the user takes the matching variant's opt-in recipe.

Say this once, at the end of a first run. It is the reason this skill is worth invoking a second time.


The registry this skill checks against is provisional: it reflects the framework maintainers' working position in the absence of a ratified ASF Legal Affairs policy for AI-assisted handling of foundation private data. Say so when a user asks whether a variant is "allowed" — the honest answer is that the framework enforces a list nobody has yet ratified, and docs/setup/privacy-llm.md carries the full caveat.

© apache, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/magpie-setup/skills/privacy-llm of apache/magpie.

Open the folder on GitHubat commit d1f8f2c

Compare with similar skills

Privacy LLM next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Privacy LLM compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Privacy LLM this skillapache/magpie110—~2.2kAutomated safety check: PassApache-2.0
Privacy Policythedaviddias/Front-End-Checklist74k—~617Automated safety check: PassMIT
Decidealirezarezvani/claude-skills28k—~871Automated safety check: PassMIT
Sendyc-software/qm15k—~1.5kAutomated safety check: PassMIT
Privacy Policyphuryn/pm-skills27k—~2.7kAutomated safety check: PassMIT
Data Privacy Controlssickn33/agentic-awesome-skills47k1 repos~3.4kAutomated safety check: PassMIT

Similar skills

  • Privacy Policy

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing whether a website has a visible, accessible privacy policy link, particularly in the footer navigation.

    74k GitHub stars~617 tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Decide

    alirezarezvani/claude-skills

    /cs:decide <memo — Log a decision to two-layer memory via decision-logger.

    28k GitHub stars~871 tokensUpdated 1 mo ago
    Auto-check passed
  • Send

    yc-software/qm

    Make a PR, wait for CI with bounded transport retries, independently review, and merge only when all gates pass.

    15k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Privacy Policy

    phuryn/pm-skills

    Draft a detailed privacy policy covering data types, jurisdiction, GDPR and compliance considerations, and clauses needing legal review.

    27k GitHub stars~2.7k tokensUpdated 23 days ago
    Legal & ComplianceAuto-check passed
  • Data Privacy Controls

    sickn33/agentic-awesome-skills

    Data privacy control register: data category, lawful basis, retention period, access roles, encryption and consent requirement per module.

    47k GitHub starsUsed in 1 repo~3.4k tokens
    Legal & ComplianceAuto-check passed
  • Performing Privacy Impact Assessment

    mukul975/Anthropic-Cybersecurity-Skills

    Automates the Privacy Impact Assessment (PIA) workflow including data flow mapping, privacy risk scoring matrices, GDPR Article 35 DPIA and CCPA/CPRA alignment checks, data inventory cataloging, and…

    34k GitHub stars~2.6k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from apache/magpie

All 47 skills in this repo
  • Archive Sweep

    apache/magpie

    Scan the release distribution area (dist/release/<project/ when releasedistbackend = svnpubsub, or the configured distribution location), identify releases past the project's retention rule, and…

    110 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • CI Runner Audit

    apache/magpie

    Read-only audit of GitHub Actions runner compatibility for one repository, a repository set, one Apache project, or the full Apache org.

    110 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Keys Sync

    apache/magpie

    Add the Release Manager's public key to the project KEYS file: check it meets the ASF strength floor, draft the KEYS diff, and emit the svn (or backend) commands and keyserver reminder for the RM to…

    110 GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • List Skills

    apache/magpie

    Print a human-readable index of every skill installed for this repository, grouped by the family each one declares, with the name to invoke it by and the first sentence of its description.

    110 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Mentor

    apache/magpie

    Draft a teaching-register comment on a GitHub issue or PR thread on the configured <upstream repo, aimed at a contributor missing context the maintainer would spell out.

    110 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Status

    apache/magpie

    Show how Magpie is adopted in this repo — install method and pin, drift, wired agent targets, installed skill families, symlink health — and change that wiring from the same view.

    110 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed

Questions about Privacy LLM

What does Privacy LLM do?

Decide which LLMs this project's skills may send private foundation content to, then prove it. Privacy LLM is an agent skill from apache/magpie. Decide which LLMs this project's skills may send private foundation content to, then prove it.

How do I install Privacy LLM in Claude Code?

Run `npx skills add apache/magpie --skill privacy-llm -a claude-code`. Or copy the skill folder (plugins/magpie-setup/skills/privacy-llm in apache/magpie) into .claude/skills/privacy-llm in your project. Claude Code loads it when a task matches its description.

How do I install Privacy LLM in Codex?

Run `npx skills add apache/magpie --skill privacy-llm -a codex`. Or copy the skill folder (plugins/magpie-setup/skills/privacy-llm in apache/magpie) into .agents/skills/privacy-llm in your project. Codex loads it when a task matches its description.

Can I use Privacy LLM in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add apache/magpie --skill privacy-llm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/privacy-llm, .gemini/skills/privacy-llm, .github/skills/privacy-llm and .opencode/skills/privacy-llm in your project.

What does Privacy LLM need to run?

Going by SKILL.md and its folder, Privacy LLM needs the command-line tools its instructions call (uv and python3). Our summary lists: Python 3.

Does Privacy LLM access the network?

SKILL.md names 1 domain. As links in the text: apache.org. This is read from the text; nothing was executed.

Is Privacy LLM safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Privacy LLM use?

Privacy LLM is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Privacy LLM use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Privacy LLM?

Skills that share tags, products or a category with Privacy LLM: Privacy Policy (thedaviddias/Front-End-Checklist, 74k stars), Decide (alirezarezvani/claude-skills, 28k stars), Send (yc-software/qm, 15k stars) and Privacy Policy (phuryn/pm-skills, 27k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Privacy LLM?

apache (a GitHub organization) maintains it in apache/magpie, which has 110 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on October 6, 2026.

Source: apache/magpie on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.