Agent skill

Write Skill

by apache in apache/magpie

Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions.

Apache-2.0Auto-check passedSecurity

Install Write Skill

skills CLI
$ npx skills add apache/magpie --skill write-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install apache/magpie write-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/magpie-utilities/skills/write-skill .claude/skills/write-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
write-skill
GitHub stars
110
Token cost
~2.6k tokens
SKILL.md length
1,202 words
Files
6 (incl. scripts)
Skills in repo
47
Repo updated
First seen
Licence
Apache-2.0

At a glance

Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions.

  • Works in 8 steps: Get three concrete examples → Decide what goes where → Scaffold it → …
  • Tasks that involve Project scaffolding
  • SKILL.md covers Pre-flight — is this project…, Step 1 — Get three concrete…, Step 2 — Decide what goes where and Step 3 — Scaffold it, plus 7 more sections
  • Runs Python scripts from its folder; calls git, python3 and uv

What it does

Write Skill is an agent skill from apache/magpie. Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions. Scaffolds the directory, walks the house style and the prompt-injection defences, and validates before it ships.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `anatomy.md`, `conventions.md` and `provenance.md`).

It sits in Security, covering Project scaffolding and Prompt injection and agent security. The repository describes itself as: Agent-assisted maintainership and development framework for Apache projects — Triage, Mentoring, Drafting (agent-authored fixes with human review), and Pairing (developer-side… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Project scaffolding
  • Tasks that involve Prompt injection and agent security

Example prompts

  • “/write-skill”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Get three concrete examples
  2. Decide what goes where
  3. Scaffold it
  4. Write the body
  5. Secure it, if it reads outside content
  6. Validate
  7. Optimize before you ship
  8. Ship, then iterate

What it can do on your machine

Read from SKILL.md and the folder at commit d1f8f2c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • python3
    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • apache.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Write Skill loads about 2.6k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 1,202 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from apache/magpie at commit d1f8f2c, republished under its Apache-2.0 licence (© apache). 1,202 words, ~2,605 tokens.

Download SKILL.mdSave it as .claude/skills/write-skill/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
write-skill
description
Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions. Scaffolds the directory, walks the house style and the prompt-injection defences, and validates before it ships.
family
utilities
mode
Meta
when_to_use
When the user says "write a skill", "create a new skill", "add a skill for X", or wants an existing skill updated to the framework's current conventions. For…
capability
capability:authoring
surface_hash
sha256:31626428a2545bce
license
Apache-2.0
measured_tokens
2583
<!-- SPDX-License-Identifier: Apache-2.0
     https://www.apache.org/licenses/LICENSE-2.0 -->
<!-- Placeholder convention (see AGENTS.md#placeholder-convention-used-in-skill-files):
     <project-config> → adopting project's `.apache-magpie/` directory
     <tracker>        → value of `tracker_repo:` in <project-config>/project.md
     <upstream>       → value of `upstream_repo:` in <project-config>/project.md
     <framework>      → `.apache-magpie/apache-magpie` in adopters; `.` in
                        the framework standalone -->

write-skill

<!-- BEGIN MAGPIE PREFLIGHT — generated from tools/dev/preflight-block.md -->

Pre-flight — is this project set up?

Do this first, before anything else in this skill, and do it silently. One command answers it and carries its own rules; there is nothing else to read.

Run the checker with this skill's own frontmatter name: and surface_hash:, and one --requires for each requires_config: entry:

bash
PYTHONPATH=".apache-magpie-local:$(git rev-parse --git-common-dir)/../.apache-magpie-local:$(git rev-parse --git-common-dir)/apache-magpie" \
  python3 -m setup_preflight --skill <name> --hash <surface_hash> [--requires <file>]...

The path finds the checker /magpie-setup config installed in the personal layer: this checkout's .apache-magpie-local/, the main checkout's when this is a linked worktree, or the git directory's apache-magpie/ when Magpie is only installed.

  • {"verdict": "ok"} → silent. Continue into the work the user asked for and say nothing about pre-flight. This is the ordinary answer.
  • {"verdict": "action", ...} → each finding names a section, and rules carries that section's text. Follow it. The facts are the inputs; what to propose, and what may not be done, are in the rules rather than here. Act on a finding only through its rules.
  • The command did not run at all — no such module, a non-zero exit, no python3 — → never read that as a pass, and do not re-derive the check by hand: it lives in code so that there is one version of it. If the project has no .apache-magpie.lock, .apache-magpie-overrides/, or personal layer (any of the three directories above), nothing has been set up here and there is nothing to reconcile — resolve this skill's requires_config: entries yourself (first match wins: .apache-magpie-local/<file>, the main checkout's .apache-magpie-local/<file>, <git-common-dir>/apache-magpie/<file>, then .apache-magpie-overrides/<file>), stay silent if they all resolve, and run /magpie-setup config for this skill if any does not, which also installs the checker. Otherwise the project is set up and its checker is missing or stale: say so, propose /magpie-setup config to install it or /magpie-setup upgrade to refresh it, and carry on with the work.

Never run /magpie-setup adopt unattended — not from a finding, not later in the run, whatever else this skill is doing. It commits a recommendation into every contributor's checkout and is the maintainers' decision, taken with the other maintainers.

Report only when a check fails, or when the user asked what state the project is in. /magpie-setup verify is the full diagnostic.

<!-- END MAGPIE PREFLIGHT -->

Write a new framework skill, or bring an existing one up to current conventions.

Three files carry the detail, each read when a step calls for it: anatomy.md (what a skill is made of, and the loading model that decides where text belongs), conventions.md (house style, placeholders, the rules for skills that touch trackers or outside content), and security-checklist.md (the nine prompt-injection patterns in full). provenance.md records where this skill came from.

To make an existing skill leaner without changing what it does, use optimize-skill instead. Step 7 runs it against every new skill regardless.

Step 1 — Get three concrete examples

Before writing anything, ask what the user will actually say, what the agent does in response, and what the apply step is. Get three to five real invocations, not paraphrases.

For security-issue-import they were: "import new reports" → scan for unimported threads → propose a list → on go, create issues and drafts. "check for unimported security@ messages" → the same. "import #<threadId>" → one named thread.

If an example stays fuzzy, ask until it is concrete. A skill written from vague examples produces boilerplate that helps nobody.

Step 2 — Decide what goes where

For each example, sort the work into three buckets.

Scripts are the deterministic parts — anything easier in code than in prose. Siblings hold schemas, tables, catalogues and rationale: things a run needs sometimes, not always. Assets are templates the skill writes out verbatim.

Most skills need a small scripts/ and nothing else. Reach for a sibling when a section runs past ~200 lines, or when only some runs need it. anatomy.md has the reasoning.

Step 3 — Scaffold it

bash
python3 <framework>/skills/write-skill/scripts/init_skill.py \
  <skill-name> --path skills/<skill-name>

This creates the directory, a SKILL.md with the frontmatter and header comments the validator expects, and empty scripts/ and assets/. Skip this step for an existing skill.

Step 4 — Write the body

Write the steps, the hard rules, and the references. conventions.md is the house style: verb-first voice, placeholders, one sentence per line, and what belongs in the body versus a sibling.

Two things decide most of the shape. Every state-changing step is a proposal the user confirms. Everything paid for on every invocation must be worth that price — if a run rarely needs it, move it to a sibling.

Show full SKILL.md (480 more words)Show less

Step 5 — Secure it, if it reads outside content

A skill reading Gmail, public PRs, mailing lists or findings files takes the patterns in security-checklist.md; conventions.md summarises them. A skill reading only framework files skips this step and says so in its body, so the next reader knows the omission was deliberate.

Step 6 — Validate

bash
uv run --directory tools/skill-and-tool-validator --group dev \
  skill-and-tool-validate

It checks the frontmatter shape, placeholder discipline, the SPDX header and internal links. Fix what it reports and run it again. CI runs the same check, so a red skill does not merge.

Step 7 — Optimize before you ship

A skill is written to be understood, and first drafts explain too much. Run optimize-skill against what you just wrote — always, not only when it feels long. This is part of writing a skill, not a later cleanup someone may or may not get to.

It checks the new skill against the two budgets in that skill's What counts as small enough: the body under 5,000 tokens, and description + when_to_use under 200. The second matters most. It is paid in every session, for every skill at once, whether or not anyone ever invokes this one — so a wordy description taxes people who will never use the skill.

Take its restructuring passes; they move text without changing it. For prose it offers the paragraph-by-paragraph rewrite, where you write the words and it learns your style as it goes.

A new skill that cannot get under both budgets is usually doing two jobs. Consider splitting it before accepting the size.

Step 8 — Ship, then iterate

Use the skill on real work and watch where it goes wrong: a step whose instructions were too loose, a missing reference, a script that would have helped. Land each fix as its own change. The body is re-read on every invocation, so a tightening here compounds.

When an adopter's .apache-magpie-overrides/<skill-name>.md has accumulated something worth having upstream, setup-override-upstream walks the promotion.

Hard rules

  • Every state-changing step is a proposal the user confirms. No skill posts, edits or pushes on its own. This is the framework's load-bearing invariant.
  • Attacker-controlled text never enters a gh argument inside quotes. Tempfile plus -F field=@file. Never --body "$(cat …)" — use --body-file. The exception is a regex-validated token such as CVE-…, where the validation is the gate.
  • license: Apache-2.0 and a capability: in the frontmatter. The validator enforces both. Pick capabilities from docs/labels-and-capabilities.md and list all that apply rather than collapsing to one. If none fit, stop: either the taxonomy needs an entry or the skill is doing too much.
  • Credit adapted third-party content in NOTICE.
  • Never ship a skill that has not been through Step 7. The budgets are the gate: body under 5,000 tokens, frontmatter under 200.

References

© apache, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts) in plugins/magpie-utilities/skills/write-skill of apache/magpie.

  • SKILL.md
  • anatomy.md
  • conventions.md
  • provenance.md
  • scripts/init_skill.py
  • security-checklist.md

Open the folder on GitHubat commit d1f8f2c

Compare with similar skills

Write Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Write Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Write Skill this skillapache/magpie110—~2.6kAutomated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence
Hol Guardhashgraph-online/hol-guard797—~542Automated safety check: PassApache-2.0
Kesekit Checkcdppcorp/KESE-KIT359—~1.3kAutomated safety check: PassMIT
Setuphashgraph-online/hol-guard797—~443Automated safety check: PassApache-2.0

Similar skills

  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Hol Guard

    hashgraph-online/hol-guard

    Run HOL Guard scanner and guard operations via uv run hol-guard.

    797 GitHub stars~542 tokensUpdated today
    SecurityAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    359 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Setup

    hashgraph-online/hol-guard

    Install or initialize HOL Guard local runtime protection for Claude Code.

    797 GitHub stars~443 tokensUpdated today
    SecurityAuto-check passed
  • Clawscan CLI

    openclaw/clawscan

    A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…

    142 GitHub stars~3k tokensUpdated yesterday
    SecurityAuto-check passed

More from apache/magpie

All 47 skills in this repo
  • Archive Sweep

    apache/magpie

    Scan the release distribution area (dist/release/<project/ when releasedistbackend = svnpubsub, or the configured distribution location), identify releases past the project's retention rule, and…

    110 GitHub stars~4.7k tokensUpdated today
    Auto-check passed
  • CI Runner Audit

    apache/magpie

    Read-only audit of GitHub Actions runner compatibility for one repository, a repository set, one Apache project, or the full Apache org.

    110 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Keys Sync

    apache/magpie

    Add the Release Manager's public key to the project KEYS file: check it meets the ASF strength floor, draft the KEYS diff, and emit the svn (or backend) commands and keyserver reminder for the RM to…

    110 GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • List Skills

    apache/magpie

    Print a human-readable index of every skill installed for this repository, grouped by the family each one declares, with the name to invoke it by and the first sentence of its description.

    110 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Mentor

    apache/magpie

    Draft a teaching-register comment on a GitHub issue or PR thread on the configured <upstream repo, aimed at a contributor missing context the maintainer would spell out.

    110 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Status

    apache/magpie

    Show how Magpie is adopted in this repo — install method and pin, drift, wired agent targets, installed skill families, symlink health — and change that wiring from the same view.

    110 GitHub stars~2.5k tokensUpdated today
    Auto-check passed

Categories

Questions about Write Skill

What does Write Skill do?

Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions. Write Skill is an agent skill from apache/magpie. Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions.

When should I use Write Skill?

Write Skill fits situations like: tasks that involve Project scaffolding; tasks that involve Prompt injection and agent security.

How do I install Write Skill in Claude Code?

Run `npx skills add apache/magpie --skill write-skill -a claude-code`. Or copy the skill folder (plugins/magpie-utilities/skills/write-skill in apache/magpie) into .claude/skills/write-skill in your project. Claude Code loads it when a task matches its description.

How do I install Write Skill in Codex?

Run `npx skills add apache/magpie --skill write-skill -a codex`. Or copy the skill folder (plugins/magpie-utilities/skills/write-skill in apache/magpie) into .agents/skills/write-skill in your project. Codex loads it when a task matches its description.

Can I use Write Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add apache/magpie --skill write-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/write-skill, .gemini/skills/write-skill, .github/skills/write-skill and .opencode/skills/write-skill in your project.

What does Write Skill need to run?

Going by SKILL.md and its folder, Write Skill needs Python for the scripts in its folder and the command-line tools its instructions call (git, python3 and uv). Our summary lists: Python 3.

Does Write Skill access the network?

SKILL.md names 1 domain. As links in the text: apache.org. This is read from the text; nothing was executed.

Is Write Skill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Write Skill use?

Write Skill is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Write Skill use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Write Skill?

Skills that share tags, products or a category with Write Skill: Skill Scanner (getsentry/skills, 1k stars), Forensify (alexgreensh/repo-forensics, 187 stars), Hol Guard (hashgraph-online/hol-guard, 797 stars) and Kesekit Check (cdppcorp/KESE-KIT, 359 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Write Skill?

apache (a GitHub organization) maintains it in apache/magpie, which has 110 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on October 6, 2026.

Source: apache/magpie on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.