Skill Scanner
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions.
$ npx skills add apache/magpie --skill write-skill -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install apache/magpie write-skill --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/magpie-utilities/skills/write-skill .claude/skills/write-skill && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "write-skill" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-utilities/skills/write-skill into .claude/skills/write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-skill", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/apache/magpie/tree/main/plugins/magpie-utilities/skills/write-skillType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add apache/magpie --skill write-skill -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install apache/magpie write-skill --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/magpie-utilities/skills/write-skill .agents/skills/write-skill && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "write-skill" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-utilities/skills/write-skill into .agents/skills/write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-skill", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add apache/magpie --skill write-skill -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install apache/magpie write-skill --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/magpie-utilities/skills/write-skill .cursor/skills/write-skill && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "write-skill" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-utilities/skills/write-skill into .cursor/skills/write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-skill", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/apache/magpie.git --path plugins/magpie-utilities/skills/write-skill--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add apache/magpie --skill write-skill -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install apache/magpie write-skill --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/magpie-utilities/skills/write-skill .gemini/skills/write-skill && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "write-skill" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-utilities/skills/write-skill into .gemini/skills/write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-skill", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install apache/magpie write-skillInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add apache/magpie --skill write-skill -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/magpie-utilities/skills/write-skill .github/skills/write-skill && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "write-skill" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-utilities/skills/write-skill into .github/skills/write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-skill", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add apache/magpie --skill write-skill -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install apache/magpie write-skill --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apache/magpie.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/magpie-utilities/skills/write-skill .opencode/skills/write-skill && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "write-skill" agent skill from https://github.com/apache/magpie/tree/main/plugins/magpie-utilities/skills/write-skill into .opencode/skills/write-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-skill", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
write-skillWrite a new skill for the Apache Magpie framework, or bring an existing one up to current conventions.
Write Skill is an agent skill from apache/magpie. Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions. Scaffolds the directory, walks the house style and the prompt-injection defences, and validates before it ships.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `anatomy.md`, `conventions.md` and `provenance.md`).
It sits in Security, covering Project scaffolding and Prompt injection and agent security. The repository describes itself as: Agent-assisted maintainership and development framework for Apache projects — Triage, Mentoring, Drafting (agent-authored fixes with human review), and Pairing (developer-side… The licence is Apache-2.0.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d1f8f2c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
gitpython3uvFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
apache.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Write Skill loads about 2.6k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 1,202 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from apache/magpie at commit d1f8f2c, republished under its Apache-2.0 licence (© apache). 1,202 words, ~2,605 tokens.
.claude/skills/write-skill/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.<!-- SPDX-License-Identifier: Apache-2.0
https://www.apache.org/licenses/LICENSE-2.0 -->
<!-- Placeholder convention (see AGENTS.md#placeholder-convention-used-in-skill-files):
<project-config> → adopting project's `.apache-magpie/` directory
<tracker> → value of `tracker_repo:` in <project-config>/project.md
<upstream> → value of `upstream_repo:` in <project-config>/project.md
<framework> → `.apache-magpie/apache-magpie` in adopters; `.` in
the framework standalone -->
<!-- BEGIN MAGPIE PREFLIGHT — generated from tools/dev/preflight-block.md -->
Do this first, before anything else in this skill, and do it silently. One command answers it and carries its own rules; there is nothing else to read.
Run the checker with this skill's own frontmatter name: and
surface_hash:, and one --requires for each requires_config: entry:
PYTHONPATH=".apache-magpie-local:$(git rev-parse --git-common-dir)/../.apache-magpie-local:$(git rev-parse --git-common-dir)/apache-magpie" \
python3 -m setup_preflight --skill <name> --hash <surface_hash> [--requires <file>]...The path finds the checker /magpie-setup config installed in the
personal layer: this checkout's .apache-magpie-local/, the main
checkout's when this is a linked worktree, or the git directory's
apache-magpie/ when Magpie is only installed.
{"verdict": "ok"} → silent. Continue into the work the user
asked for and say nothing about pre-flight. This is the ordinary answer.{"verdict": "action", ...} → each finding names a section, and
rules carries that section's text. Follow it. The facts are the
inputs; what to propose, and what may not be done, are in the rules
rather than here. Act on a finding only through its rules.python3 — → never read that as a pass, and do not re-derive the check
by hand: it lives in code so that there is one version of it. If the
project has no .apache-magpie.lock, .apache-magpie-overrides/,
or personal layer (any of the three directories above),
nothing has been set up here and there is
nothing to reconcile — resolve this skill's requires_config: entries
yourself (first match wins: .apache-magpie-local/<file>, the main
checkout's .apache-magpie-local/<file>, <git-common-dir>/apache-magpie/<file>,
then .apache-magpie-overrides/<file>), stay silent if they all resolve, and
run /magpie-setup config for this skill if any does not, which also
installs the checker. Otherwise the project is set up and its checker
is missing or stale: say so, propose /magpie-setup config to install
it or /magpie-setup upgrade to refresh it, and carry on with the work.Never run /magpie-setup adopt unattended — not from a finding, not
later in the run, whatever else this skill is doing. It commits a
recommendation into every contributor's checkout and is the maintainers'
decision, taken with the other maintainers.
Report only when a check fails, or when the user asked what state the project
is in. /magpie-setup verify is the full diagnostic.
<!-- END MAGPIE PREFLIGHT -->
Write a new framework skill, or bring an existing one up to current conventions.
Three files carry the detail, each read when a step calls for it:
anatomy.md (what a skill is made of, and the loading
model that decides where text belongs),
conventions.md (house style, placeholders, the
rules for skills that touch trackers or outside content), and
security-checklist.md (the nine
prompt-injection patterns in full). provenance.md
records where this skill came from.
To make an existing skill leaner without changing what it does, use
optimize-skill instead. Step 7 runs it
against every new skill regardless.
Before writing anything, ask what the user will actually say, what the agent does in response, and what the apply step is. Get three to five real invocations, not paraphrases.
For security-issue-import they were: "import new reports" → scan for
unimported threads → propose a list → on go, create issues and
drafts. "check for unimported security@ messages" → the same.
"import #<threadId>" → one named thread.
If an example stays fuzzy, ask until it is concrete. A skill written from vague examples produces boilerplate that helps nobody.
For each example, sort the work into three buckets.
Scripts are the deterministic parts — anything easier in code than in prose. Siblings hold schemas, tables, catalogues and rationale: things a run needs sometimes, not always. Assets are templates the skill writes out verbatim.
Most skills need a small scripts/ and nothing else. Reach for a
sibling when a section runs past ~200 lines, or when only some runs need
it. anatomy.md has the reasoning.
python3 <framework>/skills/write-skill/scripts/init_skill.py \
<skill-name> --path skills/<skill-name>This creates the directory, a SKILL.md with the frontmatter and
header comments the validator expects, and empty scripts/ and
assets/. Skip this step for an existing skill.
Write the steps, the hard rules, and the references.
conventions.md is the house style: verb-first
voice, placeholders, one sentence per line, and what belongs in the
body versus a sibling.
Two things decide most of the shape. Every state-changing step is a proposal the user confirms. Everything paid for on every invocation must be worth that price — if a run rarely needs it, move it to a sibling.
A skill reading Gmail, public PRs, mailing lists or findings files takes
the patterns in security-checklist.md;
conventions.md summarises them. A skill reading only
framework files skips this step and says so in its body, so the next
reader knows the omission was deliberate.
uv run --directory tools/skill-and-tool-validator --group dev \
skill-and-tool-validateIt checks the frontmatter shape, placeholder discipline, the SPDX header and internal links. Fix what it reports and run it again. CI runs the same check, so a red skill does not merge.
A skill is written to be understood, and first drafts explain too much.
Run optimize-skill against what you just
wrote — always, not only when it feels long. This is part of writing a
skill, not a later cleanup someone may or may not get to.
It checks the new skill against the two budgets in that skill's What
counts as small enough: the body under 5,000 tokens, and
description + when_to_use under 200. The second matters most. It is
paid in every session, for every skill at once, whether or not anyone
ever invokes this one — so a wordy description taxes people who will
never use the skill.
Take its restructuring passes; they move text without changing it. For prose it offers the paragraph-by-paragraph rewrite, where you write the words and it learns your style as it goes.
A new skill that cannot get under both budgets is usually doing two jobs. Consider splitting it before accepting the size.
Use the skill on real work and watch where it goes wrong: a step whose instructions were too loose, a missing reference, a script that would have helped. Land each fix as its own change. The body is re-read on every invocation, so a tightening here compounds.
When an adopter's .apache-magpie-overrides/<skill-name>.md has
accumulated something worth having upstream,
setup-override-upstream
walks the promotion.
gh argument inside
quotes. Tempfile plus -F field=@file. Never --body "$(cat …)" —
use --body-file. The exception is a regex-validated token such as
CVE-…, where the validation is the gate.license: Apache-2.0 and a capability: in the frontmatter. The
validator enforces both. Pick capabilities from
docs/labels-and-capabilities.md
and list all that apply rather than collapsing to one. If none fit,
stop: either the taxonomy needs an entry or the skill is doing too
much.NOTICE.anatomy.md, conventions.md,
security-checklist.md,
provenance.md — this skill's detail files.scripts/init_skill.py — Step 3's scaffold.optimize-skill — making an existing
skill leaner.AGENTS.md — framework authoring
conventions and the external-content-as-data rule.tools/skill-and-tool-validator/
— Step 6's gate.© apache, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts) in plugins/magpie-utilities/skills/write-skill of apache/magpie.
Open the folder on GitHubat commit d1f8f2c
Write Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Write Skill this skillapache/magpie | 110 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Forensifyalexgreensh/repo-forensics | 187 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Hol Guardhashgraph-online/hol-guard | 797 | — | ~542 | Automated safety check: Pass | Apache-2.0 | |
| Kesekit Checkcdppcorp/KESE-KIT | 359 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Setuphashgraph-online/hol-guard | 797 | — | ~443 | Automated safety check: Pass | Apache-2.0 |
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
hashgraph-online/hol-guard
Run HOL Guard scanner and guard operations via uv run hol-guard.
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
hashgraph-online/hol-guard
Install or initialize HOL Guard local runtime protection for Claude Code.
openclaw/clawscan
A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…
apache/magpie
Scan the release distribution area (dist/release/<project/ when releasedistbackend = svnpubsub, or the configured distribution location), identify releases past the project's retention rule, and…
apache/magpie
Read-only audit of GitHub Actions runner compatibility for one repository, a repository set, one Apache project, or the full Apache org.
apache/magpie
Add the Release Manager's public key to the project KEYS file: check it meets the ASF strength floor, draft the KEYS diff, and emit the svn (or backend) commands and keyserver reminder for the RM to…
apache/magpie
Print a human-readable index of every skill installed for this repository, grouped by the family each one declares, with the name to invoke it by and the first sentence of its description.
apache/magpie
Draft a teaching-register comment on a GitHub issue or PR thread on the configured <upstream repo, aimed at a contributor missing context the maintainer would spell out.
apache/magpie
Show how Magpie is adopted in this repo — install method and pin, drift, wired agent targets, installed skill families, symlink health — and change that wiring from the same view.
Categories
Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions. Write Skill is an agent skill from apache/magpie. Write a new skill for the Apache Magpie framework, or bring an existing one up to current conventions.
Write Skill fits situations like: tasks that involve Project scaffolding; tasks that involve Prompt injection and agent security.
Run `npx skills add apache/magpie --skill write-skill -a claude-code`. Or copy the skill folder (plugins/magpie-utilities/skills/write-skill in apache/magpie) into .claude/skills/write-skill in your project. Claude Code loads it when a task matches its description.
Run `npx skills add apache/magpie --skill write-skill -a codex`. Or copy the skill folder (plugins/magpie-utilities/skills/write-skill in apache/magpie) into .agents/skills/write-skill in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add apache/magpie --skill write-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/write-skill, .gemini/skills/write-skill, .github/skills/write-skill and .opencode/skills/write-skill in your project.
Going by SKILL.md and its folder, Write Skill needs Python for the scripts in its folder and the command-line tools its instructions call (git, python3 and uv). Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: apache.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Write Skill is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Write Skill: Skill Scanner (getsentry/skills, 1k stars), Forensify (alexgreensh/repo-forensics, 187 stars), Hol Guard (hashgraph-online/hol-guard, 797 stars) and Kesekit Check (cdppcorp/KESE-KIT, 359 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
apache (a GitHub organization) maintains it in apache/magpie, which has 110 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on October 6, 2026.
Source: apache/magpie on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.