Open a tracking issue in <tracker> for a security-relevant fix that has already been opened (or merged) as a public PR in <upstream>, in the case where there is no inbound <security-list> report. The tracker lands in the Assessed board column with the scope label applied, pr created / pr merged reflecting the PR's state, and Remediation developer / PR with the fix body fields populated from the PR. Pairs with security-cve-allocate afterwards.
$npx -y skills add apache/magpie --skill security-issue-import-from-prInstalls into the current project.
Run `npx skills use "https://github.com/apache/magpie" --skill "apache/magpie/security-issue-import-from-pr"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/apache/magpie" that are relevant to the current task. Run `npx skills add "https://github.com/apache/magpie"` and select the relevant skills, then follow their instructions.