Audit dependencies for vulnerabilities, outdated packages, and license compliance.
Make a technical decision with structured reasoning and create an Agent Decision Record (AgDR).
DFD with trust boundaries + data classifications (Mermaid + optional Threat Dragon JSON). Source-of-truth for /threat-model.
Onboard an external repo via a structured handover assessment + harnessability scoring across 5 codebase dimensions.
Cut an apexyard release — diff dev↔main, pick semver bump, generate CHANGELOG, open release PR, auto-tag on merge.
First-run framework bootstrap — 3 exchanges (describe stack → defaults → accept/customize) and the fork is configured.
Migrate single-fork to split-portfolio mode (public framework + private portfolio) via gated destructive recovery flow.
Sync the ApexYard fork with upstream — preview, merge-or-rebase on a sync branch, walk per-version migrations.