Skip to content

Resolve provenance for bundled Skills before an ASF release #2669

Description

@Astro-Han

Problem

At commit 1518442865763d603571f5d77c13ffc3b0c96125, Maka ships 30 bundled SKILL.md files under packages/runtime/resources/bundled-skills/.

Twenty-nine entered through #842 (68e99e23ec09f08e1666d8fed30b79653d325c65). The remaining computer-use Skill entered through #2147. The 29 files from #842 do not contain an author, fixed source, license, adaptation/translation declaration, or AI-generation declaration.

This is a provenance evidence gap, not a finding that the files infringe copyright or use an incompatible license.

ASF basis

ASF Generative Tooling Guidance says contributors remain responsible for disclosing third-party copyrighted material and its license. For generated material, contributors need reasonable certainty that no unlicensed third-party material is included, and recording the tool with Generated-by: is recommended:

https://www.apache.org/legal/generative-tooling.html

ASF's treatment of third-party works requires the applicable license and notices to accompany third-party material:

https://www.apache.org/legal/src-headers.html#treatment-of-third-party-works

Incubation policy permits a DISCLAIMER-WIP to disclose known incomplete or unreviewed licensing conditions, but disclosure does not establish provenance or replace release review:

https://incubator.apache.org/policy/incubation.html

During the Maka incubation discussion, reviewers recommended investigating code-origin scanning and resolving, removing, or reimplementing material whose origin remains unclear. SCANOSS and FOSSA were suggestions from individual reviewers, not ASF-mandated tools:

Evidence collected

  • None of the 29 SKILL.md files contains its own provenance or license declaration.
  • Eleven Skill names also existed before feat(skills): built-in skill catalog with install-on-demand #842 in ComposioHQ's awesome-claude-skills at commit 92568c1edaff1bde5371154f036d959346c145a8.
  • Name overlap and manual textual comparison do not establish that this repository was Maka's source.
  • The other 18 files have no external source candidate identified.
  • Local dependency and license scans found no GPL, AGPL, commercial, or source-available issue in these files.
  • SCANOSS's default WFP scope does not cover Markdown, so its results cannot close this gap.
  • computer-use has a Maka-specific introducing PR and should receive independent human confirmation, but is not part of the unresolved feat(skills): built-in skill catalog with install-on-demand #842 group.

Decision needed

For each of the 29 Skills, choose one of the following:

  1. Contributor declaration — confirm that it was independently authored or generated, identify the author/tool, and disclose any third-party inputs.
  2. Documented third-party adoption — replace or identify it from a fixed upstream commit, record the compatible license, and preserve required attribution.
  3. Clean rewrite — write a replacement from a short functional specification without consulting the old body, record the generation/authorship process, and review the result.
  4. Removal — remove Skills that are not valuable enough to justify provenance work.

We should not retroactively assign a possible upstream source without evidence.

Completion criteria

  • Every bundled Skill has an independently reviewed origin declaration.
  • Third-party material has a fixed source, compatible license, and required attribution.
  • AI-assisted replacements identify the tool and carry the repository-required Generated-by: commit trailer.
  • Files whose origin cannot be established are removed or independently recreated.
  • A human reviewer verifies the licensing and release conclusion.
  • Any remaining known limitation is stated without claiming that automated scanning proves originality.

AI assistance disclosure: Codex helped organize the evidence and draft this issue. A human maintainer verified the linked commits, repository paths, scan conclusions, and ASF references before posting.

中文对照

问题

在提交 1518442865763d603571f5d77c13ffc3b0c96125 中,Maka 在 packages/runtime/resources/bundled-skills/ 下内置了 30 个 SKILL.md 文件。

其中 29 个通过 #84268e99e23ec09f08e1666d8fed30b79653d325c65)引入,其余的 computer-use Skill 通过 #2147 引入。#842 引入的 29 个文件均未注明作者、固定来源、许可证、改编/翻译关系或 AI 生成情况。

这是来源证据缺口,并不表示已经发现这些文件侵权或使用了不兼容许可证。

ASF 依据

ASF《生成式工具指引》要求贡献者对第三方受版权保护材料及其许可证负责。对于生成内容,贡献者需要有合理把握其中不包含未经许可的第三方材料,并建议使用 Generated-by: 记录所用工具:

https://www.apache.org/legal/generative-tooling.html

ASF 对第三方作品的处理规则要求第三方材料附带适用的许可证和声明:

https://www.apache.org/legal/src-headers.html#treatment-of-third-party-works

孵化政策允许使用 DISCLAIMER-WIP 披露已知但尚未完成或审查的许可证问题,但披露本身不能建立来源,也不能替代发版审查:

https://incubator.apache.org/policy/incubation.html

在 Maka 孵化讨论中,reviewer 建议调研 code-origin 扫描,并解决、移除或重新实现来源不清的材料。SCANOSS 和 FOSSA 是个别 reviewer 提出的工具建议,并非 ASF 强制指定的工具:

已收集证据

  • 这 29 个 SKILL.md 均未在文件内注明自身来源或许可证。
  • 其中 11 个 Skill 名称在 feat(skills): built-in skill catalog with install-on-demand #842 之前已经存在于 ComposioHQ awesome-claude-skills 的提交 92568c1edaff1bde5371154f036d959346c145a8 中。
  • 名称重合和人工文本比较不足以证明该仓库就是 Maka 的来源。
  • 其余 18 个文件尚未发现外部来源候选。
  • 本地依赖与许可证扫描未在这些文件中发现 GPL、AGPL、商业或 source-available 问题。
  • SCANOSS 默认 WFP 范围不包含 Markdown,因此不能依靠其结果关闭该问题。
  • computer-use 有面向 Maka 的独立引入 PR,仍应由独立人类确认,但不属于 feat(skills): built-in skill catalog with install-on-demand #842 的未解决部分。

需要决定

对每个 Skill 选择以下一种处理方式:

  1. 贡献者声明:确认其为独立创作或生成,注明作者/工具,并披露所有第三方输入。
  2. 有记录的第三方采用:从固定上游提交重新采用或明确来源,记录兼容许可证并保留必要署名。
  3. 干净重写:只根据简短功能规格重新编写,不查看旧正文,同时记录生成/创作过程并进行审查。
  4. 移除:删除价值不足以支撑来源核查成本的 Skill。

没有证据时,不应反向指定某个可能的上游为来源。

完成标准

  • 每个 bundled Skill 都有经过独立审查的来源声明。
  • 第三方材料具有固定来源、兼容许可证和必要署名。
  • AI 辅助的替代内容注明所用工具,并包含仓库要求的 Generated-by: commit trailer。
  • 无法确认来源的文件被删除或独立重做。
  • 许可证与发版结论经过人类 reviewer 核实。
  • 对剩余局限进行明确说明,不声称自动扫描能够证明原创性。

AI 辅助披露:Codex 协助整理证据并起草此 Issue。发布前,人类维护者已核实相关 commit、仓库路径、扫描结论和 ASF 引用。

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions