You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
At commit 1518442865763d603571f5d77c13ffc3b0c96125, Maka ships 30 bundled SKILL.md files under packages/runtime/resources/bundled-skills/.
Twenty-nine entered through #842 (68e99e23ec09f08e1666d8fed30b79653d325c65). The remaining computer-use Skill entered through #2147. The 29 files from #842 do not contain an author, fixed source, license, adaptation/translation declaration, or AI-generation declaration.
This is a provenance evidence gap, not a finding that the files infringe copyright or use an incompatible license.
ASF basis
ASF Generative Tooling Guidance says contributors remain responsible for disclosing third-party copyrighted material and its license. For generated material, contributors need reasonable certainty that no unlicensed third-party material is included, and recording the tool with Generated-by: is recommended:
Incubation policy permits a DISCLAIMER-WIP to disclose known incomplete or unreviewed licensing conditions, but disclosure does not establish provenance or replace release review:
During the Maka incubation discussion, reviewers recommended investigating code-origin scanning and resolving, removing, or reimplementing material whose origin remains unclear. SCANOSS and FOSSA were suggestions from individual reviewers, not ASF-mandated tools:
For each of the 29 Skills, choose one of the following:
Contributor declaration — confirm that it was independently authored or generated, identify the author/tool, and disclose any third-party inputs.
Documented third-party adoption — replace or identify it from a fixed upstream commit, record the compatible license, and preserve required attribution.
Clean rewrite — write a replacement from a short functional specification without consulting the old body, record the generation/authorship process, and review the result.
Removal — remove Skills that are not valuable enough to justify provenance work.
We should not retroactively assign a possible upstream source without evidence.
Completion criteria
Every bundled Skill has an independently reviewed origin declaration.
Third-party material has a fixed source, compatible license, and required attribution.
AI-assisted replacements identify the tool and carry the repository-required Generated-by: commit trailer.
Files whose origin cannot be established are removed or independently recreated.
A human reviewer verifies the licensing and release conclusion.
Any remaining known limitation is stated without claiming that automated scanning proves originality.
AI assistance disclosure: Codex helped organize the evidence and draft this issue. A human maintainer verified the linked commits, repository paths, scan conclusions, and ASF references before posting.
Problem
At commit
1518442865763d603571f5d77c13ffc3b0c96125, Maka ships 30 bundledSKILL.mdfiles underpackages/runtime/resources/bundled-skills/.Twenty-nine entered through #842 (
68e99e23ec09f08e1666d8fed30b79653d325c65). The remainingcomputer-useSkill entered through #2147. The 29 files from #842 do not contain an author, fixed source, license, adaptation/translation declaration, or AI-generation declaration.This is a provenance evidence gap, not a finding that the files infringe copyright or use an incompatible license.
ASF basis
ASF Generative Tooling Guidance says contributors remain responsible for disclosing third-party copyrighted material and its license. For generated material, contributors need reasonable certainty that no unlicensed third-party material is included, and recording the tool with
Generated-by:is recommended:https://www.apache.org/legal/generative-tooling.html
ASF's treatment of third-party works requires the applicable license and notices to accompany third-party material:
https://www.apache.org/legal/src-headers.html#treatment-of-third-party-works
Incubation policy permits a
DISCLAIMER-WIPto disclose known incomplete or unreviewed licensing conditions, but disclosure does not establish provenance or replace release review:https://incubator.apache.org/policy/incubation.html
During the Maka incubation discussion, reviewers recommended investigating code-origin scanning and resolving, removing, or reimplementing material whose origin remains unclear. SCANOSS and FOSSA were suggestions from individual reviewers, not ASF-mandated tools:
Evidence collected
SKILL.mdfiles contains its own provenance or license declaration.awesome-claude-skillsat commit92568c1edaff1bde5371154f036d959346c145a8.computer-usehas a Maka-specific introducing PR and should receive independent human confirmation, but is not part of the unresolved feat(skills): built-in skill catalog with install-on-demand #842 group.Decision needed
For each of the 29 Skills, choose one of the following:
We should not retroactively assign a possible upstream source without evidence.
Completion criteria
Generated-by:commit trailer.AI assistance disclosure: Codex helped organize the evidence and draft this issue. A human maintainer verified the linked commits, repository paths, scan conclusions, and ASF references before posting.
中文对照
问题
在提交
1518442865763d603571f5d77c13ffc3b0c96125中,Maka 在packages/runtime/resources/bundled-skills/下内置了 30 个SKILL.md文件。其中 29 个通过 #842(
68e99e23ec09f08e1666d8fed30b79653d325c65)引入,其余的computer-useSkill 通过 #2147 引入。#842 引入的 29 个文件均未注明作者、固定来源、许可证、改编/翻译关系或 AI 生成情况。这是来源证据缺口,并不表示已经发现这些文件侵权或使用了不兼容许可证。
ASF 依据
ASF《生成式工具指引》要求贡献者对第三方受版权保护材料及其许可证负责。对于生成内容,贡献者需要有合理把握其中不包含未经许可的第三方材料,并建议使用
Generated-by:记录所用工具:https://www.apache.org/legal/generative-tooling.html
ASF 对第三方作品的处理规则要求第三方材料附带适用的许可证和声明:
https://www.apache.org/legal/src-headers.html#treatment-of-third-party-works
孵化政策允许使用
DISCLAIMER-WIP披露已知但尚未完成或审查的许可证问题,但披露本身不能建立来源,也不能替代发版审查:https://incubator.apache.org/policy/incubation.html
在 Maka 孵化讨论中,reviewer 建议调研 code-origin 扫描,并解决、移除或重新实现来源不清的材料。SCANOSS 和 FOSSA 是个别 reviewer 提出的工具建议,并非 ASF 强制指定的工具:
已收集证据
SKILL.md均未在文件内注明自身来源或许可证。awesome-claude-skills的提交92568c1edaff1bde5371154f036d959346c145a8中。computer-use有面向 Maka 的独立引入 PR,仍应由独立人类确认,但不属于 feat(skills): built-in skill catalog with install-on-demand #842 的未解决部分。需要决定
对每个 Skill 选择以下一种处理方式:
没有证据时,不应反向指定某个可能的上游为来源。
完成标准
Generated-by:commit trailer。AI 辅助披露:Codex 协助整理证据并起草此 Issue。发布前,人类维护者已核实相关 commit、仓库路径、扫描结论和 ASF 引用。