Skip to content

docs(attribution): narrow data-visualization import to SKILL.md - #112

Merged
erinepshovel-code merged 1 commit into
mainfrom
repair/data-visualization-attribution
Sep 28, 2026
Merged

erinepshovel-code merged 1 commit into
mainfrom
repair/data-visualization-attribution

Conversation

@erinepshovel-code

Copy link
Copy Markdown
Contributor

Summary

ATTRIBUTION.md listed the whole data-visualization/ directory as imported from anthropics/knowledge-work-plugins. Upstream supplied only SKILL.md. This PR narrows the imported path to data-visualization/SKILL.md and says that the other four items in that directory are original to skill-lib under MPL-2.0. This was flagged in The-Interdependency/stack#60 (the "One imprecision" paragraph and the hmmm at the end of that PR).

Evidence

  • Upstream tree: the recursive tree of anthropics/knowledge-work-plugins@94e1a089d28d3e0c2ad9af696f8499cd8c6f7205 has exactly one file under data/skills/data-visualization/: SKILL.md (blob 409cce6). I compared the upstream file lists for all five imported skills with git ls-files. The only paths that exist here but not upstream are:
    • data-visualization/examples/information-design-manifest.json
    • data-visualization/information_design_audit.py
    • data-visualization/references/information-design-evidence.md
    • data-visualization/visual-grammar.json
  • Local history (git log --follow):
    • data-visualization/SKILL.md was first added in the import commit be79109 ("Import batch 1: five data skills…"). That commit touched only SKILL.md in this directory. The file was changed again in 868de86.
    • Each of the four other files has exactly one commit: 868de86 ("Add evidence-grounded information design checks", Erin Spencer, 2026-08-07).
  • Local changes to SKILL.md: compared with upstream, the only removed lines are the frontmatter description (reworded to "Use this when") and the Cowork-only user-invocable: false key. Everything else is additions: the Workflow/Anti-patterns/Provenance/hmmm section from be79109 and the information-design extension from 868de86. The upstream body is otherwise unmodified, which matches the existing Provenance section of the skill.

Changes

  • ATTRIBUTION.md:
    • The imported path is now data-visualization/SKILL.md only.
    • The information-design extension is recorded as a local modification of that file.
    • The four local files are listed as original to skill-lib under MPL-2.0 (LICENSE).
  • skill-lib_msdmd.ts: regenerated with python -m msdmd.collect … --strict. The collection's snapshot identity includes the content of ATTRIBUTION.md, so --check fails without this. The diff is the new snapshot hash in every address, plus the new content_sha256 and size for ATTRIBUTION.md.

Verification

  • Native collection --check and tsc --noEmit --strict: pass
  • python -m unittest discover -s tests: 377 passed (Python 3.13, pinned msdmd/requirements.txt, Node 24.15.0 npm ci)
  • drift and compliance --warnings-fail, codex adapters --check, llms.build --check, RATIOS --strict, gonol authority, RepoLOTO audit and checks, no tracked bytecode, git diff --check: all pass

hmmm

  • Some summaries still describe data-visualization/ as a whole as "Imported from anthropics/knowledge-work-plugins (Apache-2.0)": README.md, CLAUDE.md and ORG_DISTRIBUTION.md rows, and the skill's own Provenance section. They were left unchanged to keep this PR scoped to ATTRIBUTION.md. Whether to narrow them too is open.
  • The licence of the locally written sections inside data-visualization/SKILL.md (the bookend and the information-design extension) is not declared separately. The file as a whole still carries the Apache-2.0 notice as a modified imported file.
  • Consumers such as stack vendor a verbatim copy of ATTRIBUTION.md (stack#60). They will carry the old wording until they next sync.

Upstream anthropics/knowledge-work-plugins@94e1a08 ships only
data/skills/data-visualization/SKILL.md. The examples/, references/,
information_design_audit.py, and visual-grammar.json files were added
locally in skill-lib 868de86 and are original MPL-2.0 content. Records
the appended information-design extension as a local modification of
the imported SKILL.md.

Regenerates skill-lib_msdmd.ts with msdmd.collect because the snapshot
identity binds ATTRIBUTION.md content (collection --check requires it).

Flagged in The-Interdependency/stack#60.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T21:02:03.076875Z 8f23c5e PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8f23c5ecba

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread ATTRIBUTION.md
Comment on lines +22 to +23
- `data-visualization/SKILL.md` only (upstream
`data/skills/data-visualization/` contains no other file at `94e1a08`)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update the remaining directory-level license summaries

When consumers rely on README.md:71, CLAUDE.md:78, or especially the propagation inventory in ORG_DISTRIBUTION.md:62, they are still told that the entire data-visualization/ directory is imported under Apache-2.0, contradicting this new file-level attribution and potentially causing the four MPL-2.0 helper artifacts to be redistributed under the wrong license. Update those derived summaries in the same change instead of leaving the repository with conflicting provenance.

AGENTS.md reference: AGENTS.md:L174-L177

Useful? React with 👍 / 👎.

@erinepshovel-code
erinepshovel-code merged commit 516933d into main Sep 28, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant