docs(attribution): narrow data-visualization import to SKILL.md - #112
Conversation
Upstream anthropics/knowledge-work-plugins@94e1a08 ships only data/skills/data-visualization/SKILL.md. The examples/, references/, information_design_audit.py, and visual-grammar.json files were added locally in skill-lib 868de86 and are original MPL-2.0 content. Records the appended information-design extension as a local modification of the imported SKILL.md. Regenerates skill-lib_msdmd.ts with msdmd.collect because the snapshot identity binds ATTRIBUTION.md content (collection --check requires it). Flagged in The-Interdependency/stack#60.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8f23c5ecba
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - `data-visualization/SKILL.md` only (upstream | ||
| `data/skills/data-visualization/` contains no other file at `94e1a08`) |
There was a problem hiding this comment.
Update the remaining directory-level license summaries
When consumers rely on README.md:71, CLAUDE.md:78, or especially the propagation inventory in ORG_DISTRIBUTION.md:62, they are still told that the entire data-visualization/ directory is imported under Apache-2.0, contradicting this new file-level attribution and potentially causing the four MPL-2.0 helper artifacts to be redistributed under the wrong license. Update those derived summaries in the same change instead of leaving the repository with conflicting provenance.
AGENTS.md reference: AGENTS.md:L174-L177
Useful? React with 👍 / 👎.
Summary
ATTRIBUTION.mdlisted the wholedata-visualization/directory as imported fromanthropics/knowledge-work-plugins. Upstream supplied onlySKILL.md. This PR narrows the imported path todata-visualization/SKILL.mdand says that the other four items in that directory are original to skill-lib under MPL-2.0. This was flagged in The-Interdependency/stack#60 (the "One imprecision" paragraph and thehmmmat the end of that PR).Evidence
anthropics/knowledge-work-plugins@94e1a089d28d3e0c2ad9af696f8499cd8c6f7205has exactly one file underdata/skills/data-visualization/:SKILL.md(blob409cce6). I compared the upstream file lists for all five imported skills withgit ls-files. The only paths that exist here but not upstream are:data-visualization/examples/information-design-manifest.jsondata-visualization/information_design_audit.pydata-visualization/references/information-design-evidence.mddata-visualization/visual-grammar.jsongit log --follow):data-visualization/SKILL.mdwas first added in the import commitbe79109("Import batch 1: five data skills…"). That commit touched onlySKILL.mdin this directory. The file was changed again in868de86.868de86("Add evidence-grounded information design checks", Erin Spencer, 2026-08-07).SKILL.md: compared with upstream, the only removed lines are the frontmatterdescription(reworded to "Use this when") and the Cowork-onlyuser-invocable: falsekey. Everything else is additions: the Workflow/Anti-patterns/Provenance/hmmm section frombe79109and the information-design extension from868de86. The upstream body is otherwise unmodified, which matches the existing Provenance section of the skill.Changes
ATTRIBUTION.md:data-visualization/SKILL.mdonly.LICENSE).skill-lib_msdmd.ts: regenerated withpython -m msdmd.collect … --strict. The collection's snapshot identity includes the content ofATTRIBUTION.md, so--checkfails without this. The diff is the new snapshot hash in every address, plus the newcontent_sha256andsizeforATTRIBUTION.md.Verification
--checkandtsc --noEmit --strict: passpython -m unittest discover -s tests: 377 passed (Python 3.13, pinnedmsdmd/requirements.txt, Node 24.15.0npm ci)--warnings-fail, codex adapters--check,llms.build --check, RATIOS--strict, gonol authority, RepoLOTO audit and checks, no tracked bytecode,git diff --check: all passhmmm
data-visualization/as a whole as "Imported fromanthropics/knowledge-work-plugins(Apache-2.0)":README.md,CLAUDE.mdandORG_DISTRIBUTION.mdrows, and the skill's own Provenance section. They were left unchanged to keep this PR scoped toATTRIBUTION.md. Whether to narrow them too is open.data-visualization/SKILL.md(the bookend and the information-design extension) is not declared separately. The file as a whole still carries the Apache-2.0 notice as a modified imported file.ATTRIBUTION.md(stack#60). They will carry the old wording until they next sync.