Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions LICENSE.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
# License

Third-party files under `wiki/skills/` are excluded from the CC BY 4.0
grant below. They retain the upstream MIT licenses listed in
`wiki/sources.json` and reproduced in `wiki/licenses/`.
Comment on lines +3 to +5

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reflect the mixed licenses in package metadata

Because this remains a publishable package and npm pack --dry-run includes all 268 wiki/skills files, leaving package.json with only "license": "CC-BY-4.0" causes registries, SBOMs, and automated compliance tooling to report the newly bundled MIT material under the wrong license. The npm package metadata documentation requires accurate package-level license metadata; use an appropriate SPDX expression or SEE LICENSE IN LICENSE.md, or exclude the wiki from the package.

Useful? React with 👍 / 👎.

Reference-only catalog entries do not grant rights to their implementations.

This project is licensed under the Creative Commons Attribution 4.0
International License (CC BY 4.0).

Expand Down
5 changes: 5 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,11 @@ work.

## What this is

For a browsable reference, see the [skills and workflows wiki](wiki/README.md):
505 distinct public skill entries, 268 attributed MIT definition copies, and
the 19 existing workflow playbooks. The wiki distinguishes copied source from
reference-only entries and records its inventory limits.

`agentic-workflows` turns AI workflows into repo-native operating files:
validate them, render runbooks, audit authority, and compile them into agent
skills. The current sample pack focuses on public-safe operator workflows and
Expand Down
2 changes: 2 additions & 0 deletions cli/aw.ts
Original file line number Diff line number Diff line change
Expand Up @@ -189,6 +189,8 @@ const PUBLICATION_SCAN_GLOBS = [
"tests/**/*.ts",
"workflows/**/*.md",
"workflows/**/*.yml",
"wiki/**/*.md",
"wiki/**/*.json",
Comment on lines +192 to +193

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include wiki license notices in publication scans

When the default publication gate is run, these new globs scan the wiki Markdown and JSON but omit all seven public wiki/licenses/*.txt files; publication-scan --list confirms that none of those notices reaches scanPublicationText. A refreshed upstream license containing a non-example email, private path, or token-shaped value can therefore pass bun run validate unexamined, so include wiki/**/*.txt and assert one of the license files appears in scan coverage.

Useful? React with 👍 / 👎.

];

const [, , command, ...args] = Bun.argv;
Expand Down
52 changes: 52 additions & 0 deletions tests/wiki.test.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
import { test, expect } from 'bun:test';
import { readFileSync, existsSync } from 'node:fs';
import catalog from '../wiki/catalog.json';
import sources from '../wiki/sources.json';

test('public catalog has distinct identities and reconciled counts', () => {
const skills = catalog.entries.filter(entry => entry.type === 'skill');
expect(skills).toHaveLength(505);
expect(new Set(skills.map(entry => entry.name)).size).toBe(skills.length);
expect(catalog.entries.filter(entry => entry.type === 'workflow')).toHaveLength(19);
expect(catalog.distinctSkillNames - catalog.withheldPrivateSkills).toBe(skills.length);
expect(skills.filter(entry => entry.availability === 'Reference copy')).toHaveLength(268);
});

test('every copied definition and existing playbook resolves to a real file', () => {
for (const entry of catalog.entries) {
if (!entry.documentation) continue;
const path = entry.documentation.split('/blob/main/')[1];
expect(existsSync(path)).toBe(true);
expect(readFileSync(path, 'utf8').trim().length).toBeGreaterThan(50);
}
for (const source of sources) {
expect(source.license).toBe('MIT');
expect(readFileSync(source.licensePath, 'utf8')).toContain('Permission is hereby granted');
}
});

test('public metadata contains no private paths or recognizable secrets', () => {
const text = JSON.stringify(catalog);
expect(text).not.toMatch(/\/Users\/|\/home\//);
expect(text).not.toMatch(/\b(?:sk-[A-Za-z0-9_-]{20,}|gh[pousr]_[A-Za-z0-9]{20,})/);
for (const entry of catalog.entries) {
if (entry.source) expect(entry.source).toStartWith('https://');
expect(entry.name).not.toContain('\n');
}
});

test('reference-only entries never claim a redistributed implementation', () => {
for (const entry of catalog.entries.filter(entry => entry.availability === 'Reference only')) {
expect(entry.documentation).toBeNull();
expect(entry.license).toBe('Not reviewed');
}
});

test('directory descriptions are English and source checks record exact commits', () => {
for (const entry of catalog.entries) {
expect(entry.description).not.toMatch(/[\u3400-\u9fff]/);
}
for (const source of sources) {
expect(source.checkedCommit).toMatch(/^[a-f0-9]{40}$/);
}
});
72 changes: 72 additions & 0 deletions wiki/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
# Skills and workflows wiki

A practical reference for choosing a skill, learning its purpose, and finding
the source. This wiki expands the original seven-library design catalog.

## What is included

| Material | Count | What you can use |
| --- | ---: | --- |
| Distinct skill names reviewed | 511 | Inventory denominator |
| Public skill entries | 505 | Names, short descriptions, categories, and available sources |
| MIT reference copies | 268 | Definition snapshots from the seven credited libraries |
| Existing public workflow playbooks | 19 | Reusable playbooks already in this repository |
| Private-project skills withheld | 6 | Names and instructions are not published |

The inventory covers shared, Codex, Cursor, portfolio-local, and public workflow
skill folders. It does not represent every vendor plugin or every project on
the machine. The 362 local command files are pending individual publication
review; they are not silently represented as public workflows.

## Browse

- [Skill directory](catalog.md): one row per distinct skill name.
- [Machine-readable catalog](catalog.json): the same public entries.
- [Workflow playbooks](../workflows): existing Markdown and executable templates.
- [Sources and licenses](sources.json): upstream attribution for copied material.

## Use a skill

1. Find the job you need to do and read the definition.
2. Open the source library for installation and dependencies.
3. Mention the available skill in your assistant, then supply a concrete goal,
relevant files, constraints, and the checks you expect.
4. Review the result. A skill is guidance, not evidence that work succeeded.

The files under `wiki/skills` are documentation snapshots, not an installation
bundle. Referenced scripts, assets, and supporting documents remain upstream.
Use the source links in the catalog to obtain the complete maintained package.
The English directory summarizes the skills; snapshots retain their original
language. Supporting-file links are pinned to verified upstream commits.
Thirteen references across three snapshots were absent upstream and are
explicitly marked as unavailable text rather than left as broken links.

## Distinct entries

Entries are grouped by frontmatter name. Real-path aliases are resolved before
counting. Repeated names appear once, with the shared copy preferred. Different
implementations with different names are not claimed to be equivalent. This
process does not delete working copies from an assistant's installation.

Counts describe catalog composition, not usage, popularity, quality, or proof
that a skill is currently enabled. The labels are editorial browsing aids.

## Publication boundary

No credentials, conversations, calendars, account data, private project names,
or hidden platform instructions are exported. Source ownership and licensing
for reference-only entries remain unreviewed. Listing an entry does not place
its implementation under this repository's license.

The 268 snapshots retain their upstream MIT licenses, collected in
[licenses](licenses). Original wiki prose and the existing repository workflow
material remain CC BY 4.0. Changes to snapshot formatting or links must be
identified. These copies preserve the installed definition text except for
supporting-link repairs, unavailable-reference labels, and trailing whitespace.

## Keep it current

Review the source, license, and privacy boundary before adding a copy. Keep
`catalog.json` and `catalog.md` aligned. Run the repository validation and wiki
tests before publishing. Refresh the portfolio copy from the same catalog,
not from a separate handwritten list.
Loading
Loading