diff --git a/engineering/book-to-skill/skills/book-to-skill/references/conversion_workflow.md b/engineering/book-to-skill/skills/book-to-skill/references/conversion_workflow.md index f8da377f..eec9a665 100644 --- a/engineering/book-to-skill/skills/book-to-skill/references/conversion_workflow.md +++ b/engineering/book-to-skill/skills/book-to-skill/references/conversion_workflow.md @@ -382,10 +382,23 @@ Emits `//` with `.claude-plugin/plugin.json`, `README.md`, `skills//`, then prints the marketplace entry to register. Drop `--dry-run` to write. **Rights gate.** The emitter defaults to `--distribution local`, which records -`source.cleared_for_distribution: false` in the manifest. `--distribution shareable` **refuses** unless `--rights` names a basis: +`source.cleared_for_distribution: false` in `.claude-plugin/authoring-notes.json`. +`--distribution shareable` **refuses** unless `--rights` names a basis: `public-domain`, `open-license`, `internal-docs`, or `author-permission`. Fair use is deliberately not an option — it is a defence, not a licence, and not this tool's call. +**Attribution is yours to add, by hand, when the source is someone else's work.** The emitter +writes a `source` block — how the skill was built — because that is all it can know; it has +`--source-note` free text and a rights basis, not an upstream URL, author or licence, and a +half-filled `attribution` block is worse than none. So when `--rights` is anything but +`internal-docs`, add an `attribution` block beside it in `authoring-notes.json` +(`derived_from`, `original_author`, `original_license`, `original_copyright`, +`derivation_note` — the shape the rest of this repo uses), and put the upstream licence +notice in the package's `LICENSE` and a credit line in its `README.md`. **That last part is +the obligation:** `authoring-notes.json` is authoring metadata Claude Code never reads, and a +sidecar JSON file is not a licence notice. `engineering/spinning-up-deep-rl` is the worked +example. + The emitter also refuses to wrap a skill with validation errors. Fix the source skill first. Registration in `.claude-plugin/marketplace.json` stays manual — it is a repo-wide change. diff --git a/engineering/spinning-up-deep-rl/.claude-plugin/authoring-notes.json b/engineering/spinning-up-deep-rl/.claude-plugin/authoring-notes.json index 57efee25..d9ec975f 100644 --- a/engineering/spinning-up-deep-rl/.claude-plugin/authoring-notes.json +++ b/engineering/spinning-up-deep-rl/.claude-plugin/authoring-notes.json @@ -9,5 +9,14 @@ "license_scope": "plugin.json's top-level `license` covers this package's scaffolding only. The compiled notes under skills/ are derived from the source document and carry that work's terms; see source.rights_basis.", "rights_basis": "open-license", "rights_note": "the source work carries a licence permitting derivative distribution" + }, + "attribution": { + "derived_from": "https://github.com/openai/spinningup", + "upstream_docs": "https://spinningup.openai.com/", + "upstream_path": "docs/ (reStructuredText tree, 38 files)", + "original_author": "Joshua Achiam, OpenAI", + "original_license": "MIT", + "original_copyright": "Copyright (c) 2018 OpenAI (http://openai.com)", + "derivation_note": "No upstream code or prose is reproduced. The compiled skill is structured study notes -- named frameworks, key concepts, decision rules and per-chapter summaries -- generated by engineering/book-to-skill from the source's docs/ tree, with chapter structure taken from the source's own toctree. Upstream's MIT notice is reproduced in full in this package's LICENSE, which is where the licence obligation is met; this file is authoring metadata and is not a licence notice. Coverage is pinned to the source's final (January 2020 PyTorch) update." } }