Skip to content

Review vendored packs: drop candidates, licences, and the C# conventions gap #107

Description

@Potolski

The kit vendors (redistributes) every ext/ pack as a submodule. Some are hard to justify or carry licence risk.

Drop or move to registry-only

Pack Concern
solana-game SuperteamBR's own repo; last push 2026-01-30, 9 stars, one skill. It's also the only remaining home for the C# / Unity conventions (see below).
qedgen Lean 4 formal proofs. Needs the qedgen CLI and MISTRAL_API_KEY (upstream also mentions ARISTOTLE_API_KEY), neither in .env.example. About 11 MB, the largest pack.
eth-to-sol No licence, single skill. solana-dev covers EVM migration.
solana-new Registry safety notes telemetry preambles that POST usage events. Disclose this in the README, or move it to registry-only. Also see #98, since bundled skills depend on it.

Licence

Of the packs we redistribute, these don't grant redistribution in a LICENSE file:

Pack Status
colosseum proprietary ("Copyright Colosseum"), and needs COLOSSEUM_COPILOT_PAT
metaplex licence stated in README only, no LICENSE file
vercel licence stated in README and package.json only, no LICENSE file
safe-solana-builder MIT stated in README only, no LICENSE file; this is a core pack
trailofbits CC-BY-SA-4.0 is share-alike; confirm that vendoring it in an MIT kit creates no obligation (not legal advice)

defending-code is fine: Apache-2.0 LICENSE file (GitHub shows NOASSERTION because of edits to the file).

C# conventions

The old rules/dotnet.md was deleted in the token cut. unity-engineer now links only to ext/solana-game/skill/csharp-patterns.md (an extension). The global.json SDK-pinning guidance survives nowhere. If solana-game is dropped or stays an extension, decide whether Unity work gets a small kit-owned conventions file.

To do

  • Decide per pack: keep / registry-only / drop.
  • Ask the upstream maintainers of metaplex, vercel and safe-solana-builder to add LICENSE files. Get permission from Colosseum or stop vendoring it.
  • Follow the ripple map for any removal (.gitmodules, registry, README, hub, tests).

Activity

  1. added
    questionFurther information is requested
    submodulesPull requests that update submodules code
    on Oct 1, 2026
  2. kauenet commented on Oct 1, 2026

    @kauenet
    Collaborator

    Factual correction, shared with #100

    Both issues state that qedgen's MISTRAL_API_KEY is missing from .env.example. It is present at .env.example:11. Only ARISTOTLE_API_KEY is genuinely absent.

    Direct conflict with #98 on solana-new

    This issue wants solana-new registry-only (telemetry preambles); #98 wants it promoted to core, because the three shipped go-to-market skills link into it 36 times (idea-sprint 23, pitch-deck 8, hackathon 5) plus 44 occurrences under plugin/, where ext/ never exists.

    "Core" means vendored into every install; "registry-only" means not a submodule at all. These cannot both happen. Registry-only would also permanently break the dead-link gate at tests/test_skill_extensions.sh:126-152, which tolerates an unresolved ext/ link only when the same line offers skills.sh add <pack>.

    Suggested ordering: settle this issue's licence clearance before #98 promotes anything, since #98's candidates include trailofbits (CC-BY-SA-4.0 share-alike) and the core tier already contains safe-solana-builder with no LICENSE file. Promoting into every install is the moment redistribution exposure becomes real.

    #100's registry-accuracy work feeds both and should land first. Its other claims verified: meteora-sdk-skill source 404s; get-shit-done is ARCHIVED while the registry says safety: clean; emilkowalski/skill is now emilkowalski/skills (MIT, ~42.6k stars, pushed 2026-09-23) against the registry's none/unspecified, 2400 stars, "stale (~Mar 2026)"; exactly 7 entries share the placeholder last_commit: 2026-06-15; 38 of 59 entries are untiered.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requestedsubmodulesPull requests that update submodules code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions