The kit vendors (redistributes) every ext/ pack as a submodule. Some are hard to justify or carry licence risk.
Drop or move to registry-only
| Pack |
Concern |
solana-game |
SuperteamBR's own repo; last push 2026-01-30, 9 stars, one skill. It's also the only remaining home for the C# / Unity conventions (see below). |
qedgen |
Lean 4 formal proofs. Needs the qedgen CLI and MISTRAL_API_KEY (upstream also mentions ARISTOTLE_API_KEY), neither in .env.example. About 11 MB, the largest pack. |
eth-to-sol |
No licence, single skill. solana-dev covers EVM migration. |
solana-new |
Registry safety notes telemetry preambles that POST usage events. Disclose this in the README, or move it to registry-only. Also see #98, since bundled skills depend on it. |
Licence
Of the packs we redistribute, these don't grant redistribution in a LICENSE file:
| Pack |
Status |
colosseum |
proprietary ("Copyright Colosseum"), and needs COLOSSEUM_COPILOT_PAT |
metaplex |
licence stated in README only, no LICENSE file |
vercel |
licence stated in README and package.json only, no LICENSE file |
safe-solana-builder |
MIT stated in README only, no LICENSE file; this is a core pack |
trailofbits |
CC-BY-SA-4.0 is share-alike; confirm that vendoring it in an MIT kit creates no obligation (not legal advice) |
defending-code is fine: Apache-2.0 LICENSE file (GitHub shows NOASSERTION because of edits to the file).
C# conventions
The old rules/dotnet.md was deleted in the token cut. unity-engineer now links only to ext/solana-game/skill/csharp-patterns.md (an extension). The global.json SDK-pinning guidance survives nowhere. If solana-game is dropped or stays an extension, decide whether Unity work gets a small kit-owned conventions file.
To do
The kit vendors (redistributes) every
ext/pack as a submodule. Some are hard to justify or carry licence risk.Drop or move to registry-only
solana-gameqedgenMISTRAL_API_KEY(upstream also mentionsARISTOTLE_API_KEY), neither in.env.example. About 11 MB, the largest pack.eth-to-solsolana-devcovers EVM migration.solana-newsafetynotes telemetry preambles that POST usage events. Disclose this in the README, or move it to registry-only. Also see #98, since bundled skills depend on it.Licence
Of the packs we redistribute, these don't grant redistribution in a LICENSE file:
colosseumCOLOSSEUM_COPILOT_PATmetaplexvercelsafe-solana-buildertrailofbitsdefending-codeis fine: Apache-2.0 LICENSE file (GitHub shows NOASSERTION because of edits to the file).C# conventions
The old
rules/dotnet.mdwas deleted in the token cut.unity-engineernow links only toext/solana-game/skill/csharp-patterns.md(an extension). Theglobal.jsonSDK-pinning guidance survives nowhere. Ifsolana-gameis dropped or stays an extension, decide whether Unity work gets a small kit-owned conventions file.To do
metaplex,vercelandsafe-solana-builderto add LICENSE files. Get permission from Colosseum or stop vendoring it..gitmodules, registry, README, hub, tests).