Several open PRs could not be decided because CONTRIBUTING.md had nothing to
point at: no scope, no self-promotion or affiliation rules, no PR-size
guidance. Declining on an unwritten rule is unfair to contributors, so the
rules go in first.
SCOPE.md (new)
What a skill is, and what this repository is not: runtimes, engines,
products and applications belong in their own repositories. Offensive and
dual-use content is explicitly in scope - the line is defensive framing and
authorization, not subject matter.
CONTRIBUTING.md
- one skill per pull request, and why batching stalls good work
- overlap: while the description backlog is worked down, a new skill that
overlaps an existing one will usually be asked to extend it instead
- self-promotion and vendor links: commercial tools are fine, including
ones with no free tier, but cost must be stated in Prerequisites and
links must go to documentation rather than signup funnels
- affiliation disclosure, with the consequence stated: the PR goes on hold
until it is disclosed, and nothing is closed over it
- AI-assisted contributions are allowed and must be disclosed; a human must
have run the commands and takes responsibility
- review and response, including a 14-day stale window that closes nothing
permanently
- subdomain list corrected from 24 entries to the 34 canonical values the
validator actually accepts, with the 12 accepted aliases named
README.md
Removed the claim that every PR is reviewed within 48 hours. The oldest
open PR has been waiting since April. Replaced the stale "most in need"
counts, which named domains with 2 and 5 skills that actually have 6 and 10.
tools/README.md
Corrected to match the code: eight required frontmatter fields, not five,
and PyYAML is now a dependency.
Three issues fixed:
1. Description list check — added elif isinstance(desc, list) branch that
emits 'Description must be a string value, not a list'. Previously the
block was silently skipped when YAML returned a list, causing the skill
to pass without validating the description field.
2. tools/README.md synced — updated description constraint from '20-500
characters' to 'at least 50 characters (no upper limit)' to match the
current code (DESCRIPTION_MIN_CHARS=50, no max enforced).
3. --all with wrong CWD now exits 1 — if glob returns no skill dirs,
the script prints an error and exits with code 1 instead of reporting
'Total: 0 Passed: 0 Failed: 0' and exiting 0, which would cause CI to
silently pass while validating nothing.
All 754 skills continue to pass (0 regressions).
- Wrap open() call in try/except for IOError and UnicodeDecodeError
to report clean errors instead of crashing on encoding issues
- Add all subdomains actually used by existing skills in the repo:
identity-access-management (33 skills), security-operations (28),
identity-and-access-management, zero-trust, ot-security, purple-team,
red-team, ai-security, social-engineering-defense, and others
- Remove identity-security as the canonical form is identity-access-management