Agent skill

Qv Notice Generate

by tetherto in tetherto/qvac

Generate NOTICE files with third-party attributions for all packages in the monorepo.

Apache-2.0Auto-check: notesDevelopment

Install Qv Notice Generate

skills CLI
$ npx skills add tetherto/qvac --skill qv-notice-generate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tetherto/qvac qv-notice-generate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tetherto/qvac.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/qv-notice-generate .claude/skills/qv-notice-generate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
qv-notice-generate
GitHub stars
685
Token cost
~2k tokens
SKILL.md length
839 words
Files
13 (incl. scripts)
Skills in repo
50
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate NOTICE files with third-party attributions for all packages in the monorepo.

  • Works in 5 steps: Ask which package to generate NOTICE for… → Source .env in the shell → Run the generator script — this writes… → …
  • Tasks that involve Monorepo tooling
  • SKILL.md covers Relationship to the CI license…, When to use this skill, Prerequisites and Workflow, plus 7 more sections
  • Runs JavaScript scripts from its folder; calls node and npm; needs GH_TOKEN and HF_TOKEN

What it does

Qv Notice Generate is an agent skill from tetherto/qvac. Generate NOTICE files with third-party attributions for all packages in the monorepo.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts (for example `scripts/check-forbidden-licenses.js`, `scripts/constants.js` and `scripts/generate-notice.js`).

It sits in Development, covering Monorepo tooling. It works with GitHub. The repository describes itself as: Open-source local AI SDK - run AI on-device with no cloud, no API keys. Supports GGUF, RAG, image, music, and video generation, speech-to-text, P2P inference, and more… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Monorepo tooling

Example prompts

  • “/qv-notice-generate”

Requirements

  • Python 3
  • Node.js
  • A credential in NPM_TOKEN

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Ask which package to generate NOTICE for (or --all for all packages)
  2. Source .env in the shell
  3. Run the generator script — this writes NOTICE files directly
  4. If JS stdout is Found 0 JS dependencies while HEAD's NOTICE still has a
  5. Only use --dry-run if the user explicitly asks for it

What it can do on your machine

Read from SKILL.md and the folder at commit 673ea94. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 12 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GH_TOKEN
    • HF_TOKEN
    • NPM_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Qv Notice Generate loads about 2k tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 839 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~26
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:30
    Before running, ensure `.env` is sourced and contains:
  • NoteMentions a .env fileSKILL.md:41
    2. Source `.env` in the shell
  • NoteMentions a .env fileSKILL.md:56
    source .env
  • NoteMentions a .env fileSKILL.md:69
    source .env
  • NoteMentions a .env fileSKILL.md:76
    source .env
  • NoteMentions a .env fileSKILL.md:89
    source .env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from tetherto/qvac at commit 673ea94, republished under its Apache-2.0 licence (© tetherto). 839 words, ~2,004 tokens.

Download SKILL.mdSave it as .claude/skills/qv-notice-generate/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
qv-notice-generate
description
Generate NOTICE files with third-party attributions for all packages in the monorepo.

NOTICE File Generator

Generate deterministic, sorted NOTICE files for individual packages or all packages at once, covering model, JS, Python, and C++ dependency attributions.

Relationship to the CI license gate (this SKILL is the fallback)

As of QVAC-21554, license/compliance enforcement on Tier-1 PRs is primarily a CI gate — .github/workflows/license-compliance.yml, delegating to the org reusable workflow public-reusable-license.yml (design: tetherto/qvac-actions/docs/license-compliance-ci.md). The gate deterministically classifies newly added PR dependencies against the org policy (allow/deny/review), honours .github/license-allowlist.yml, and posts a PR comment.

This SKILL is now the human fallback for the long tail the gate cannot decide:

  • Novel / unclassifiable licenses. When the gate blocks a High finding it cannot classify, run check-forbidden-licenses.js to investigate, then record the decision in .github/license-allowlist.yml (CODEOWNERS-reviewed) or remove/replace the dependency. The gate is deterministic from then on.
  • Full transitive audit. The CI gate reads GitHub's dependency graph, which is manifest-only in this repo (package lockfiles are gitignored), so it does not resolve the full transitive tree. check-forbidden-licenses.js does a real npm install + license-checker (plus Python/C++/model scans) and is the tool for a complete audit — e.g. before a release, or when the gate's coverage is insufficient.
  • NOTICE authoring. The gate only verifies NOTICE presence (advisory). Generating/updating the NOTICE files themselves remains this SKILL's generate-notice.js job.

When to use this skill

Use when:

  • Generating or updating NOTICE files for any package
  • Adding new third-party dependencies that need attribution
  • Preparing a release that requires up-to-date NOTICE files
  • User invokes /qv-notice-generate

Prerequisites

Before running, ensure .env is sourced and contains:

  • GH_TOKEN -- GitHub token (access to private repos and GitHub API)
  • HF_TOKEN -- HuggingFace token (model license verification)
  • NPM_TOKEN -- npm registry token (private package resolution)

System requirements for Python scanning:

  • python3 and pip available in PATH (for pip-licenses)

Workflow

  1. Ask which package to generate NOTICE for (or --all for all packages)
  2. Source .env in the shell
  3. Run the generator script — this writes NOTICE files directly
  4. If JS stdout is Found 0 JS dependencies while HEAD's NOTICE still has a JS section, restore that JS block from HEAD. (npm install failed is written to gitignored NOTICE_LOG.txt, not stdout.) Keep successful model-scan additions. Do not commit a wiped JS section.
  5. Only use --dry-run if the user explicitly asks for it

Do NOT commit changes. The user will review and commit manually.

Running the scripts

Generate NOTICE for a specific package
bash
source .env
node .agents/skills/qv-notice-generate/scripts/generate-notice.js <package-dir-name>

Example: node .agents/skills/qv-notice-generate/scripts/generate-notice.js sdk

For registry sub-packages use the full path:

  • registry-server/client
  • registry-server/shared
Generate NOTICE for all packages
bash
source .env
node .agents/skills/qv-notice-generate/scripts/generate-notice.js --all
Dry-run (no file writes, safe for testing)
bash
source .env
node .agents/skills/qv-notice-generate/scripts/generate-notice.js --all --dry-run
node .agents/skills/qv-notice-generate/scripts/generate-notice.js sdk --dry-run

In dry-run mode:

  • No files are written (NOTICE, NOTICE_LOG.txt, FORBIDDEN_LICENSES.txt)
  • All scans run fully (npm install, license-checker, pip-licenses, GitHub API, models)
  • NOTICE content is previewed in the console instead of written to disk
Show full SKILL.md (393 more words)Show less
Check for disallowed licenses
bash
source .env
node .agents/skills/qv-notice-generate/scripts/check-forbidden-licenses.js --all --dry-run
node .agents/skills/qv-notice-generate/scripts/check-forbidden-licenses.js --all

Uses an allowlist approach. The ALLOWED_LICENSES array in config.js controls which licenses pass:

  • Empty list (default) -- every license is allowed (open gate). Useful while you are still cataloguing your deps.
  • Populated list -- only those SPDX identifiers pass; anything else is a violation.

License strings from all sources (npm, PyPI, GitHub, models) are normalized to canonical SPDX ids before comparison, so adding apache-2.0 to the list automatically covers Apache 2.0, Apache Software License, Apache License 2.0, etc.

If violations are found, writes FORBIDDEN_LICENSES.txt to the repo root and exits with code 1.

Important: The agent should NOT edit ALLOWED_LICENSES directly. Present the scan results to the user and let them decide which licenses to allow. The allowlist and normalization map live in .agents/skills/qv-notice-generate/scripts/constants.js.

Generate license overview report
bash
node .agents/skills/qv-notice-generate/scripts/generate-report.js

Reads existing NOTICE files across all packages (no scanning, no tokens needed) and produces NOTICE_FULL_REPORT.txt with:

  • Global license distribution with counts and percentages
  • Per-package breakdown by dependency type (models, JS, Python, C++)
  • Packages with no dependencies listed separately
What it produces
  1. Per-package NOTICE file inside each scanned package directory (from generate-notice.js)
  2. NOTICE_FULL_REPORT.txt license overview report (from generate-report.js, gitignored)
  3. NOTICE_LOG.txt at the repo root with errors/warnings (gitignored)

Scan types

TypeWhatTool
ModelsModel attributions from models.prod.jsonDirect JSON parsing
JSProduction npm dependencies (no peers / extraneous)npm install --omit=dev --omit=peer + license-checker, intersected with npm ls
PythonBenchmark/script Python depspip-licenses (auto-installed in temp virtualenv)
C++vcpkg native dependenciesGitHub API + local portfile parsing

Package coverage

  • Models (full list): sdk, inference, registry-server/client
  • Models (by engine): All addon packages, mapped by engine name
  • JS: Every package with dependencies in package.json
  • Python: Packages with requirements.txt or pyproject.toml in benchmarks/scripts
  • C++: Packages with vcpkg.json

Addon-to-engine mapping

Package directoryEngine
embed-llamacpp@qvac/embed-llamacpp
llm-llamacpp@qvac/llm-llamacpp
translation-nmtcpp@qvac/translation-nmtcpp
tts-onnx@qvac/tts-onnx
asr-ggml@qvac/transcription-whispercpp, @qvac/asr-ggml
diffusion-cpp@qvac/diffusion-cpp

asr-ggml carries two engine keys because the whisper + parakeet packages were unified: models.prod.json still names the retired @qvac/transcription-whispercpp engine until the SDK/registry repoint lands.

Sorting guarantee

All entries within every NOTICE file section are sorted deterministically using locale-independent collation. Re-runs on identical input always produce identical output, resulting in clean git diffs.

  • Model license verification: npm run verify:licenses in packages/registry-server -- verifies model licenses in models.prod.json against HuggingFace/GitHub APIs (dry-run only, console output, fails on unverifiable).

References

  • Constants (allowlist, normalization, copyright): .agents/skills/qv-notice-generate/scripts/constants.js
  • Package definitions & internal wiring: .agents/skills/qv-notice-generate/scripts/lib/config.js
  • SDK pod ownership: .github/teams/sdk.json

© tetherto, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (scripts) in .agents/skills/qv-notice-generate of tetherto/qvac.

  • SKILL.md
  • scripts/check-forbidden-licenses.js
  • scripts/constants.js
  • scripts/generate-notice.js
  • scripts/generate-report.js
  • scripts/lib/config.js
  • scripts/lib/notice-writer.js
  • scripts/lib/scan-cpp-deps.js
  • scripts/lib/scan-js-deps.js
  • scripts/lib/scan-js-deps.test.js
  • scripts/lib/scan-models.js
  • scripts/lib/scan-python-deps.js
  • scripts/lib/utils.js

Open the folder on GitHubat commit 673ea94

Compare with similar skills

Qv Notice Generate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Qv Notice Generate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Qv Notice Generate this skilltetherto/qvac685—~2kAutomated safety check: NotesApache-2.0
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Create Vechain Dappvechain/x-app-template450—~1.8kAutomated safety check: PassMIT
Dependabot Alerts Updatelivesession/xyd114—~2kAutomated safety check: PassMIT
Investigate Issueanalogjs/analog3.2k—~2kAutomated safety check: PassMIT

Similar skills

  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Create Vechain Dapp

    vechain/x-app-template

    Scaffold a VeChain dApp with Next.js, VeChain Kit, Chakra UI v3, and GitHub Pages deployment.

    450 GitHub stars~1.8k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

    114 GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Investigate Issue

    analogjs/analog

    Investigate a GitHub issue end to end — reproduce the reporter's repo or code snippet in an isolated sandbox outside the monorepo, trace the root cause in the source, and draft a reply back to the…

    3.2k GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Automate npm Release

    jd-solanki/slidev-theme-dracula

    Automate npm package publishing via GitHub Actions for single-package repos and independent monorepo packages, including bumpp version tags, GitHub release notes, trusted publishing, provenance, and…

    161 GitHub stars~626 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed

More from tetherto/qvac

All 50 skills in this repo
  • Creates a Solutions page in the QVAC documentation website from a real use case, generalizing the case into reusable guidance and registering the page in the site navigation.

    685 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Qv Docs Update

    tetherto/qvac

    Updates the docs website after a change to the SDK or CLI. An agent skill from tetherto/qvac.

    685 GitHub stars~11k tokensUpdated today
    Auto-check passed
  • Qv Agent Stack Sync

    tetherto/qvac

    Plan and prepare the QVAC agent-stack release cascade across @qvac/inference, @qvac/sdk, @qvac/cli, @qvac/ai-sdk-provider, @qvac/opencode-plugin, and @qvac/openclaw-plugin.

    685 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Run the deterministic code-quality audit, turn related findings into contextual remediation groups, prepare approval-gated Asana proposals, reconcile recurring runs, or configure twice-monthly…

    685 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Review C++ changes for string parameter and call-site efficiency conventions (std::stringview, std::string&&, const std::string&, const char, and TransparentStringMap lookup).

    685 GitHub stars~702 tokensUpdated today
    Auto-check passed
  • Qv Addon Changelog

    tetherto/qvac

    Generate changelog entries for a target add-on package. An agent skill from tetherto/qvac.

    685 GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Works with

Questions about Qv Notice Generate

What does Qv Notice Generate do?

Generate NOTICE files with third-party attributions for all packages in the monorepo. Qv Notice Generate is an agent skill from tetherto/qvac. Generate NOTICE files with third-party attributions for all packages in the monorepo.

When should I use Qv Notice Generate?

Qv Notice Generate fits situations like: tasks that involve Monorepo tooling.

How do I install Qv Notice Generate in Claude Code?

Run `npx skills add tetherto/qvac --skill qv-notice-generate -a claude-code`. Or copy the skill folder (.agents/skills/qv-notice-generate in tetherto/qvac) into .claude/skills/qv-notice-generate in your project. Claude Code loads it when a task matches its description.

How do I install Qv Notice Generate in Codex?

Run `npx skills add tetherto/qvac --skill qv-notice-generate -a codex`. Or copy the skill folder (.agents/skills/qv-notice-generate in tetherto/qvac) into .agents/skills/qv-notice-generate in your project. Codex loads it when a task matches its description.

Can I use Qv Notice Generate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tetherto/qvac --skill qv-notice-generate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qv-notice-generate, .gemini/skills/qv-notice-generate, .github/skills/qv-notice-generate and .opencode/skills/qv-notice-generate in your project.

What does Qv Notice Generate need to run?

Going by SKILL.md and its folder, Qv Notice Generate needs JavaScript for the scripts in its folder, the command-line tools its instructions call (node and npm) and credentials named GH_TOKEN, HF_TOKEN and NPM_TOKEN. Our summary lists: Python 3; Node.js; A credential in NPM_TOKEN.

Does Qv Notice Generate access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Qv Notice Generate safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Qv Notice Generate use?

Qv Notice Generate is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Qv Notice Generate use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Qv Notice Generate?

Skills that share tags, products or a category with Qv Notice Generate: Cutting A Release (TriliumNext/Trilium, 38k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Create Vechain Dapp (vechain/x-app-template, 450 stars) and Dependabot Alerts Update (livesession/xyd, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Qv Notice Generate?

tetherto (a GitHub organization) maintains it in tetherto/qvac, which has 685 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 10, 2026.

Source: tetherto/qvac on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.