Agent skill

Deidentify

by Aperivue in Aperivue/medsci-skills

A skill your agent uses when clinical data may contain PHI and must be de-identified before any LLM-assisted analysis.

MITAuto-check passedResearch & Science

Install Deidentify

skills CLI
$ npx skills add Aperivue/medsci-skills --skill deidentify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Aperivue/medsci-skills deidentify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Aperivue/medsci-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deidentify .claude/skills/deidentify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deidentify
GitHub stars
329
Token cost
~3.4k tokens
SKILL.md length
1,760 words
Files
25 (incl. references)
Skills in repo
54
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when clinical data may contain PHI and must be de-identified before any LLM-assisted analysis.

  • Works in 5 steps: Assessment → Script Execution → Interactive Review Guidance → …
  • Clinical data may contain PHI and must be de-identified before any LLM-assisted analysis
  • SKILL.md covers Critical Safety Rules, Reference Files, Prerequisites and Five-Phase Workflow, plus 5 more sections
  • Runs Python scripts from its folder; calls python3 and pip

What it does

Deidentify is an agent skill from Aperivue/medsci-skills. Use when clinical data may contain PHI and must be de-identified before any LLM-assisted analysis. A local Python script (no network or AI calls) detects identifiers with regex and heuristics in 11 country locale packs, with interactive terminal review.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 26 other files, including reference files (for example `deidentify.py`, `locales/_template.json` and `locales/au.json`).

It sits in Research & Science. It works with Python and Microsoft Excel. The repository describes itself as: Agent Skills for medical research — literature search, reporting-guideline & citation checks, statistics, publication figures, submission. Works with Claude Code, Codex, Cursor &… The licence is MIT.

When your agent uses it

  • Clinical data may contain PHI and must be de-identified before any LLM-assisted analysis

Example prompts

  • “/deidentify”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Assessment
  2. Script Execution
  3. Interactive Review Guidance
  4. Verify and Document
  5. Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit 3b14ae2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deidentify loads about 3.4k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 1,760 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Aperivue/medsci-skills at commit 3b14ae2, republished under its MIT licence (© Aperivue). 1,760 words, ~3,412 tokens.

Download SKILL.mdSave it as .claude/skills/deidentify/SKILL.md (or your agent's skills folder). This skill also uses 24 other files; get the full folder from GitHub.
name
deidentify
description
Use when clinical data may contain PHI and must be de-identified before any LLM-assisted analysis. A local Python script (no network or AI calls) detects identifiers with regex and heuristics in 11 country locale packs, with interactive terminal review.
metadata.triggers
deidentify, de-identify, anonymize, 비식별화, 익명화, remove PHI, remove PII, strip patient info

De-identification Skill

You are guiding a medical researcher through data de-identification. The actual de-identification is performed by a standalone Python script that runs WITHOUT any LLM. Your role is to explain, guide, and verify — not to see or process raw PHI data.

Critical Safety Rules

  1. NEVER ask the user to paste, show, or upload raw data containing PHI. The script processes data locally. You never need to see patient-level data.
  2. NEVER read or display the mapping file contents. It contains original PHI values.
  3. You may read the scan and reviewed reports (column classifications; no cell values) and the audit log (keyed hashes; no original values). Read the de-identified output only after the researcher has run the review and confirmed it; it has the identifiers they chose to anonymize removed, and nothing more (see "What the tool does not do").
  4. Always communicate in the user's preferred language about the process, but use English for technical terms (PHI, HIPAA, Safe Harbor, etc.).
  5. The researcher runs the script in their own terminal, not through you (no ! prefix, no Bash tool call): the review prints sample values of every column.

Reference Files

  • ${CLAUDE_SKILL_DIR}/references/hipaa_18_identifiers.md — HIPAA Safe Harbor checklist
  • ${CLAUDE_SKILL_DIR}/references/korean_phi_patterns.md — Korean-specific regex patterns
  • ${CLAUDE_SKILL_DIR}/references/date_shift_guide.md — Date shifting best practices

Read relevant references before advising the researcher.

Prerequisites

  • Python 3.9+
  • openpyxl (for .xlsx files): pip install openpyxl
  • Supported formats: CSV, TSV, Excel (.xlsx)

Five-Phase Workflow

Phase 1: Assessment

Ask the researcher:

  1. What file format is the data? (CSV, Excel, etc.)
  2. What PHI do you expect in the data? (names, dates, IDs, etc.)
  3. Does your IRB require specific de-identification documentation?
  4. Do you need to re-identify later? (affects mapping file choice)

Based on answers, recommend the appropriate command:

  • Full pipeline (most common): python3 deidentify.py full <file> --locale <code>
  • Step-by-step (cautious): python3 deidentify.py scan <file> --locale <code> first

Available locale codes: kr (Korea), us (USA), jp (Japan), cn (China), de (Germany), uk (United Kingdom), fr (France), ca (Canada), au (Australia), in (India), it (Italy). If --locale is omitted, the script shows an interactive country selection menu. Users can provide a custom locale file via --locale-file custom.json.

Phase 2: Script Execution

Guide the researcher to run the script. The script is located at:

${CLAUDE_SKILL_DIR}/deidentify.py

Full pipeline (recommended for most users):

bash
python3 ${CLAUDE_SKILL_DIR}/deidentify.py full data.xlsx \
    --locale kr \
    --output-dir ./deidentified/

Step-by-step (for careful review):

bash
# Step 1: Scan
python3 ${CLAUDE_SKILL_DIR}/deidentify.py scan data.xlsx --locale kr --output-dir ./deidentified/

# Step 2: Review (interactive)
python3 ${CLAUDE_SKILL_DIR}/deidentify.py review ./deidentified/scan_report.json

# Step 3: Apply (refuses a report that was not reviewed, has a column without a decision,
# or was made from data that has changed since: edit the file, then scan and review again)
python3 ${CLAUDE_SKILL_DIR}/deidentify.py apply ./deidentified/reviewed_report.json

Options:

  • --locale CODE: Country locale for PHI patterns (kr, us, jp, cn, de, uk, fr, ca, au, in, it)
  • --locale-file PATH: Custom locale JSON file (copy locales/_template.json to create one)
  • --auto-accept-safe: Keep SAFE columns without showing them. Not recommended: SAFE means no pattern matched, not that the column holds no identifiers (a name typed into a short comment matches no pattern), and this option means nobody looks at those columns
  • --hash-mapping: Store unkeyed SHA-256 hashes instead of original names/IDs in the mapping file. Dates and numeric IDs can be recovered from such hashes by trying every candidate, so mapping.json stays restricted either way
  • --output-dir: Where to save de-identified file, mapping, and audit log
  • -v/--verbose: Enable debug logging
Phase 3: Interactive Review Guidance

The script's terminal review has three passes:

  1. Pass 1 — Column Classification: Each column is shown as PHI / REVIEW_NEEDED / SAFE, with sample values. The researcher confirms or overrides each classification.
  2. Pass 2 — Undecided Items: Columns that weren't resolved in Pass 1 get a second look with more sample values displayed.
  3. Pass 3 — Final Summary: A table of all planned actions. The researcher can edit individual decisions before confirming.
  4. Patient key (only when dates will be shifted): the researcher picks the column that identifies the patient, or row if every row is a different patient. Each patient gets their own offset; without a key the tool does not shift dates.

Coach the researcher. Deliver these prompts in the researcher's preferred language:

  • "Columns classified as PHI are anonymized by default. Press 'k' to keep the original value."
  • "REVIEW_NEEDED are columns the script could not vouch for: free text, a PHI word inside a longer column name, ID-like numbers, a rare address. Read the sample values and type 'a' or 'k' — Enter alone is not accepted for these."
  • "SAFE means no pattern matched, not that the column is free of identifiers. Read its sample values too, and press 'r' if a column holds names or anything else identifying."
  • For free-text columns, 'a' replaces each whole text with [REDACTED]: the script cannot find a name inside a sentence, so it does not try to keep the rest of the text.
Phase 4: Verify and Document

After the script completes, help the researcher verify:

  1. Read the audit log (no original values; before_hash is an HMAC-SHA256 under a per-run key that is kept only in mapping.json):

    bash
    cat ./deidentified/audit_log.csv | head -20

    Verify the number of changes, affected columns, and PHI types.

  2. Ask the researcher to spot-check the de-identified file first, in their own terminal: pseudonyms (P0001, etc.), shifted dates and [REDACTED] markers where expected, and no names in the columns they kept. Read it yourself only after they confirm.

  3. Check that sensitive columns are actually removed: Verify no original names, phone numbers, or RRN values remain.

  4. Mapping file security:

    • Remind the researcher: "mapping.json contains original patient identifiers — treat it as restricted."
    • Recommend storing it separately from the de-identified data
    • File permissions are automatically set to 0600 (owner-only)
Phase 5: Documentation

Generate a de-identification methods paragraph for the manuscript or IRB:

Template:

Direct identifiers were removed from the dataset prior to analysis using a rule-based de-identification tool (deidentify.py, medsci-skills) with the [COUNTRY] locale pattern pack. The tool scanned column names and cell values using regex patterns for country-specific identifiers (e.g., national ID numbers, phone numbers), email addresses, dates, and addresses. Each column classification was reviewed by the researcher in an interactive terminal session. Names were replaced with pseudonyms (P0001, P0002, ...), dates were shifted by a random per-patient offset (1-365 days, either direction) preserving relative temporal intervals, and direct identifiers (phone numbers, email addresses, national ID numbers) were suppressed. A total of [N] cells across [M] columns were de-identified. The de-identification mapping file was stored separately under restricted access (file permissions 0600).

Customize based on the actual audit log statistics. Do not call the dataset "de-identified under HIPAA Safe Harbor" (or anonymised under another law) unless the gaps listed in "What the tool does not do" were closed as well, or an expert determination covers them.

Show full SKILL.md (708 more words)Show less

Cross-Skill Integration

  • deidentify sits BEFORE clean-data in the research pipeline
  • After de-identification, hand off to /clean-data for data quality profiling
  • /analyze-stats can safely process the de-identified output
  • /write-paper Methods section should reference the de-identification process
  • /write-protocol can use the HIPAA/PIPA reference files for protocol documentation

Output Files

FileContains PHI?Safe for Claude?Purpose
*_deidentified.xlsx/csvOnly what the researcher kept, and what the tool cannot detect (see below)After the researcher confirms itData for analysis
mapping.jsonYESNoOriginal ↔ pseudonym mapping, per-patient date offsets, audit hash key
audit_log.csvNo original values (keyed hashes)YesWhat was changed and where
scan_report.jsonNo cell valuesYesColumn classification results
reviewed_report.jsonNo cell valuesYesResearcher-reviewed classifications and patient key column

What the tool does not do

The tool removes or replaces the identifiers the researcher marked for anonymization. It does not by itself make a dataset HIPAA Safe Harbor de-identified, or anonymous under other laws:

  • Ages over 89 are kept as they are. Safe Harbor requires ages 90 and over to be grouped (e.g. "90+"); do it before sharing.
  • Shifted dates keep a day and a month. Safe Harbor removes every date element except the year; date shifting is a different method (typically justified by an expert determination or used within a limited data set). Dates the script cannot parse become [DATE_SHIFTED].
  • Names in text are not found. Free-text columns are REVIEW_NEEDED and, if anonymized, replaced as a whole. A name in a short comment column can still be classified SAFE: the review shows every column's sample values so the researcher can catch it.
  • Rare combinations are not assessed. Small cells, rare diagnoses, or quasi-identifiers (age + sex + ZIP + admission month) can identify a patient; no k-anonymity check is run.
  • Geography is only as fine as the patterns. Addresses and postcodes are detected per locale; truncating ZIP codes to three digits (Safe Harbor) is not done.
  • Known limits — bare 5-digit US ZIP codes: a ZIP column is caught by its name (zip, zipcode, zip_code) or by the ZIP+4 form (94110-1234). A bare 5-digit value cannot be told apart from other 5-digit codes (e.g. procedure codes), so a ZIP column under another name can be classified SAFE: check the sample values in review.
  • Known limits — dates: these spellings are still classified SAFE: month-first with a dash (Mar-15-2024), year-first with a month word (2024-Mar-15), month and year only (March 2024), non-English month words (15 mars 2024, 15. März 2024), and two-digit-year day/month dates outside the us locale (15/03/24 under uk). Under us, any M/D/YY-shaped value (e.g. 1/2/10) is treated as a date, so a column of such three-part numbers is flagged PHI/date.
  • Not detected: URLs, IP addresses, account, licence, vehicle and device numbers (fax numbers only where they look like the locale's phone numbers), and identifiers written in column names or file names. Only the first sheet of an Excel file is processed (the other sheets are not written to the output).

Scope and Limitations

Supported (v1):

  • Structured tabular data: CSV, TSV, Excel (.xlsx)
  • 11 country locales with country-specific PHI patterns:
    • Korea (kr): RRN (주민번호), phone, email, address, Hangul names, dates
    • USA (us): SSN, US phone, US address, zip codes
    • Japan (jp): マイナンバー, Japanese phone, 都道府県 address, Kanji names
    • China (cn): 身份证号, Chinese phone, 省市区 address, Chinese names
    • Germany (de): Steuer-ID, German phone, Straße address
    • UK (uk): NHS Number, NI Number, UK phone, postcodes
    • France (fr): NIR/INSEE, French phone, Rue address
    • Canada (ca): SIN, Canadian phone, postal codes
    • Australia (au): TFN, Medicare number, AU phone
    • India (in): Aadhaar, PAN, Indian phone, pin codes
    • Italy (it): Codice Fiscale, Italian phone, Via address
  • Universal patterns (all locales): email, ISO dates, high-cardinality numeric IDs (MRN)
  • English column names recognized across all locales
  • Custom locale support via --locale-file with template
  • Pseudonymization, date shifting, ID replacement, suppression

NOT supported (planned for v2):

  • DICOM image metadata (PS3.15 Annex E) — requires pydicom
  • Clinical free-text NER (clinical notes, radiology reports)
  • Automated k-anonymity / l-diversity assessment
  • SPSS (.sav), SAS (.sas7bdat), or other statistical formats

Anti-Hallucination

  • Never fabricate file paths, URLs, DOIs, or package names. Verify existence before recommending.
  • Never invent journal metadata, impact factors, or submission policies without verification at the journal's website.
  • If a tool, package, or resource does not exist or you are unsure, say so explicitly rather than guessing.

© Aperivue, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 24 other files (references) in skills/deidentify of Aperivue/medsci-skills.

  • SKILL.md
  • deidentify.py
  • locales/_template.json
  • locales/au.json
  • locales/ca.json
  • locales/cn.json
  • locales/de.json
  • locales/fr.json
  • locales/in.json
  • locales/it.json
  • locales/jp.json
  • locales/kr.json
  • locales/uk.json
  • locales/us.json
  • references/date_shift_guide.md
  • references/hipaa_18_identifiers.md
  • references/korean_phi_patterns.md
  • skill.yml
  • tests
  • … and 6 more

Open the folder on GitHubat commit 3b14ae2

Compare with similar skills

Deidentify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deidentify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deidentify this skillAperivue/medsci-skills329—~3.4kAutomated safety check: PassMIT
Topic Model ConsolidationTyrealQ/q-skills108—~1kAutomated safety check: PassMIT
ModelViz Scientific PlotshrdZhu/modelviz-skill286—~3.6kAutomated safety check: PassNone
Excel Spreadsheet Creation and Editinganthropics/skills180k4 repos~2.1kAutomated safety check: PassProprietary
Excel and CSV Data Analysisbytedance/deer-flow83k4 repos~2.2kAutomated safety check: PassMIT
XLSXrvdbreemen/OTGW-firmware20735 repos~2.9kAutomated safety check: PassProprietary

Similar skills

  • Consolidates BERTopic, LDA or NMF topic output into a theory-driven classification framework and writes the final labels back to an Excel file.

    108 GitHub stars~1k tokensUpdated 14 days ago
    Research & ScienceAuto-check passed
  • ModelViz Scientific Plots

    hrdZhu/modelviz-skill

    Turns your CSV or Excel data and a plain-language request into a publication-style scientific chart by adapting a catalog template, then checks and repairs it.

    286 GitHub stars~3.6k tokensUpdated 2 mo ago
    Data & AnalyticsAuto-check passed
  • Official

    Creates, edits and analyzes spreadsheets (.xlsx, .xlsm, .csv, .tsv) with openpyxl and pandas, writing live formulas and recalculating to confirm zero formula errors.

    180k GitHub starsUsed in 4 repos~2.1k tokens
    Documents & OfficeAuto-check passed
  • Excel and CSV Data Analysis

    bytedance/deer-flow

    Analyzes uploaded Excel and CSV files with SQL through DuckDB, producing schema inspections, statistical summaries and exports to CSV, JSON or Markdown.

    83k GitHub starsUsed in 4 repos~2.2k tokens
    Data & AnalyticsAuto-check passed
  • XLSX

    rvdbreemen/OTGW-firmware

    Use this skill any time a spreadsheet file is the primary input or output.

    207 GitHub starsUsed in 35 repos~2.9k tokens
    Documents & OfficeAuto-check passed
  • PipesHub Excel Spreadsheet Builder

    pipeshub-ai/pipeshub-ai

    Creates and edits .xlsx workbooks with real Excel formulas rather than hardcoded computed values, defaulting to exceljs in TypeScript with a static formula-safety check.

    3.8k GitHub stars~1.8k tokensUpdated today
    Documents & OfficeAuto-check passed

More from Aperivue/medsci-skills

All 54 skills in this repo
  • Model Assessment

    Aperivue/medsci-skills

    A skill your agent uses when validating or evaluating a trained medical-imaging model.

    329 GitHub starsUsed in 1 repo~4.5k tokens
    Auto-check passed
  • Obsidian Paper Vault

    Aperivue/medsci-skills

    A skill your agent uses when turning a folder of research PDFs into Obsidian notes, even if Obsidian is not named.

    329 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Radiomics ML

    Aperivue/medsci-skills

    A skill your agent uses when building or auditing a radiomics or tabular clinical-ML prediction model with a classical learner (LASSO, SVM, random forest, XGBoost and similar).

    329 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Verify Refs

    Aperivue/medsci-skills

    A skill your agent uses when checking whether a manuscript's references are real.

    329 GitHub starsUsed in 1 repo~3.1k tokens
    Auto-check passed
  • Clean Data

    Aperivue/medsci-skills

    A skill your agent uses when a clinical CSV/Excel dataset needs profiling and cleaning before analysis (missing values, outliers, duplicates, type mismatches).

    329 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Design Study

    Aperivue/medsci-skills

    A skill your agent uses when checking a radiology or medical AI study design before drafting or submission.

    329 GitHub stars~3.9k tokensUpdated 2 days ago
    Auto-check passed

Questions about Deidentify

What does Deidentify do?

A skill your agent uses when clinical data may contain PHI and must be de-identified before any LLM-assisted analysis. Deidentify is an agent skill from Aperivue/medsci-skills. Use when clinical data may contain PHI and must be de-identified before any LLM-assisted analysis.

When should I use Deidentify?

Deidentify fits situations like: clinical data may contain PHI and must be de-identified before any LLM-assisted analysis.

How do I install Deidentify in Claude Code?

Run `npx skills add Aperivue/medsci-skills --skill deidentify -a claude-code`. Or copy the skill folder (skills/deidentify in Aperivue/medsci-skills) into .claude/skills/deidentify in your project. Claude Code loads it when a task matches its description.

How do I install Deidentify in Codex?

Run `npx skills add Aperivue/medsci-skills --skill deidentify -a codex`. Or copy the skill folder (skills/deidentify in Aperivue/medsci-skills) into .agents/skills/deidentify in your project. Codex loads it when a task matches its description.

Can I use Deidentify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Aperivue/medsci-skills --skill deidentify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deidentify, .gemini/skills/deidentify, .github/skills/deidentify and .opencode/skills/deidentify in your project.

What does Deidentify need to run?

Going by SKILL.md and its folder, Deidentify needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and pip). Our summary lists: Python 3.

Does Deidentify access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Deidentify safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deidentify use?

Deidentify is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deidentify use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.8k tokens, read only when the agent opens those files.

What are the alternatives to Deidentify?

Skills that share tags, products or a category with Deidentify: Topic Model Consolidation (TyrealQ/q-skills, 108 stars), ModelViz Scientific Plots (hrdZhu/modelviz-skill, 286 stars), Excel Spreadsheet Creation and Editing (anthropics/skills, 180k stars) and Excel and CSV Data Analysis (bytedance/deer-flow, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deidentify?

Aperivue (a GitHub organization) maintains it in Aperivue/medsci-skills, which has 329 GitHub stars. The repository holds 54 skills in this directory. The repository was last updated on October 5, 2026.

Source: Aperivue/medsci-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.