FLOW SEO Framework
AgriciDaniel/claude-seo
Brings the FLOW framework's stage-specific SEO prompts into the agent, from keyword discovery through backlinks, on-page work and conversion to local SEO, loaded on demand.
Enterprise risk management (ERM) framework layer — integrates COSO ERM 2017 (five components, 20 principles), ISO 31000, three-lines model, risk appetite, risk heatmap, and key risk indicators (KRI)…
$ npx skills add asgard-ai-platform/skills --skill biz-erm -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install asgard-ai-platform/skills biz-erm --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/asgard-ai-platform/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/biz-erm .claude/skills/biz-erm && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "biz-erm" agent skill from https://github.com/asgard-ai-platform/skills/tree/main/biz-erm into .claude/skills/biz-erm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "biz-erm", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/asgard-ai-platform/skills/tree/main/biz-ermType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add asgard-ai-platform/skills --skill biz-erm -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install asgard-ai-platform/skills biz-erm --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgard-ai-platform/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/biz-erm .agents/skills/biz-erm && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "biz-erm" agent skill from https://github.com/asgard-ai-platform/skills/tree/main/biz-erm into .agents/skills/biz-erm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "biz-erm", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add asgard-ai-platform/skills --skill biz-erm -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install asgard-ai-platform/skills biz-erm --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgard-ai-platform/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/biz-erm .cursor/skills/biz-erm && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "biz-erm" agent skill from https://github.com/asgard-ai-platform/skills/tree/main/biz-erm into .cursor/skills/biz-erm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "biz-erm", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/asgard-ai-platform/skills.git --path biz-erm--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add asgard-ai-platform/skills --skill biz-erm -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install asgard-ai-platform/skills biz-erm --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgard-ai-platform/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/biz-erm .gemini/skills/biz-erm && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "biz-erm" agent skill from https://github.com/asgard-ai-platform/skills/tree/main/biz-erm into .gemini/skills/biz-erm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "biz-erm", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install asgard-ai-platform/skills biz-ermInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add asgard-ai-platform/skills --skill biz-erm -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/asgard-ai-platform/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/biz-erm .github/skills/biz-erm && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "biz-erm" agent skill from https://github.com/asgard-ai-platform/skills/tree/main/biz-erm into .github/skills/biz-erm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "biz-erm", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add asgard-ai-platform/skills --skill biz-erm -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install asgard-ai-platform/skills biz-erm --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgard-ai-platform/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/biz-erm .opencode/skills/biz-erm && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "biz-erm" agent skill from https://github.com/asgard-ai-platform/skills/tree/main/biz-erm into .opencode/skills/biz-erm/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "biz-erm", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
biz-ermEnterprise risk management (ERM) framework layer — integrates COSO ERM 2017 (five components, 20 principles), ISO 31000, three-lines model, risk appetite, risk heatmap, and key risk indicators (KRI)…
Biz Erm is an agent skill from asgard-ai-platform/skills. Enterprise risk management (ERM) framework layer — integrates COSO ERM 2017 (five components, 20 principles), ISO 31000, three-lines model, risk appetite, risk heatmap, and key risk indicators (KRI) into a complete governance playbook covering structure through culture. Use for ERM implementation, risk-system build, risk mapping, risk-appetite statement drafting, three-lines setup, CRO role design, or Taiwan FSC corporate-governance evaluation response. Triggers: 『ERM 導入』『風險管理框架』『COSO』『風險地圖』『風險胃納』『KRI』『CRO…
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `examples/listed-manufacturer-erm.md`, `references/coso-erm-2017.md` and `references/emba-risk-courses.md`).
It sits in Marketing & SEO, covering Conversion rate optimization and Legal risk assessment. The repository describes itself as: 301 open-source coding agent skills across 22 domains — methodology, judgment & gotchas packaged as Claude Agent Skills for the Asgard AI Platform. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4e7f4f8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Biz Erm loads about 2.3k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 193 tokens; SKILL.md has 458 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from asgard-ai-platform/skills at commit 4e7f4f8, republished under its MIT licence (© asgard-ai-platform). 458 words, ~2,307 tokens.
.claude/skills/biz-erm/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.為什麼 EMBA 要學 ERM 框架
台灣企業風險管理常見兩種極端:
本 skill 拉回「框架+治理」層,整合 COSO ERM 2017 與 ISO 31000,讓學員能:
與相近 Asgard skill 的邊界
algo-risk-altman-z — 財務危機預測(單一量化工具)algo-risk-benford — 舞弊偵測數學algo-risk-credit — 信用風險評分algo-risk-var — 市場風險 VaRgrad-governance — 公司治理學理觸發條件
不適用
algo-risk-*pr-crisis-communication、pr-crisis-responsebiz-net-zero-transition、Asgard grad-sustainabilitylaw-contract、law-gdpr-pdpaIRON LAW 1:ERM 不是風險清單,是決策品質
ERM 的終極目的不是列出 500 條風險 tracking,
而是讓每個重大決策都「在可承受範圍內追求適當報酬」。
沒連結到策略與決策的 ERM = 高級稽核,不是 ERM。IRON LAW 2:風險胃納(Risk Appetite)是董事會的事
「公司願意承擔多少風險以追求報酬」必須由董事會定義。
管理層只能在胃納範圍內決策。
沒有明文胃納書的 ERM = 盲人開車,風險文化無從建立。IRON LAW 3:三道防線各司其職、互不取代
第一道(業務單位)擁有並管理風險;
第二道(風險/合規)監督方法、協調政策;
第三道(內部稽核)獨立驗證前兩道有效性。
最常見的失敗:第二道取代第一道(風險部變成風險保母)
或 第三道與第二道合署(失去獨立性)。| 可能想 | 但 Iron Law 仍適用,因為 |
|---|---|
| 「列出 50 條風險熱圖就算 ERM 上線」 | 熱圖只是中間產物;必須連回策略與重大決策,否則只是「高級稽核」 |
| 「管理層可以先訂一版風險胃納,董事會日後追認」 | 胃納書是董事會責任不可下放;必須標註「未經董事會通過 = 無治理效力」 |
| 「小公司讓風管部兼任內稽以節省人力」 | 第二道取代第三道 = 失去獨立性;即使人力合一,彙報線必須分離(內稽向審計委員會) |
COSO 2017 版將 ERM 與策略、績效深度整合。五大要素:
┌─────────────────────────────────────────────┐
│ 要素 5:資訊、溝通與報告 │
│ Risk Information Governance │
├─────────────────────────────────────────────┤
│ 要素 4:檢視與修訂 │
│ Review and Revision │
├─────────────────────────────────────────────┤
│ 要素 3:績效(核心) │
│ Performance — 風險辨識、評估、選擇回應 │
├─────────────────────────────────────────────┤
│ 要素 2:策略與目標設定 │
│ Strategy & Objective-Setting │
├─────────────────────────────────────────────┤
│ 要素 1:治理與文化 │
│ Governance & Culture │
└─────────────────────────────────────────────┘要素 1:治理與文化(原則 1–5)
要素 2:策略與目標設定(原則 6–9) 6. 分析業務背景 7. 定義風險胃納 8. 評估替代策略 9. 形成業務目標
要素 3:績效(原則 10–14) 10. 辨識風險 11. 評估風險嚴重度 12. 排序風險優先序 13. 制定風險回應 14. 發展組合觀點
要素 4:檢視與修訂(原則 15–17) 15. 評估重大變動 16. 檢視風險與績效 17. 持續改進 ERM
要素 5:資訊、溝通與報告(原則 18–20) 18. 善用資訊與技術 19. 溝通風險資訊 20. 向利害關係人報告
┌───────────────────────────────────────────────┐
│ 治理機構(董事會 / 審計委員會 / 風險委員會) │
│ 監督、課責、最終風險責任 │
└───────────────────────────────────────────────┘
↑ 報告 ↑ 報告 ↑ 報告
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ 第一道防線 │ │ 第二道防線 │ │ 第三道防線 │
│ 業務/營運 │ │ 風險/合規 │ │ 內部稽核 │
│ │ │ 財務控管 │ │ │
│ 擁有與管理 │ │ 提供方法論 │ │ 獨立驗證 │
│ 日常風險 │ │ 監督與挑戰 │ │ 有效性 │
└──────────────┘ └──────────────┘ └──────────────┘2020 年新版變化
台灣實務常見失衡
Risk Appetite 風險胃納(策略層)
↓ 具體化
Risk Tolerance 風險容忍度(績效層)
↓ 量化
Risk Limits 風險限額(營運層)範例(製造業)
| 類別 | 子項 |
|---|---|
| 策略風險 | 競爭、併購、創新、商業模式 |
| 營運風險 | 供應鏈、品質、資安、人員、流程 |
| 財務風險 | 流動性、匯率、利率、信用、稅務 |
| 合規風險 | 法規變動、反壟斷、勞動、個資 |
| 聲譽/ESG 風險 | 品牌、媒體、氣候、社會議題 |
兩軸:發生可能性(Likelihood)× 衝擊(Impact)
衝擊 ↑
│ 黃 │ 橙 │ 紅 │ 紅 │
│ 黃 │ 橙 │ 橙 │ 紅 │
│ 綠 │ 黃 │ 橙 │ 橙 │
│ 綠 │ 綠 │ 黃 │ 黃 │
│ 綠 │ 綠 │ 綠 │ 黃 │
└───────────────────→ 可能性五級制常用尺度
選擇邏輯
| KPI | KRI |
|---|---|
| 衡量過去績效 | 預警未來風險 |
| 落後指標為主 | 領先指標為主 |
| 成功衡量 | 偏離警訊 |
| 部門層 | 跨部門整合 |
範例(供應鏈風險 KRI)
| 指標 | 綠 | 黃 | 紅 | 回應 |
|---|---|---|---|---|
| 單一供應商依賴 | < 25% | 25–40% | > 40% | 啟動多元化計畫 |
| 庫存天數 | 45–60 | 30–45 | < 30 | 緊急採購 |
| 交貨準時率 | > 98% | 95–98% | < 95% | 供應商稽核 |
風險透明度
↑
高透明度 │ 高透明度
低當責 │ 高當責
─────────────┼──────────→ 風險當責度
低透明度 │ 低透明度
低當責 │ 高當責
↓健康狀態:高透明度 + 高當責
常見病態
根據個案性質跳過不適用步驟;以下為完整候選路徑,非必跑清單。
Step 1:現況盤點(1–2 個月)
- 治理結構(委員會、CRO)
- 現有風險管理活動
- 三道防線清點
- 已知重大風險
Step 2:風險胃納設計(2–3 個月)
- 董事會工作坊
- 策略對齊
- 量化 KRI 門檻
- 胃納書正式通過
Step 3:風險辨識與熱圖(3–6 個月)
- 跨部門工作坊
- 風險分類與評估
- 熱圖繪製
- 前 10–15 條主要風險優先處理
Step 4:風險回應與 KRI(6–9 個月)
- 每條主要風險的 ARTA 選擇
- KRI 設計與監測機制
- 報告模板
Step 5:整合與治理(9–12 個月)
- 納入策略規劃流程
- 納入績效考核
- 董事會定期檢視節奏
- 文化活動(訓練、溝通)
Step 6:持續改進(12 個月以後)
- 年度胃納書檢視
- 季度風險報告
- 三道防線協作會議
- ERM 成熟度評估(每 2–3 年)# ERM 診斷與導入建議:{公司名稱/個案}
## 一、現況盤點
- 治理結構(董事會、委員會、CRO)
- 三道防線現況
- 已知重大風險
- 與 COSO 2017 原則對照
## 二、核心缺口診斷
- 治理層缺口
- 胃納層缺口
- 流程層缺口
- 文化層缺口
## 三、風險胃納建議
- 策略胃納
- 財務胃納
- 營運胃納
- 合規/聲譽胃納
- 關鍵量化門檻
## 四、風險熱圖
- 辨識前 10–15 條主要風險
- 分類、評估、熱圖定位
- 風險回應選擇
## 五、KRI 架構
- 依分類設計 15–25 個 KRI
- 門檻、資料源、回應機制
- 自動化與儀表板
## 六、三道防線重建
- 各道責任與權限
- 協作機制
- 獨立性保障
## 七、文化與組織
- CRO 角色與彙報線
- 風險委員會組成
- 訓練與溝通
## 八、路線圖(12–18 個月)
## 九、風險與限制
- 資源配置限制
- 文化阻力
- 法遵框架變動情境:某上市電子製造業(營收 120 億、員工 1,200 人),金管會公司治理評鑑連續兩年未達 20%,新任獨董要求全面整頓風險管理體系。
診斷:
建議:
algo-risk-altman-z 做財務危機量化警示正確之處:六大框架覆蓋、時程合理、量化工具與治理框架整合。
references/coso-erm-2017.mdreferences/three-lines-model.mdreferences/risk-appetite-template.mdreferences/tw-governance-regulation.mdreferences/emba-risk-courses.mdalgo-risk-altman-z、algo-risk-benford、algo-risk-credit、algo-risk-var、grad-governance、本 repo biz-corporate-governance、biz-net-zero-transition© asgard-ai-platform, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in biz-erm of asgard-ai-platform/skills.
Open the folder on GitHubat commit 4e7f4f8
Biz Erm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Biz Erm this skillasgard-ai-platform/skills | 242 | — | ~2.3k | Automated safety check: Pass | MIT | |
| FLOW SEO FrameworkAgriciDaniel/claude-seo | 19k | 2 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Paywallscoreyhaines31/marketingskills | 54k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Onboarding Crofreekmurze/dotfiles | 1k | 16 repos | ~1.6k | Automated safety check: Pass | None | |
| Paywall Upgrade Crofreekmurze/dotfiles | 1k | 15 repos | ~1.4k | Automated safety check: Pass | None | |
| Revenue Centric Designheliocosta-dev/revenue-centric-design | 740 | — | ~1.6k | Automated safety check: Pass | Custom licence |
AgriciDaniel/claude-seo
Brings the FLOW framework's stage-specific SEO prompts into the agent, from keyword discovery through backlinks, on-page work and conversion to local SEO, loaded on demand.
coreyhaines31/marketingskills
When the user wants to create or optimize in-app paywalls, upgrade screens, upsell modals, or feature gates.
freekmurze/dotfiles
When the user wants to optimize post-signup onboarding, user activation, first-run experience, or time-to-value.
freekmurze/dotfiles
When the user wants to create or optimize in-app paywalls, upgrade screens, upsell modals, or feature gates.
heliocosta-dev/revenue-centric-design
Playbook for designing SaaS and startup products that convert, retain, and monetize — landing pages & CRO, checkout & forms, onboarding/activation, churn reduction, pricing psychology, dashboards…
thatrebeccarae/claude-marketing
Analyze Google Analytics data, review website performance metrics, identify traffic patterns, and suggest data-driven improvements.
asgard-ai-platform/skills
Implement BM25 ranking function for e-commerce product search relevance scoring.
asgard-ai-platform/skills
Calculate Cpk process capability index to assess whether a process meets specification requirements.
asgard-ai-platform/skills
Calculate price elasticity of demand to quantify how price changes affect sales volume.
asgard-ai-platform/skills
Apply Bayesian averaging to rank items by combining observed ratings with prior expectations.
asgard-ai-platform/skills
Implement Elo rating system to rank items or players from pairwise comparison outcomes.
asgard-ai-platform/skills
Calculate Wilson Score confidence intervals for ranking items by positive proportion with sample size correction.
Categories
Enterprise risk management (ERM) framework layer — integrates COSO ERM 2017 (five components, 20 principles), ISO 31000, three-lines model, risk appetite, risk heatmap, and key risk indicators (KRI)…. Biz Erm is an agent skill from asgard-ai-platform/skills. Enterprise risk management (ERM) framework layer — integrates COSO ERM 2017 (five components, 20 principles), ISO 31000, three-lines model, risk appetite, risk heatmap, and key risk indicators (KRI) into a complete governance playbook covering structure through culture.
Biz Erm fits situations like: ERM implementation; risk-system build; risk-appetite statement drafting; three-lines setup.
Run `npx skills add asgard-ai-platform/skills --skill biz-erm -a claude-code`. Or copy the skill folder (biz-erm in asgard-ai-platform/skills) into .claude/skills/biz-erm in your project. Claude Code loads it when a task matches its description.
Run `npx skills add asgard-ai-platform/skills --skill biz-erm -a codex`. Or copy the skill folder (biz-erm in asgard-ai-platform/skills) into .agents/skills/biz-erm in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add asgard-ai-platform/skills --skill biz-erm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/biz-erm, .gemini/skills/biz-erm, .github/skills/biz-erm and .opencode/skills/biz-erm in your project.
SKILL.md names no scripts, command-line tools or credentials: Biz Erm is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Biz Erm is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Biz Erm: FLOW SEO Framework (AgriciDaniel/claude-seo, 19k stars), Paywalls (coreyhaines31/marketingskills, 54k stars), Onboarding Cro (freekmurze/dotfiles, 1k stars) and Paywall Upgrade Cro (freekmurze/dotfiles, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
asgard-ai-platform (a GitHub organization) maintains it in asgard-ai-platform/skills, which has 242 GitHub stars. The repository holds 207 skills in this directory. The repository was last updated on June 6, 2026.
Source: asgard-ai-platform/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.