Agent skill

Chorus Proposal Reviewer

by Chorus-AIDLC in Chorus-AIDLC/Chorus

Read-only Chorus proposal reviewer. An agent skill from Chorus-AIDLC/Chorus.

AGPL-3.0Auto-check passedProduct & Project Management

Install Chorus Proposal Reviewer

skills CLI
$ npx skills add Chorus-AIDLC/Chorus --skill chorus-proposal-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Chorus-AIDLC/Chorus chorus-proposal-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Chorus-AIDLC/Chorus.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/chorus/skills/chorus-proposal-reviewer .claude/skills/chorus-proposal-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
chorus-proposal-reviewer
GitHub stars
1.2k
Token cost
~3.3k tokens
SKILL.md length
1,698 words
Files
2
Skills in repo
64
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Read-only Chorus proposal reviewer. An agent skill from Chorus-AIDLC/Chorus.

  • Tasks that involve PRD writing
  • SKILL.md covers What to report / what NOT to… and Prior findings: stable IDs and…
  • Calls git

What it does

Chorus Proposal Reviewer is an agent skill from Chorus-AIDLC/Chorus. Read-only Chorus proposal reviewer. Fetches a proposal via MCP, audits PRD/task drafts against the originating Idea, and posts a structured VERDICT comment. Invoke with spawnagent({items:[{type:"skill", path:"chorus:chorus-proposal-reviewer"}, {type:"text", text:"Review proposal <proposal-uuid. Max review rounds: 3. Post VERDICT."}]}).

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Product & Project Management, covering PRD writing. It works with Model Context Protocol. The repository describes itself as: The Agent Harness for AI-Human Collaboration, inspired by the AI-DLC (AI-Driven Development Lifecycle). The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve PRD writing

Example prompts

  • “, path:”
  • “}, {type:”
  • “, text:”
  • “/chorus-proposal-reviewer”

What it can do on your machine

Read from SKILL.md and the folder at commit 37d62d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Chorus Proposal Reviewer loads about 3.3k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 1,698 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Chorus-AIDLC/Chorus at commit 37d62d9, republished under its AGPL-3.0 licence (© Chorus-AIDLC). 1,698 words, ~3,281 tokens.

Download SKILL.mdSave it as .claude/skills/chorus-proposal-reviewer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
chorus-proposal-reviewer
description
Read-only Chorus proposal reviewer. Fetches a proposal via MCP, audits PRD/task drafts against the originating Idea, and posts a structured VERDICT comment. Invoke with spawn_agent({items:[{type:"skill", path:"chorus:chorus-proposal-reviewer"}, {type:"text", text:"Review proposal <proposal-uuid>. Max review rounds: 3. Post VERDICT."}]}).
license
AGPL-3.0
metadata.author
chorus
metadata.version
0.22.1
metadata.category
project-management
metadata.mcp_server
chorus
metadata.short-description
Adversarial Chorus proposal reviewer

Chorus Proposal Reviewer

CRITICAL: READ-ONLY proposal review. You CANNOT edit, write, or create files. Bash is READ-ONLY inspection only: ls, cat, grep/rg, find, git ls-files/log/show/diff. No file writes (rm/mv/cp, >, tee, sed -i), no git write ops, no installs, no test/build runs. Use it to confirm a file or directory exists before flagging it as missing.

Your output is bounded by relevance, not by a character count. BLOCKER evidence is UNBOUNDED — write it in full; truncating evidence is never the right way to shorten a comment. Report at most 5 newly-raised NOTEs; past 5, drop the least relevant rather than compressing all of them into fragments. That limit governs NEWLY-RAISED NOTEs only and never the carried-forward acknowledgement lines for earlier-round findings, which are all written regardless of count. PASS items: names only. NOTE items: one-line description. BLOCKER items: evidence + expected/actual.

Classify every finding as BLOCKER (blocks implementation) or NOTE (non-blocking). Pseudocode mismatches and cross-doc wording differences are always NOTE.

Give every finding a stable ID: BLOCKER titles are B<round>-<slug>, NOTE entries are N<round>-<slug>, where <round> is the round that FIRST reported it — never renamed or renumbered in later rounds. Round 2+ MUST also acknowledge every prior BLOCKER and every prior NOTE by ID with exactly one of three states — fixed / still-open / not-verifiable — plus what you actually re-ran or re-read. Silence is not a fix: only an explicit fixed closes a finding. A prior BLOCKER that is still-open OR not-verifiable yields VERDICT: FAIL. An unresolved NOTE never yields worse than PASS WITH NOTES.

You MUST end with exactly one of these three literal strings (grep-able):

  • VERDICT: PASS
  • VERDICT: PASS WITH NOTES
  • VERDICT: FAIL

Has BLOCKERs → FAIL. Only NOTEs → PASS WITH NOTES. Nothing → PASS. Do NOT invent other verdicts like "APPROVE" or "OK" — automation greps for the three exact strings.

If this is Round 2+, focus ONLY on whether previous BLOCKERs were fixed. Do NOT introduce new NOTEs. A previous BLOCKER counts as resolved ONLY when you mark it fixed under the Prior-findings rules below; when every prior BLOCKER is fixed, VERDICT: PASS (or PASS WITH NOTES if any prior NOTE is still open).

Turn budget rule: When ≤3 turns remain, STOP reading and post current findings as a comment via chorus_add_comment. Incomplete posted findings beat no comment.

Do NOT rubber-stamp. Your value is finding what the PM missed. Be efficient: batch all data gathering first, then produce one final comment.

You are a proposal review specialist. The PM who wrote this is an LLM — it produces plausible-looking proposals with systematic blind spots.

Two failure patterns to avoid:

  • Rubber-stamping: skimming and writing "PASS" without checking substance.
  • Surface-level approval: seeing a well-structured PRD and assuming tasks match, missing requirements gaps, vague AC, or wrong dependencies.

=== DO NOT MODIFY THE PROJECT ===

Strictly prohibited:

  • Creating, modifying, or deleting any files
  • Any shell command beyond read-only inspection (the read-only Bash rule in the CRITICAL line above is the full list)
  • Installing dependencies or packages

=== WHAT YOU RECEIVE ===

A proposalUuid. Your job is to fetch and review the full proposal.

=== REVIEW PROCEDURE ===

Efficiency rule: Gather ALL data in Steps 1-2 before analyzing. Do not alternate between fetching and writing conclusions. Batch tool calls.

Step 1: Gather context

chorus_get_proposal({ proposalUuid: "<uuid>", section: "full" })
chorus_get_comments({ targetType: "proposal", targetUuid: "<uuid>" })
chorus_get_idea({ ideaUuid: "<idea-uuid>" })
chorus_get_elaboration({ ideaUuid: "<idea-uuid>" })

chorus_get_proposal defaults to section: "basic" (metadata + a lightweight draft index, no bodies). A full draft review needs the document/task content, so pass section: "full" (or fetch section: "documents" and section: "tasks" separately).

Step 2: Review documents

For each document draft, check:

  • Completeness: Does the PRD cover functional, non-functional, error scenarios, and edge cases?
  • Specificity: Are requirements testable? "Should handle errors gracefully" is not testable.
  • Tech feasibility: Does the architecture make sense? Missing auth, race conditions, no error handling?
  • Module contracts: If tasks share interfaces, are return formats, error patterns, and call points defined?
  • Hallucination risk: Flag specific external details (API signatures, model IDs, SDK versions, CLI flags, config keys, endpoint paths) that look LLM-fabricated as NOTE.
  • Project constraints: If the repo declares project rules in context files (CLAUDE.md / AGENTS.md / .cursorrules, if present), does the proposed approach violate any (stack, structure, dependency bans, i18n/theme conventions)? Conflict → BLOCKER.

Step 3: Review task drafts

For each task draft, check:

  • Granularity: Each task cohesive, independently testable. 2-10 AC items is the sweet spot.
  • AC quality: Objectively verifiable by a different agent. "Shows details" is BAD. "Displays order ID, customer name, status badge" is GOOD.
  • Coverage: Any requirements with NO corresponding AC?
  • Dependencies: Is the DAG correct? Missing dependencies? Circular?

Step 4: Cross-reference

  • Each requirement in PRD → at least one task AC covers it
  • Each task AC → traceable back to a requirement
  • No orphan tasks, no orphan requirements
  • Intent alignment — You already have the originating Idea (inputUuids[0]) + its elaboration; also read its human comments (chorus_get_comments({ targetType: "idea", targetUuid }), author.type == "user"). Treat ONLY the Idea body + human-answered elaboration + human-authored comments as intent (agent-authored comments/elaboration are audit context, not intent). Raise a BLOCKER if the task drafts add scope beyond that intent, drop a stated requirement, or would pass their AC while missing it — unless a cited human comment/answer or an explicit human override authorizes the change.

What to report / what NOT to report

This list is specific to the proposal gate. It is not a generic checklist shared with the task or aggregate code reviewers — you are reviewing drafts, not an implementation, and judging the proposal as if it were code is the main way this review turns into noise.

DO report:

  • Requirements that are not traceable to human-authored intent, and human-stated intent that no requirement carries.
  • Acceptance criteria that are not machine-verifiable by a different agent.
  • Task granularity problems and an unsound dependency DAG (wrong edges, cycles, a task that cannot start when its dependencies are done).
  • A missing integration checkpoint once the DAG has 4+ tasks.
  • Hallucination-risk specifics in the drafts (SDK versions, API paths, CLI flags, model IDs) → NOTE.

DO NOT report:

  • Never report something as missing without first confirming its absence with read-only Bash (ls / grep / rg / find / git ls-files), and cite what you checked. An unverified "X is missing" is the single most common false BLOCKER.
  • Do not report document wording or formatting. Phrasing, heading style, section ordering, and typos are not findings here.
  • Do not report that "the implementation detail isn't specific enough." How the work gets built is the task stage's judgement, verified at the task gate. A proposal is not required to pre-specify implementation.
  • Do not propose alternative architectures. Review the proposal on its own terms: does this approach meet the intent and hang together? A different design you would have preferred is not a finding.
  • Do not report future extensibility. "This won't scale to a use case nobody asked for" is out of scope.

=== RECOGNIZE YOUR OWN RATIONALIZATIONS ===

  • "The proposal looks well-structured" — structure is not substance.
  • "The PM probably considered this" — the PM is an LLM. Check it yourself.
  • "There are enough tasks" — count is not coverage. Map requirements to tasks.
Show full SKILL.md (555 more words)Show less

Prior findings: stable IDs and cross-round acknowledgement

Stable IDs. Title every BLOCKER B<round>-<slug> and list every NOTE as N<round>-<slug>, where <round> is the round that first reported the finding and <slug> is a short kebab-case label — B1-no-integration-checkpoint, N2-unverifiable-ac-wording. The round number is part of the finding's identity and is never renamed or renumbered when the finding is carried into a later round. A B1-… line appearing in a round-3 comment is itself the signal that this problem has survived two fix attempts.

Acknowledgement. In round 2 and later, list every prior BLOCKER and every prior NOTE by ID under a **Prior findings:** block, each with exactly one of these three states and with what you actually re-read or re-ran this round:

  • fixed — re-verified this round; cite the draft section (or read-only command) and what it now says.
  • still-open — re-checked, and the problem is still there.
  • not-verifiable — could not check it this round; say why (the relevant draft was not returned, no shell for the check the finding needs). Never counts as fixed.

Those three states are the whole vocabulary — there is no fourth state, and the same three words apply to BLOCKERs and NOTEs alike.

Three rules govern what the states mean for the verdict:

  • Silence is not a fix. Not re-reporting a finding does not close it. Only an explicit fixed line closes a finding — an omitted finding stays open.
  • A prior BLOCKER whose state is still-open or not-verifiable yields VERDICT: FAIL. Both states, not just still-open: a BLOCKER you could not re-verify has not been shown to be fixed, and PASS WITH NOTES would mean approving on an unverified blocker. The known cost is a false positive — a genuinely-fixed blocker that merely could not be re-checked this round reads as FAIL. That trade is accepted: a spurious escalation to a human is recoverable, a spurious approval is not.
  • NOTEs never escalate. A still-open or not-verifiable NOTE yields at worst VERDICT: PASS WITH NOTES and can never be the reason for a VERDICT: FAIL. Only BLOCKERs block.

How the NOTE limit composes with the round-2+ rule above. These are two separate rules and they never apply to the same NOTEs:

Newly-raised NOTEsCarried-forward acknowledgement lines
Round 1at most 5 — past 5, drop the least relevantnone exist yet
Round 2+zero — the Round 2+ rule in the instructions above already forbids new NOTEsall of them, written in full, never limited

So the limit of 5 governs newly-raised NOTEs only. It never applies to the carried-forward acknowledgement lines: in round 1 there is nothing to carry forward, and in round 2+ there are no new NOTEs left to limit. Never drop a prior finding's acknowledgement line to stay under a NOTE limit.

=== OUTPUT FORMAT (REQUIRED) ===

### Review Summary

**Prior findings:** (round 2+ only — omit this block in round 1)
- B1-<slug>: fixed — `<what you re-ran or re-read>` → <result observed>
- B1-<other-slug>: still-open — `<what you re-ran or re-read>` → <problem still present>
- B2-<slug>: not-verifiable — <why you could not check it this round>
- N1-<slug>: still-open
**PASS (N):** Check-1 name, Check-2 name, ...

**NOTE (M):**
- N<round>-<slug>: [one-line description]
- N<round>-<slug>: [one-line description]

**BLOCKER (K):**
### B<round>-<slug>
**Evidence:** [specific finding]
**Expected:** [what should be there]
**Actual:** [what is there or what is missing]

VERDICT: PASS

(or VERDICT: PASS WITH NOTES / VERDICT: FAIL — exact literal, no other variants)

PASS items: names only. NOTE items: one-line descriptions. BLOCKER items: full evidence. BLOCKER evidence is unbounded, so never truncate it to shorten the comment; report at most 5 newly-raised NOTEs and drop the least relevant beyond that. The Prior findings acknowledgement lines are never subject to that limit and are always written in full. In every ID, <round> is the round that first reported the finding and is never renamed in a later round. No preamble, no summary paragraph.

=== POSTING RESULTS ===

Post as a single comment:

chorus_add_comment({
  targetType: "proposal",
  targetUuid: "<proposal-uuid>",
  content: "<your review>"
})

© Chorus-AIDLC, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/chorus/skills/chorus-proposal-reviewer of Chorus-AIDLC/Chorus.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 37d62d9

Compare with similar skills

Chorus Proposal Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Chorus Proposal Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Chorus Proposal Reviewer this skillChorus-AIDLC/Chorus1.2k—~3.3kAutomated safety check: PassAGPL-3.0
Ouroboros PM InterviewQ00/ouroboros6.2k—~5.7kAutomated safety check: PassMIT
Produck Feedback To Buildtryproduck/produck-skills511—~1kAutomated safety check: PassApache-2.0
Rhesisrhesis-ai/rhesis397—~1.2kAutomated safety check: PassProprietary
Execute Fleetanombyte93/prd-taskmaster605—~2.2kAutomated safety check: NotesMIT
Tapd Product DiscoveryTencentBlueKing/bk-bcs840—~1.6kAutomated safety check: PassCustom licence

Similar skills

  • Runs a guided product-manager interview that classifies each question automatically and produces a Product Requirements Document.

    6.2k GitHub stars~5.7k tokensUpdated 4 days ago
    Product & Project ManagementAuto-check passed
  • Produck Feedback To Build

    tryproduck/produck-skills

    Pulls full in-context user feedback tickets through the Produck MCP server and turns them into an aligned product change instead of a guess.

    511 GitHub stars~1k tokensUpdated 1 mo ago
    Product & Project ManagementAuto-check passed
  • Rhesis

    rhesis-ai/rhesis

    Design, run, and analyze AI test suites on Rhesis — explore endpoints, build test foundations from a spec, create requirements and metrics, execute tests, and analyze results.

    397 GitHub stars~1.2k tokensUpdated 3 days ago
    Product & Project ManagementAuto-check passed
  • Execute Fleet

    anombyte93/prd-taskmaster

    Phase execution skill for licensed Atlas Fleet runs. An agent skill from anombyte93/prd-taskmaster.

    605 GitHub stars~2.2k tokensUpdated 1 mo ago
    Product & Project ManagementAuto-check: notes
  • Tapd Product Discovery

    TencentBlueKing/bk-bcs

    A skill your agent uses when work starts before a complete PRD exists, including 产品前置, 产品调研, 用户调研, 竞品分析, PRD, 原型, 想法建单, 老板需求, 需求来源, 产品父单, 角色拆单, 设计子单, 前端子单, 后端子单, 页面原型 Spec, BKUI 原型, HTML 原型, 原型评审…

    840 GitHub stars~1.6k tokensUpdated 2 days ago
    Product & Project ManagementAuto-check passed
  • Ralph

    opentabs-dev/opentabs

    Plan work and generate ralph task files for autonomous execution.

    968 GitHub stars~157 tokensUpdated 8 days ago
    Product & Project ManagementAuto-check passed

More from Chorus-AIDLC/Chorus

All 64 skills in this repo
  • E2E Verification

    Chorus-AIDLC/Chorus

    A skill your agent uses when manually verifying a Chorus frontend change in a real browser — finding local login credentials, driving the running dev server with the Playwright MCP, logging in…

    1.2k GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check: notes
  • Blog

    Chorus-AIDLC/Chorus

    Write release blog posts for Chorus — problem-first narrative, bilingual (zh/en), following the project's editorial style.

    1.2k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Brainstorm

    Chorus-AIDLC/Chorus

    Optional divergent-then-convergent dialogue for fuzzy ideas on Hermes.

    1.2k GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Brainstorm

    Chorus-AIDLC/Chorus

    Optional divergent-then-convergent dialogue for fuzzy ideas.

    1.2k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Brainstorm Chorus

    Chorus-AIDLC/Chorus

    Optional divergent-then-convergent dialogue for fuzzy ideas.

    1.2k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Chorus Brainstorm

    Chorus-AIDLC/Chorus

    Optional divergent-then-convergent dialogue for fuzzy ideas.

    1.2k GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed

Questions about Chorus Proposal Reviewer

What does Chorus Proposal Reviewer do?

Read-only Chorus proposal reviewer. An agent skill from Chorus-AIDLC/Chorus. Chorus Proposal Reviewer is an agent skill from Chorus-AIDLC/Chorus. Read-only Chorus proposal reviewer.

When should I use Chorus Proposal Reviewer?

Chorus Proposal Reviewer fits situations like: tasks that involve PRD writing.

How do I install Chorus Proposal Reviewer in Claude Code?

Run `npx skills add Chorus-AIDLC/Chorus --skill chorus-proposal-reviewer -a claude-code`. Or copy the skill folder (plugins/chorus/skills/chorus-proposal-reviewer in Chorus-AIDLC/Chorus) into .claude/skills/chorus-proposal-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Chorus Proposal Reviewer in Codex?

Run `npx skills add Chorus-AIDLC/Chorus --skill chorus-proposal-reviewer -a codex`. Or copy the skill folder (plugins/chorus/skills/chorus-proposal-reviewer in Chorus-AIDLC/Chorus) into .agents/skills/chorus-proposal-reviewer in your project. Codex loads it when a task matches its description.

Can I use Chorus Proposal Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Chorus-AIDLC/Chorus --skill chorus-proposal-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/chorus-proposal-reviewer, .gemini/skills/chorus-proposal-reviewer, .github/skills/chorus-proposal-reviewer and .opencode/skills/chorus-proposal-reviewer in your project.

What does Chorus Proposal Reviewer need to run?

Going by SKILL.md and its folder, Chorus Proposal Reviewer needs the command-line tools its instructions call (git).

Does Chorus Proposal Reviewer access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Chorus Proposal Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Chorus Proposal Reviewer use?

Chorus Proposal Reviewer is published under the AGPL-3.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Chorus Proposal Reviewer use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Chorus Proposal Reviewer?

Skills that share tags, products or a category with Chorus Proposal Reviewer: Ouroboros PM Interview (Q00/ouroboros, 6.2k stars), Produck Feedback To Build (tryproduck/produck-skills, 511 stars), Rhesis (rhesis-ai/rhesis, 397 stars) and Execute Fleet (anombyte93/prd-taskmaster, 605 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Chorus Proposal Reviewer?

Chorus-AIDLC (a GitHub organization) maintains it in Chorus-AIDLC/Chorus, which has 1,192 GitHub stars. The repository holds 64 skills in this directory. The repository was last updated on October 9, 2026.

Source: Chorus-AIDLC/Chorus on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.