Code Graph Mermaid Diagrams
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
Search for packages and assess security risk before adding as dependencies
$ npx skills add davepoon/buildwithclaude --skill package-search -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install davepoon/buildwithclaude package-search --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vulnetix/skills/package-search .claude/skills/package-search && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "package-search" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/package-search into .claude/skills/package-search/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-search", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/package-searchType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add davepoon/buildwithclaude --skill package-search -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install davepoon/buildwithclaude package-search --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/vulnetix/skills/package-search .agents/skills/package-search && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "package-search" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/package-search into .agents/skills/package-search/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-search", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davepoon/buildwithclaude --skill package-search -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install davepoon/buildwithclaude package-search --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/vulnetix/skills/package-search .cursor/skills/package-search && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "package-search" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/package-search into .cursor/skills/package-search/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-search", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/davepoon/buildwithclaude.git --path plugins/vulnetix/skills/package-search--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add davepoon/buildwithclaude --skill package-search -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install davepoon/buildwithclaude package-search --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/vulnetix/skills/package-search .gemini/skills/package-search && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "package-search" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/package-search into .gemini/skills/package-search/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-search", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install davepoon/buildwithclaude package-searchInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add davepoon/buildwithclaude --skill package-search -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/vulnetix/skills/package-search .github/skills/package-search && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "package-search" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/package-search into .github/skills/package-search/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-search", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davepoon/buildwithclaude --skill package-search -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install davepoon/buildwithclaude package-search --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davepoon/buildwithclaude.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/vulnetix/skills/package-search .opencode/skills/package-search && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "package-search" agent skill from https://github.com/davepoon/buildwithclaude/tree/main/plugins/vulnetix/skills/package-search into .opencode/skills/package-search/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "package-search", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
package-searchSearch for packages and assess security risk before adding as dependencies
Package Search is an agent skill from davepoon/buildwithclaude. Search for packages and assess security risk before adding as dependencies
Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with Python and Mermaid. The repository describes itself as: A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 616deb5. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadGlobGrepEditWriteFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghpipgouvcargopython3pythongemcomposernpmFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Package Search loads about 4.3k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 1,968 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Glob, Grep, Edit, WriteAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from davepoon/buildwithclaude at commit 616deb5, republished under its MIT licence (© davepoon). 1,968 words, ~4,276 tokens.
.claude/skills/package-search/SKILL.md (or your agent's skills folder).This skill searches for packages across ecosystems and provides a comprehensive security risk assessment before adding them as dependencies.
Primary output format: Markdown. All reports, tables, summaries, and diffs MUST be presented as formatted markdown text directly — never generate scripts or programs to produce output that can be expressed as markdown.
Visual data — use Mermaid diagrams to display data visually when it aids comprehension. Mermaid renders natively in markdown and requires no external tools. Use it for:
graph TD or graph LRtimelinepie or quadrantChartflowchartExample — vulnerability distribution for a package:
```mermaid
pie title Vulnerability Severity
"Critical" : 1
"High" : 2
"Medium" : 5
"Low" : 3
```If uv is available, richer visualizations can be generated with Python (matplotlib, plotly) and saved to .vulnetix/:
command -v uv &>/dev/null && uv run --with matplotlib python3 -c '
import matplotlib.pyplot as plt
# ... generate chart ...
plt.savefig(".vulnetix/chart.png", dpi=150, bbox_inches="tight")
'When Python charts are generated, display them inline and keep the Mermaid version as a text fallback.
Data processing — tooling cascade (strict order):
jq for JSON, yq for YAML. Pipe to head, tail, cut, sed, grep, sort, uniq, wc for shaping.uv first:command -v uv &>/dev/null && uv run --with pandas,matplotlib python3 -c '...'uv is unavailable. Use json, csv, collections, statistics modules — no pip dependencies:command -v python3 &>/dev/null && python3 -c 'import json, sys; ...'Never assume any runtime is available — always check with command -v before use. If all programmatic tools are unavailable, analyze manually with the Read tool and present results as markdown with Mermaid diagrams.
Version detection commands (pip show, go list -m, cargo pkgid, etc.) are exempt — they query package managers directly and are tried as-available per the version detection priority in Step 1b.
This skill reads the .vulnetix/memory.yaml file in the repository root to surface prior vulnerability history for packages being searched. This file is shared with /vulnetix:fix and /vulnetix:exploits.
At the start of every invocation:
.vulnetix/memory.yaml exists in the repo root.vulnetix/scans/*.cdx.json — if CycloneDX SBOMs exist from prior scans (pre-commit hook or fix skill), cross-reference package names against SBOM component lists for additional vulnerability contextDuring risk assessment (Step 4):
CVE-2021-44228 — Fixed (2024-01-15), CVE-2023-1234 — Risk accepted (2024-03-01), P3 (52.0)pocs exist for a vuln, note: N PoC(s) on file — do not display PoC URLs or paths in package search outputaffected or under_investigation), flag this prominently in the risk assessment. If CWSS priority is P1 or P2, add a warning: "Active exploit intelligence available — run /vulnetix:exploits <vuln-id> for details"After completing the search:
vulnerabilityCount or maxSeverity in the API response) that are NOT already tracked in the memory file, record them as new entries with:status: under_investigationdiscovery.source: scandiscovery.sbom: path to the relevant .vulnetix/scans/*.cdx.json if one exists for this package's manifestdecision.choice: investigatingdecision.reason: "Discovered via /vulnetix:package-search"history: event: discovered, detail: "Found via package search for <query>"VEX-to-developer-language: When surfacing prior decisions, use developer-friendly language:
not_affected → "Not affected", affected → "Vulnerable", fixed → "Fixed", under_investigation → "Investigating"When gh CLI is available (check with gh auth status 2>/dev/null), query Dependabot alerts for packages in the search results to enrich the risk assessment.
During Step 4 (Risk Assessment):
gh api repos/{owner}/{repo}/dependabot/alerts?state=open --jq '[.[] | select(.dependency.package.name == "'"$PACKAGE_NAME"'")] | length'"Dependabot PR #N open for <package> upgrade"dependabot section, surface it in the Known History output:CVE-2021-44228 — Fixed (2024-01-15, Dependabot: merged PR #187)During Step 5 (Propose Dependency Addition):
"Dependabot PR #N already proposes this upgrade — consider merging it instead"This avoids duplicate work and leverages Dependabot's existing CI validation.
When gh CLI is available, check if CodeQL has flagged issues related to packages being searched. The canonical state-to-VEX mapping is defined in /vulnetix:fix.
During Step 4 (Risk Assessment):
gh api repos/{owner}/{repo}/code-scanning/alerts --jq '[.[] | select(.rule.tags[]? | test("CWE-<NUMBER>"; "i"))] | length'code_scanning section, surface it in Known History:CVE-2021-44228 — Fixed (2024-01-15, CodeQL: alert #15 fixed)During Step 5 (Propose Dependency Addition):
When gh CLI is available, check for secret scanning alerts relevant to packages handling authentication or credentials.
During Step 4 (Risk Assessment):
jsonwebtoken, bcrypt, passport, oauth2, crypto, keyring), check for open secret scanning alerts:gh api repos/{owner}/{repo}/secret-scanning/alerts?state=open --jq 'length'secret_scanning section, surface it in Known HistoryCheck cached manifest data first: If .vulnetix/memory.yaml has a manifests section, use it to identify previously detected ecosystems and their scan dates. This avoids re-globbing for manifests that are already tracked. If the manifests section exists and is recent (< 24h), use the cached ecosystem list as a starting point.
Then verify with Glob to catch any new manifest files:
package.json, package-lock.json, yarn.lock, pnpm-lock.yaml → npmgo.mod, go.sum → goCargo.toml, Cargo.lock → cargorequirements.txt, pyproject.toml, Pipfile, poetry.lock, uv.lock → pypiGemfile, Gemfile.lock → rubygemspom.xml, build.gradle, gradle.lockfile → mavencomposer.json, composer.lock → packagistDetermine which ecosystems this repository uses. If new manifest files are discovered that aren't in the manifests section of .vulnetix/memory.yaml, add them with ecosystem, path, and scan_source: package-search (without sbom_generated: true since this skill doesn't generate SBOMs).
For the package being searched, determine if it is already installed and what version is in use. You MUST resolve the current version using one of these methods (in priority order) and always disclose the source in your output:
package-lock.json or yarn.lock or pnpm-lock.yaml for the resolved versionpoetry.lock, Pipfile.lock, or uv.lockgo.sum for the recorded versionCargo.lock for the resolved versionGemfile.lockgradle.lockfile if presentcomposer.lockpackage.json → dependencies / devDependenciesrequirements.txt (pkg==1.2.3), pyproject.tomlgo.mod (require pkg v1.2.3)Cargo.toml [dependencies]Gemfilepom.xml <version>, build.gradlecomposer.jsonnode_modules/<package>/package.json → version fieldpip show <package> or python -c "import <pkg>; print(<pkg>.__version__)"go list -m <package>cargo pkgid <package>gem list <package> --local<binary> --version or which <binary>If the package is not currently installed (not found in any of the above), explicitly state: "Not currently installed — no existing version detected."
Version Source Label: In all outputs, tag the version with its source, e.g.:
1.2.3 (from lockfile: package-lock.json)^1.2.0 (from manifest: package.json — constraint, not exact)1.2.3 (from node_modules)1.2.3 (user-supplied)Not installedRun the Vulnetix VDB package search command:
vulnetix vdb packages search "$ARGUMENTS" -o jsonIf you detected a single ecosystem, add the --ecosystem <ecosystem> flag to filter results.
For example:
vulnetix vdb packages search "express" --ecosystem npm -o jsonThe output is JSON with this structure:
{
"packages": [
{
"name": "express",
"ecosystem": "npm",
"description": "Fast, unopinionated, minimalist web framework",
"latestVersion": "4.18.2",
"vulnerabilityCount": 3,
"maxSeverity": "high",
"safeHarbourScore": 85,
"repository": "https://github.com/expressjs/express"
}
]
}Version enrichment: After receiving results, enrich each package with the current version detected in Step 1b. The API returns latestVersion — you must pair this with the currentVersion you resolved from the filesystem.
Discard packages from ecosystems not present in the repository. For example, if the repo only has package.json, filter out PyPI and Cargo results.
Present the matching packages in a comparison table with these columns:
| Package | Ecosystem | Current Version | Latest Version | Vulnerabilities | Max Severity | Safe Harbour | Confidence | Repository |
|---|---|---|---|---|---|---|---|---|
| express | npm | 4.17.1 (lockfile) | 4.18.2 | 3 | high | 0.85 | High | [link] |
Column definitions:
4.17.1 (lockfile), ^4.17.0 (manifest), Not installed). This is resolved from Step 1b.85 → display 0.85). This represents a safety confidence percentage where 1.0 = 100% confidence in safety.Below the table, always include a Version Context summary:
Version Context:
- express: 4.17.1 → 4.18.2 (patch upgrade available) — source: package-lock.json
- lodash: Not installed — no existing version detectedThis gives the user full transparency on where version information was derived and what upgrade path exists.
For the best candidate (lowest vuln count, highest Safe Harbour value):
currentVersion → latestVersion. If new, show (new) latestVersion.dependencies in package.jsonrequirements.txt or pyproject.tomlgo get command with version[dependencies] in Cargo.toml<dependency> XML with versionGemfile with versioncomposer require command with versionUse the Edit tool to show the proposed change, but DO NOT apply it yet.
Example for npm (new dependency):
{
"dependencies": {
+ "express": "^4.18.2",
"other-package": "1.0.0"
}
}Example for npm (upgrade):
{
"dependencies": {
- "express": "^4.17.1",
+ "express": "^4.18.2",
"other-package": "1.0.0"
}
}Always include the specific version in the proposed edit — never use * or latest.
Ask the user:
npm install, pip install, etc.)/vulnetix:exploits <vuln-id> for any critical/high severity vulnerabilities found)If the user requests alternatives, repeat steps 2-6 with the suggested names.
vulnetix vdb packages search fails, inform the user to check vulnetix vdb status© davepoon, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/vulnetix/skills/package-search of davepoon/buildwithclaude.
Open the folder on GitHubat commit 616deb5
Package Search next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Package Search this skilldavepoon/buildwithclaude | 3.6k | — | ~4.3k | Automated safety check: Notes | MIT | |
| Code Graph Mermaid Diagramstrailofbits/skills | 7.4k | — | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Design Doc MermaidSpillwaveSolutions/design-doc-mermaid | 176 | 1 repos | ~5.6k | Automated safety check: Pass | None | |
| Markdown Mermaid Writingneflibata-feng/MyArxiv-Agent | 126 | 5 repos | ~3.8k | Automated safety check: Notes | Apache-2.0 | |
| Code To Diagramzebbern/claude-code-guide | 4.7k | — | ~972 | Automated safety check: Pass | MIT | |
| Generate Readmedivar-ir/ai-doc-gen | 767 | — | ~996 | Automated safety check: Pass | MIT |
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
SpillwaveSolutions/design-doc-mermaid
Create Mermaid diagrams (flowchart, sequence, class, ER, state, C4, architecture) from text or source code.
neflibata-feng/MyArxiv-Agent
Comprehensive markdown and Mermaid diagram writing skill that establishes text-based diagrams as the DEFAULT documentation standard.
zebbern/claude-code-guide
Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.
divar-ir/ai-doc-gen
Generate or refresh a comprehensive, professional README.md for a repository, with architecture overview, mermaid and optional C4 diagrams, repository structure, dependencies, and API documentation.
aospbooks/aosp-internal-book
Patterns for writing technical book chapters in Markdown with Mermaid diagrams, served via ProperDocs (a MkDocs fork).
davepoon/buildwithclaude
Build, update, and apply iOS design specifications using Apple Human Interface Guidelines (HIG) source data.
davepoon/buildwithclaude
Download YouTube videos with customizable quality and format options.
davepoon/buildwithclaude
A skill your agent uses when the user asks to "analyze video", "watch this video", "what happens in this video", "describe this clip", "review this footage", "classify these videos", "compare…
davepoon/buildwithclaude
Discover Atlas Cloud image and video models, inspect their live schemas, and submit one confirmed media generation request with bounded GET polling.
davepoon/buildwithclaude
面向没有编程经验的用户,把想法做成可试用的浏览器插件,并完成检查、商店材料、审核提交和上线验证;也用于继续已有插件、排错和发布新版。用户说“帮我做个插件”“把插件上架”“继续我的插件”时使用。普通网站开发、仅查询插件知识不触发。
davepoon/buildwithclaude
Toolkit for creating animated GIFs optimized for Slack, with validators for size constraints and composable animation primitives.
Categories
Search for packages and assess security risk before adding as dependencies. Package Search is an agent skill from davepoon/buildwithclaude.
Package Search fits situations like: development work in your project.
Run `npx skills add davepoon/buildwithclaude --skill package-search -a claude-code`. Or copy the skill folder (plugins/vulnetix/skills/package-search in davepoon/buildwithclaude) into .claude/skills/package-search in your project. Claude Code loads it when a task matches its description.
Run `npx skills add davepoon/buildwithclaude --skill package-search -a codex`. Or copy the skill folder (plugins/vulnetix/skills/package-search in davepoon/buildwithclaude) into .agents/skills/package-search in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davepoon/buildwithclaude --skill package-search -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/package-search, .gemini/skills/package-search, .github/skills/package-search and .opencode/skills/package-search in your project.
Going by SKILL.md and its folder, Package Search needs the command-line tools its instructions call (gh, pip, go, uv, cargo and python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep, Edit, Write.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Package Search is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Package Search: Code Graph Mermaid Diagrams (trailofbits/skills, 7.4k stars), Design Doc Mermaid (SpillwaveSolutions/design-doc-mermaid, 176 stars), Markdown Mermaid Writing (neflibata-feng/MyArxiv-Agent, 126 stars) and Code To Diagram (zebbern/claude-code-guide, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
davepoon (a GitHub user) maintains it in davepoon/buildwithclaude, which has 3,605 GitHub stars. The repository holds 246 skills in this directory. The repository was last updated on October 9, 2026.
Source: davepoon/buildwithclaude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.