Warp Vulnerability Triage
warpdotdev/warp
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
Configure single-project Google Cloud Logging: regional log buckets, log sinks, log views, restricting or hiding sensitive logs in the default view (Default) filter, IAM permissions for views (Logs…
$ npx skills add google/skills --skill cloud-logging-configuration-basics -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install google/skills cloud-logging-configuration-basics --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/cloud-logging-configuration-basics .claude/skills/cloud-logging-configuration-basics && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cloud-logging-configuration-basics" agent skill from https://github.com/google/skills/tree/main/skills/cloud/cloud-logging-configuration-basics into .claude/skills/cloud-logging-configuration-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-logging-configuration-basics", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/google/skills/tree/main/skills/cloud/cloud-logging-configuration-basicsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add google/skills --skill cloud-logging-configuration-basics -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install google/skills cloud-logging-configuration-basics --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloud/cloud-logging-configuration-basics .agents/skills/cloud-logging-configuration-basics && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cloud-logging-configuration-basics" agent skill from https://github.com/google/skills/tree/main/skills/cloud/cloud-logging-configuration-basics into .agents/skills/cloud-logging-configuration-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-logging-configuration-basics", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill cloud-logging-configuration-basics -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install google/skills cloud-logging-configuration-basics --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloud/cloud-logging-configuration-basics .cursor/skills/cloud-logging-configuration-basics && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cloud-logging-configuration-basics" agent skill from https://github.com/google/skills/tree/main/skills/cloud/cloud-logging-configuration-basics into .cursor/skills/cloud-logging-configuration-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-logging-configuration-basics", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/google/skills.git --path skills/cloud/cloud-logging-configuration-basics--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add google/skills --skill cloud-logging-configuration-basics -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install google/skills cloud-logging-configuration-basics --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloud/cloud-logging-configuration-basics .gemini/skills/cloud-logging-configuration-basics && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cloud-logging-configuration-basics" agent skill from https://github.com/google/skills/tree/main/skills/cloud/cloud-logging-configuration-basics into .gemini/skills/cloud-logging-configuration-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-logging-configuration-basics", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install google/skills cloud-logging-configuration-basicsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add google/skills --skill cloud-logging-configuration-basics -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloud/cloud-logging-configuration-basics .github/skills/cloud-logging-configuration-basics && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cloud-logging-configuration-basics" agent skill from https://github.com/google/skills/tree/main/skills/cloud/cloud-logging-configuration-basics into .github/skills/cloud-logging-configuration-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-logging-configuration-basics", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add google/skills --skill cloud-logging-configuration-basics -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install google/skills cloud-logging-configuration-basics --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloud/cloud-logging-configuration-basics .opencode/skills/cloud-logging-configuration-basics && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cloud-logging-configuration-basics" agent skill from https://github.com/google/skills/tree/main/skills/cloud/cloud-logging-configuration-basics into .opencode/skills/cloud-logging-configuration-basics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-logging-configuration-basics", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cloud-logging-configuration-basicsConfigure single-project Google Cloud Logging: regional log buckets, log sinks, log views, restricting or hiding sensitive logs in the default view (Default) filter, IAM permissions for views (Logs…
Cloud Logging Configuration Basics is an agent skill from google/skills, published by the product's own GitHub organization. Configure single-project Google Cloud Logging: regional log buckets, log sinks, log views, restricting or hiding sensitive logs in the default view (Default) filter, IAM permissions for views (Logs View Accessor, IAM conditions), logs-based metrics, log exclusions, and sampling. Don't use for cross-project logging or multi-project setups.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security. It works with Google Cloud. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8a1ac05. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gcloudFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.cloud.google.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cloud Logging Configuration Basics loads about 3.5k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 1,395 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from google/skills at commit 8a1ac05, republished under its Apache-2.0 licence (© google). 1,395 words, ~3,463 tokens.
.claude/skills/cloud-logging-configuration-basics/SKILL.md (or your agent's skills folder).Use this skill to configure Cloud Logging resources such as log buckets, log views, or log sinks.
[!IMPORTANT] Sandbox Network Limitation (CRITICAL for Agent Testing): During evaluation or in restricted sandboxed environments, network traffic to Google Cloud APIs is blocked. Do NOT run network discovery commands to find resource names, project IDs, or organization IDs. Always use the exact project IDs or placeholders provided in the user prompt or instructions for example,
{project_id}. Assume these resources exist and proceed directly with configuration commands. Running these discovery commands will cause the execution to hang and timeout.
Before executing any commands on behalf of the user, you MUST adhere to the following safety tiers based on the action requested:
gcloud logging readgcloud logging buckets listgcloud logging views creategcloud logging views updategcloud logging scopes creategcloud logging buckets creategcloud logging metrics creategcloud logging links creategcloud projects add-iam-policy-bindinggcloud logging buckets deletegcloud logging sinks update --add-exclusionIf the gcloud executable is missing, refer to the
Google Cloud CLI Installation Guide
to install it.
To create a regional log bucket with a specific retention policy for regulatory compliance, and with Observability Analytics enabled:
[!WARNING] Mandatory Observability Analytics Downgrade Warning: Whenever providing guidance, writing a guide, or drafting commands on Cloud Logging cost optimization or exclusions, you must explicitly include the following warning in your final text response and any generated guides: "After a log bucket has been upgraded to use Observability Analytics, it cannot be downgraded to remove the analytics capability."
gcloud logging buckets create {bucket_id} \
--project={project_id} \
--location={region} \
--retention-days={retention_days} \
--enable-analytics{bucket_id}: for example, my-custom-bucket{region}: for example, us-central1. You must use a regional log bucket
to also use Observability Analytics.{retention_days}: for example, 365A log bucket incurs no storage or ingestion charges until logs are routed to it with a log sink.
Check the log bucket's configuration to verify its compliance:
gcloud logging buckets describe {bucket_id} \
--location={region} \
--project={project_id}[!IMPORTANT] Billing Action (Tier B): Routing log entries to a bucket incurs ongoing charges based on the volume of data stored. You MUST get interactive user confirmation before running this command.
Log entries are stored in the log bucket only if a log sink filter matches the entries and targets that bucket.
To route log entries to the log bucket:
gcloud logging sinks create {sink_id} \
projects/{project_id}/locations/{region}/buckets/{bucket_id} \
--log-filter='{filter_expression}' \
--project={project_id}Logs-based metrics count the number of log entries that match a filter, allowing you to track error rates and set up alerting policies.
[!IMPORTANT] Billing Action (Tier B): Creating logs-based metrics incurs ongoing charges based on the volume of data points reported. You MUST get interactive user confirmation before running this command.
To count the occurrences of a specific log pattern, for example, "OutOfMemory" errors:
gcloud logging metrics create {metric_name} \
--log-filter='{filter_expression}' \
--description='{description}' \
--project={project_id}{metric_name}: for example, oom_error_count{filter_expression}: for example, textPayload:"OutOfMemory"{description}: for example, "Count of log entries about OOMs"Refer to REST Resource: projects.metric for restrictions on the metric fields.
To verify that the metric exists and inspect its configuration, use the
describe command:
gcloud logging metrics describe {metric_name} \
--project={project_id}Anyone with roles/logging.viewer on that project can see logs in a project's
_Default log bucket via _Default log view. To restrict visibility of the
logs:
[!IMPORTANT] Ambiguity Handling (Guidance for Agents): If the user asks to "exclude", "hide", or "remove" sensitive logs without explicitly specifying whether they want to stop storing them, you MUST default to excluding them from the default view (Step 1). This is a safe, non-destructive Tier M action. Only configure a storage exclusion (under the "Discarding Sensitive Logs from Storage" section) if the user explicitly uses destructive terms like "stop storing", "permanently discard", or "sink exclusion".
To explicitly exclude sensitive logs from general access, update the filter for
the _Default log view:
gcloud logging views update _Default \
--bucket=_Default \
--location=global \
--project={project_id} \
--log-filter='NOT LOG_ID("cloudaudit.googleapis.com/data_access") AND NOT LOG_ID("externalaudit.googleapis.com/data_access") AND NOT LOG_ID("{sensitive_log_id}")'Create a new log view that includes the sensitive logs in the project's
_Default log bucket. For example, a "security-logs-view" with access to the
{sensitive_log_id}
gcloud logging views create security-logs-view \
--bucket=_Default \
--location=global \
--project={project_id} \
--log-filter='LOG_ID("{sensitive_log_id}")' \
--description="Sensitive logs"[!IMPORTANT] Security Action (Tier B): Granting IAM permissions changes access control policy and must be explicitly confirmed by the user before execution.
To restrict access to log view use IAM. When granting the Logs Viewer Accessor
role, always attach an IAM condition that restricts the grant to a specific log
view. For example, to grant {security_group_email} access ONLY to the
security-logs-view in the _Default bucket:
gcloud projects add-iam-policy-binding {project_id} \
--member='group:{security_group_email}' \
--role='roles/logging.viewAccessor' \
--condition="expression=resource.name=='projects/{project_id}/locations/global/buckets/_Default/views/security-logs-view',title=Restricted to Specific Log View,description=Only allows access to the specified log view"Replace {location} with the location of the log bucket, for example global
or a regional location like us-central1.
To verify that your Log View for sensitive logs is configured correctly:
gcloud logging views describe {view_id} \
--bucket={bucket_id} \
--location={region} \
--project={project_id}Ensure that the filter block contains the appropriate restriction expression.
If your organization's compliance policies prohibit storing sensitive logs at all, you can configure an exclusion to discard them before they are written to disk.
[!CAUTION] Destructive Action (Tier D): Excluding logs from all log sinks deletes the log entries immediately and irreversibly.
Safety Rule: You MUST ask the user for explicit typed confirmation, for example, "I confirm I want to exclude
{sensitive_log_id}logs from storage", before running this command. Same-Turn Restriction: Do NOT execute thegcloud logging sinks updatecommand in the same turn as asking for confirmation. Stop tool execution immediately and wait for the user to reply.
Exclude sensitive logs from storage using sink exclusions
gcloud logging sinks update _Default \
--project={project_id} \
--add-exclusion=name=exclude-sensitive,filter='LOG_ID("{sensitive_log_id}")'Cloud Logging costs are based on the volume of data ingested and stored. You can reduce costs by excluding high-volume, low-value logs or by sampling them. Each log sink that routes logs to a distinct log bucket contributes to cost and is a candidate for optimization.
[!CAUTION] Destructive Actions (Tier D): Exclusions in this section may immediately halt storage of log entries.
Safety Rule: You MUST ask for explicit typed confirmation (for example, "I confirm I want to exclude load balancer logs") before executing exclusions or sampling updates.
To completely stop ingesting a specific type of log into a log bucket, add an exclusion to the log sinks that route logs into that bucket.
gcloud logging sinks update {sink_id} \
--project={project_id} \
--add-exclusion=name={exclusion_name},filter={exclusion_filter}{sink_id}: for example '_Default'{exclusion_name}: for example 'exclude-lb-logs'{exclusion_filter}: for example 'resource.type="http_load_balancer"'If you need some logs for analysis but want to reduce volume, use the sample()
function in the exclusion filter.
[!IMPORTANT] The
sample(field, fraction)function matches afractionof logs. When used in an exclusion filter, the matched logs are discarded. If you exclude 90% of log entries, then only 10% are retained. To exclude 90%, usesample(insertId, 0.9)in the exclusion filter.
To exclude 90% of DEBUG severity logs:
gcloud logging sinks update _Default \
--project={project_id} \
--add-exclusion=name=sample-debug-logs,filter='severity=DEBUG AND sample(insertId, 0.9)'To verify that log exclusions are correct, list the details of the sink and
check the exclusions to ensure your filter is present. For example, for the
_Default sink:
gcloud logging sinks describe _Default --project={project_id}© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/cloud/cloud-logging-configuration-basics of google/skills.
Open the folder on GitHubat commit 8a1ac05
Cloud Logging Configuration Basics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cloud Logging Configuration Basics this skillgoogle/skills | 21k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| Warp Vulnerability Triagewarpdotdev/warp | 65k | 1 repos | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Cloud Auditbriiirussell/cybersecurity-skills | 412 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Configuring Identity Aware Proxy With Google Iapmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Beyondcorp Zero Trust Access Modelmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | |
| Auditing Cloud With Cis Benchmarksmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 |
warpdotdev/warp
Gathers security findings from Dependabot, GCP container scanning, Docker Scout and Linear security issues, then triages and remediates them across Warp's repos and images.
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
mukul975/Anthropic-Cybersecurity-Skills
Configures Google Cloud Identity-Aware Proxy (IAP) via gcloud to enforce per-request identity verification on Compute Engine, App Engine, Cloud Run, and GKE, including IAM bindings, Access Context…
mukul975/Anthropic-Cybersecurity-Skills
Implement Google's BeyondCorp zero trust access model using Cloud IAP, Access Context Manager, Endpoint Verification, Chrome Enterprise Premium, and BeyondCorp Enterprise Connectors to enforce…
mukul975/Anthropic-Cybersecurity-Skills
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…
mukul975/Anthropic-Cybersecurity-Skills
Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…
google/skills
Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.
google/skills
Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.
google/skills
Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.
google/skills
Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.
google/skills
Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.
google/skills
Analyzes BigQuery slot use, query costs and execution bottlenecks from INFORMATION_SCHEMA to diagnose slow queries, slot contention and unpartitioned scans.
Works with
Categories
Configure single-project Google Cloud Logging: regional log buckets, log sinks, log views, restricting or hiding sensitive logs in the default view (Default) filter, IAM permissions for views (Logs…. Cloud Logging Configuration Basics is an agent skill from google/skills, published by the product's own GitHub organization. Configure single-project Google Cloud Logging: regional log buckets, log sinks, log views, restricting or hiding sensitive logs in the default view (Default) filter, IAM permissions for views (Logs View Accessor, IAM conditions), logs-based metrics, log exclusions, and sampling.
Cloud Logging Configuration Basics fits situations like: cross-project logging; multi-project setups.
Run `npx skills add google/skills --skill cloud-logging-configuration-basics -a claude-code`. Or copy the skill folder (skills/cloud/cloud-logging-configuration-basics in google/skills) into .claude/skills/cloud-logging-configuration-basics in your project. Claude Code loads it when a task matches its description.
Run `npx skills add google/skills --skill cloud-logging-configuration-basics -a codex`. Or copy the skill folder (skills/cloud/cloud-logging-configuration-basics in google/skills) into .agents/skills/cloud-logging-configuration-basics in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill cloud-logging-configuration-basics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-logging-configuration-basics, .gemini/skills/cloud-logging-configuration-basics, .github/skills/cloud-logging-configuration-basics and .opencode/skills/cloud-logging-configuration-basics in your project.
Going by SKILL.md and its folder, Cloud Logging Configuration Basics needs the command-line tools its instructions call (gcloud).
SKILL.md names 1 domain. As links in the text: docs.cloud.google.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cloud Logging Configuration Basics is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cloud Logging Configuration Basics: Warp Vulnerability Triage (warpdotdev/warp, 65k stars), Cloud Audit (briiirussell/cybersecurity-skills, 412 stars), Configuring Identity Aware Proxy With Google Iap (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Beyondcorp Zero Trust Access Model (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
google (a GitHub organization, an official publisher) maintains it in google/skills, which has 20,994 GitHub stars. The repository holds 145 skills in this directory. The repository was last updated on October 6, 2026.
Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.