Agent skill

Building Purpose Limitation Enforcement

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Technical enforcement of GDPR Article 5(1)(b) purpose limitation principle.

Apache-2.0Auto-check passedLegal & Compliance

Install Building Purpose Limitation Enforcement

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill building-purpose-limitation-enforcement -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills building-purpose-limitation-enforcement --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/building-purpose-limitation-enforcement .claude/skills/building-purpose-limitation-enforcement && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
building-purpose-limitation-enforcement
GitHub stars
301
Token cost
~2.9k tokens
SKILL.md length
839 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Technical enforcement of GDPR Article 5(1)(b) purpose limitation principle.

  • Works in 4 steps: Purpose binding at ingestion — Every… → Purpose-based access control — Access… → Purpose audit trail — Every access is… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Article 6(4) Compatibility…, Purpose-Tagged Data Architecture and Access Control Per Purpose, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Building Purpose Limitation Enforcement is an agent skill from mukul975/Privacy-Data-Protection-Skills. Technical enforcement of GDPR Article 5(1)(b) purpose limitation principle. Covers purpose-tagged data stores, access control per purpose, Article 6(4) compatibility assessment factors, and system design for preventing purpose creep. Includes purpose binding architecture and compatibility test implementation.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR and Authorization and RBAC. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve Authorization and RBAC

Example prompts

  • “/building-purpose-limitation-enforcement”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Purpose binding at ingestion — Every data record is tagged with its collection purpose at the point of entry into the system
  2. Purpose-based access control — Access policies are defined per purpose, not per data field alone
  3. Purpose audit trail — Every access is logged with the purpose under which it was authorized
  4. Purpose expiry — When a purpose is fulfilled, the associated data enters a retention countdown

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Building Purpose Limitation Enforcement loads about 2.9k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 839 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 839 words, ~2,859 tokens.

Download SKILL.mdSave it as .claude/skills/building-purpose-limitation-enforcement/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
building-purpose-limitation-enforcement
description
Technical enforcement of GDPR Article 5(1)(b) purpose limitation principle. Covers purpose-tagged data stores, access control per purpose, Article 6(4) compatibility assessment factors, and system design for preventing purpose creep. Includes purpose binding architecture and compatibility test implementation.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-by-design
metadata.tags
purpose-limitation, article-5, compatibility-test, purpose-binding, access-control

Building Purpose Limitation Enforcement

Overview

Article 5(1)(b) of the GDPR requires that personal data be "collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes." This is the purpose limitation principle, one of the foundational data protection principles.

The controller must specify the purpose at or before the time of collection (Article 13(1)(c) for direct collection, Article 14(1)(c) for indirect collection). Any subsequent processing for a different purpose requires either a new lawful basis or must pass the compatibility assessment under Article 6(4).

The Article 29 Working Party Opinion 03/2013 on purpose limitation (WP203) provides detailed guidance on assessing compatibility, identifying five key factors codified in Article 6(4).

Article 6(4) Compatibility Assessment Factors

When a controller wishes to process personal data for a purpose other than that for which it was collected, Article 6(4) requires an assessment of compatibility considering:

FactorArticle 6(4) ReferenceAssessment Question
Link between purposesArticle 6(4)(a)Is there a connection between the original and new purpose?
Context of collectionArticle 6(4)(b)What is the relationship between controller and data subject? What are the reasonable expectations?
Nature of dataArticle 6(4)(c)Does the data include special categories (Article 9) or criminal convictions (Article 10)?
ConsequencesArticle 6(4)(d)What are the possible consequences of the further processing for data subjects?
SafeguardsArticle 6(4)(e)Are appropriate safeguards in place, including encryption or pseudonymisation?

Compatibility is not required when:

  • Processing is based on consent (Article 6(1)(a)) — new consent can be obtained for the new purpose
  • Processing is based on Union or Member State law that constitutes a necessary and proportionate measure (Article 6(4) final paragraph)
  • Processing is for archiving in the public interest, scientific/historical research, or statistics per Article 89(1)

Purpose-Tagged Data Architecture

Design Principles
  1. Purpose binding at ingestion — Every data record is tagged with its collection purpose at the point of entry into the system
  2. Purpose-based access control — Access policies are defined per purpose, not per data field alone
  3. Purpose audit trail — Every access is logged with the purpose under which it was authorized
  4. Purpose expiry — When a purpose is fulfilled, the associated data enters a retention countdown
Architecture Diagram
┌────────────────────────────────────────────────────────────┐
│                   Data Collection Points                    │
│  ┌──────────┐  ┌──────────┐  ┌──────────┐  ┌──────────┐  │
│  │ Web Form │  │ API Call │  │ IoT Feed │  │ Partner  │  │
│  │ P:ONBRD  │  │ P:ANALYT │  │ P:MAINT  │  │ P:MARKET │  │
│  └────┬─────┘  └────┬─────┘  └────┬─────┘  └────┬─────┘  │
│       └──────────────┼──────────────┼──────────────┘       │
└──────────────────────┼──────────────┼──────────────────────┘
                       │              │
┌──────────────────────▼──────────────▼──────────────────────┐
│              Purpose Tagging Gateway                        │
│  ┌─────────────────┐  ┌─────────────────────────────────┐  │
│  │ Purpose Registry │  │ Tag Injection Middleware        │  │
│  │ (canonical IDs)  │  │ (attaches purpose + timestamp)  │  │
│  └─────────────────┘  └─────────────────────────────────┘  │
└──────────────────────────────┬─────────────────────────────┘
                               │
┌──────────────────────────────▼─────────────────────────────┐
│              Purpose-Partitioned Data Store                  │
│  ┌──────────┐  ┌──────────┐  ┌──────────┐  ┌──────────┐  │
│  │ ONBRD    │  │ ANALYT   │  │ MAINT    │  │ MARKET   │  │
│  │ Partition│  │ Partition│  │ Partition│  │ Partition│  │
│  └──────────┘  └──────────┘  └──────────┘  └──────────┘  │
└──────────────────────────────┬─────────────────────────────┘
                               │
┌──────────────────────────────▼─────────────────────────────┐
│              Purpose Enforcement Layer                       │
│  ┌─────────────────┐  ┌────────────────┐  ┌────────────┐  │
│  │ Policy Engine   │  │ Compatibility  │  │ Audit      │  │
│  │ (OPA / Cedar)   │  │ Assessor       │  │ Logger     │  │
│  └─────────────────┘  └────────────────┘  └────────────┘  │
└────────────────────────────────────────────────────────────┘
Purpose Registry Schema

Each processing purpose is registered with canonical metadata:

json
{
  "purpose_id": "PRP-ONBRD-001",
  "purpose_name": "Customer Account Onboarding",
  "description": "Collection and processing of personal data necessary to create and activate a customer account, verify identity, and establish the contractual relationship.",
  "lawful_basis": "Article 6(1)(b)",
  "data_categories": ["email", "display_name", "country_code", "identity_verification_result"],
  "controller": "Prism Data Systems AG",
  "retention_period_days": 2555,
  "retention_trigger": "account_closure",
  "compatible_purposes": ["PRP-SUPRT-001", "PRP-SECUR-001"],
  "incompatible_purposes": ["PRP-MARKET-001", "PRP-RESRCH-001"],
  "special_categories": false,
  "created_date": "2025-06-01",
  "last_reviewed": "2026-01-15",
  "review_cadence_days": 180,
  "owner": "product_team",
  "dpo_approved": true
}

Access Control Per Purpose

Policy-as-Code with Open Policy Agent (OPA)

Purpose-based access control is implemented using OPA policies that evaluate access requests against the purpose registry:

# Prism Data Systems AG — Purpose-Based Access Policy

# Rule: Access is granted only if the requesting service's declared purpose
# matches a purpose tag on the requested data record.

allow {
    input.action == "read"
    input.resource.purpose_tags[_] == input.requester.declared_purpose
    purpose_is_active(input.requester.declared_purpose)
    role_authorized_for_purpose(input.requester.role, input.requester.declared_purpose)
}

# Rule: Cross-purpose access requires a completed compatibility assessment
allow {
    input.action == "read"
    not input.resource.purpose_tags[_] == input.requester.declared_purpose
    compatibility_assessment_approved(input.resource.purpose_tags, input.requester.declared_purpose)
    purpose_is_active(input.requester.declared_purpose)
}

# Rule: Write operations must include a valid purpose tag
allow {
    input.action == "write"
    valid_purpose(input.resource.purpose_tag)
    input.requester.declared_purpose == input.resource.purpose_tag
}
Role-Purpose Authorization Matrix
RoleONBRDANALYTSUPRTMARKETSECURBILLING
Onboarding ServiceRead/Write—————
Analytics Pipeline—Read————
Support AgentRead—Read/Write——Read
Marketing Automation———Read——
Security OperationsReadReadReadReadRead/WriteRead
Billing ServiceRead————Read/Write
Show full SKILL.md (400 more words)Show less

Purpose Compatibility Assessment Workflow

  1. Request submission — Service owner submits a request to process data collected under purpose A for new purpose B, documenting the business justification.

  2. Factor analysis — The Data Protection Office evaluates the five Article 6(4) factors:

    • Link between purposes (scored 1-5: 1 = no link, 5 = closely linked)
    • Context and expectations (scored 1-5: 1 = unexpected, 5 = fully expected)
    • Nature of data (scored 1-5: 1 = special category, 5 = non-sensitive)
    • Consequences (scored 1-5: 1 = severe, 5 = minimal impact)
    • Safeguards (scored 1-5: 1 = no safeguards, 5 = comprehensive safeguards)
  3. Scoring — Total score calculated (range 5-25):

    • 20-25: Compatible. Approve with standard documentation.
    • 15-19: Potentially compatible. Approve with additional safeguards (pseudonymization, access restriction).
    • 10-14: Likely incompatible. Requires DPO escalation and DPIA consideration.
    • 5-9: Incompatible. Denied. New lawful basis or separate consent required.
  4. Decision recording — Assessment result recorded in the purpose registry with the assessor identity, date, score breakdown, conditions, and review date.

  5. Policy update — If approved, OPA policies are updated to allow cross-purpose access under documented conditions.

Prism Data Systems AG Implementation

Purpose Registry

Prism Data Systems AG maintains 14 registered purposes in their purpose registry:

Purpose IDNameLawful BasisData Categories
PRP-ONBRD-001Customer onboardingArt. 6(1)(b)email, display_name, country_code
PRP-AUTH-001AuthenticationArt. 6(1)(b)email, password_hash, mfa_token
PRP-BILLING-001Billing and invoicingArt. 6(1)(b)billing_address, payment_method, vat_id
PRP-SUPRT-001Customer supportArt. 6(1)(b)email, display_name, support_ticket_history
PRP-ANALYT-001Product analyticsArt. 6(1)(f)pseudonymized_user_id, feature_events, session_duration
PRP-MARKET-001Direct marketingArt. 6(1)(a)email, display_name, marketing_preferences
PRP-SECUR-001Security monitoringArt. 6(1)(f)ip_address, user_agent, login_events
PRP-LEGAL-001Legal complianceArt. 6(1)(c)transaction_records, consent_records
Enforcement Metrics

Prism Data Systems AG tracks the following purpose limitation enforcement metrics:

MetricTargetMeasurement
Purpose tag coverage100% of recordsPercentage of data records with valid purpose tags
Cross-purpose access attempts blocked> 95% without assessmentPolicy engine denial count vs. total cross-purpose requests
Compatibility assessments completed100% within 5 business daysTime from request to DPO decision
Purpose registry review currency100% reviewed within cadencePercentage of purposes reviewed within their review cadence

Key Regulatory References

  • GDPR Article 5(1)(b) — Purpose limitation principle
  • GDPR Article 6(4) — Compatibility assessment factors
  • GDPR Article 13(1)(c) — Information about purpose at collection
  • GDPR Article 14(1)(c) — Information about purpose for indirect collection
  • GDPR Article 89(1) — Exception for archiving, research, statistics
  • GDPR Recital 50 — Further processing compatibility
  • Article 29 Working Party Opinion 03/2013 on purpose limitation (WP203)
  • EDPB Guidelines 4/2019 on Article 25 Data Protection by Design and by Default

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/building-purpose-limitation-enforcement of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Building Purpose Limitation Enforcement next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Building Purpose Limitation Enforcement compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Building Purpose Limitation Enforcement this skillmukul975/Privacy-Data-Protection-Skills301—~2.9kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~4.2kAutomated safety check: PassMIT
Tos Clause Scannerzebbern/claude-code-guide4.7k1 repos~3.3kAutomated safety check: PassMIT
Healthcare Phi Complianceaffaan-m/ECC277k1 repos~1.4kAutomated safety check: PassMIT
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Fondo Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    946 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Tos Clause Scanner

    zebbern/claude-code-guide

    Audit Terms of Service, user agreements, and privacy policies for consumer risks, producing a structured report that flags unfair clauses, data traps, and liability issues.

    4.7k GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Protected Health Information (PHI) and PII compliance patterns for healthcare applications: data classification, row-level access control, tamper-proof audit trails, schema tagging, and common leak…

    277k GitHub starsUsed in 1 repo~1.4k tokens
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Fondo Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Apply security best practices for Fondo including OAuth token management, financial data protection, SOC 2 compliance, and access control.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Building Purpose Limitation Enforcement

What does Building Purpose Limitation Enforcement do?

Technical enforcement of GDPR Article 5(1)(b) purpose limitation principle. Building Purpose Limitation Enforcement is an agent skill from mukul975/Privacy-Data-Protection-Skills. Technical enforcement of GDPR Article 5(1)(b) purpose limitation principle.

When should I use Building Purpose Limitation Enforcement?

Building Purpose Limitation Enforcement fits situations like: tasks that involve Privacy and GDPR; tasks that involve Authorization and RBAC.

How do I install Building Purpose Limitation Enforcement in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill building-purpose-limitation-enforcement -a claude-code`. Or copy the skill folder (skills/privacy/building-purpose-limitation-enforcement in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/building-purpose-limitation-enforcement in your project. Claude Code loads it when a task matches its description.

How do I install Building Purpose Limitation Enforcement in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill building-purpose-limitation-enforcement -a codex`. Or copy the skill folder (skills/privacy/building-purpose-limitation-enforcement in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/building-purpose-limitation-enforcement in your project. Codex loads it when a task matches its description.

Can I use Building Purpose Limitation Enforcement in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill building-purpose-limitation-enforcement -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/building-purpose-limitation-enforcement, .gemini/skills/building-purpose-limitation-enforcement, .github/skills/building-purpose-limitation-enforcement and .opencode/skills/building-purpose-limitation-enforcement in your project.

What does Building Purpose Limitation Enforcement need to run?

Going by SKILL.md and its folder, Building Purpose Limitation Enforcement needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Building Purpose Limitation Enforcement access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Building Purpose Limitation Enforcement safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Building Purpose Limitation Enforcement use?

Building Purpose Limitation Enforcement is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Building Purpose Limitation Enforcement use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Building Purpose Limitation Enforcement?

Skills that share tags, products or a category with Building Purpose Limitation Enforcement: Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), Tos Clause Scanner (zebbern/claude-code-guide, 4.7k stars), Healthcare Phi Compliance (affaan-m/ECC, 277k stars) and Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Building Purpose Limitation Enforcement?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.