PCI DSS Compliance
wshobson/agents
Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.
Evaluate whether a Stripe dispute is economical to contest, then gather evidence and submit only when approved.
$ npx skills add OpenClaudia/openclaudia-skills --skill stripe-dispute -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OpenClaudia/openclaudia-skills stripe-dispute --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OpenClaudia/openclaudia-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/stripe-dispute .claude/skills/stripe-dispute && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "stripe-dispute" agent skill from https://github.com/OpenClaudia/openclaudia-skills/tree/main/skills/stripe-dispute into .claude/skills/stripe-dispute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-dispute", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OpenClaudia/openclaudia-skills/tree/main/skills/stripe-disputeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OpenClaudia/openclaudia-skills --skill stripe-dispute -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OpenClaudia/openclaudia-skills stripe-dispute --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenClaudia/openclaudia-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/stripe-dispute .agents/skills/stripe-dispute && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "stripe-dispute" agent skill from https://github.com/OpenClaudia/openclaudia-skills/tree/main/skills/stripe-dispute into .agents/skills/stripe-dispute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-dispute", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OpenClaudia/openclaudia-skills --skill stripe-dispute -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OpenClaudia/openclaudia-skills stripe-dispute --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenClaudia/openclaudia-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/stripe-dispute .cursor/skills/stripe-dispute && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "stripe-dispute" agent skill from https://github.com/OpenClaudia/openclaudia-skills/tree/main/skills/stripe-dispute into .cursor/skills/stripe-dispute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-dispute", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OpenClaudia/openclaudia-skills.git --path skills/stripe-dispute--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OpenClaudia/openclaudia-skills --skill stripe-dispute -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OpenClaudia/openclaudia-skills stripe-dispute --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenClaudia/openclaudia-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/stripe-dispute .gemini/skills/stripe-dispute && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "stripe-dispute" agent skill from https://github.com/OpenClaudia/openclaudia-skills/tree/main/skills/stripe-dispute into .gemini/skills/stripe-dispute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-dispute", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OpenClaudia/openclaudia-skills stripe-disputeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OpenClaudia/openclaudia-skills --skill stripe-dispute -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OpenClaudia/openclaudia-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/stripe-dispute .github/skills/stripe-dispute && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "stripe-dispute" agent skill from https://github.com/OpenClaudia/openclaudia-skills/tree/main/skills/stripe-dispute into .github/skills/stripe-dispute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-dispute", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OpenClaudia/openclaudia-skills --skill stripe-dispute -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OpenClaudia/openclaudia-skills stripe-dispute --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OpenClaudia/openclaudia-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/stripe-dispute .opencode/skills/stripe-dispute && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "stripe-dispute" agent skill from https://github.com/OpenClaudia/openclaudia-skills/tree/main/skills/stripe-dispute into .opencode/skills/stripe-dispute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "stripe-dispute", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
stripe-disputeEvaluate whether a Stripe dispute is economical to contest, then gather evidence and submit only when approved.
Stripe Dispute is an agent skill from OpenClaudia/openclaudia-skills. Evaluate whether a Stripe dispute is economical to contest, then gather evidence and submit only when approved. Use for Stripe disputes, chargebacks, counter-disputes, evidence packages, or Stripe dispute IDs.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance. It works with Stripe. The repository describes itself as: 77 open-source marketing skills for Claude Code, Codex, and other AI coding agents. SEO, content, email, ads, analytics, and growth. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 28bf209. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3nodeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.stripe.comfiles.stripe.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
STRIPE_SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Stripe Dispute loads about 3.3k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 1,238 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from OpenClaudia/openclaudia-skills at commit 28bf209, republished under its MIT licence (© OpenClaudia). 1,238 words, ~3,328 tokens.
.claude/skills/stripe-dispute/SKILL.md (or your agent's skills folder).Evaluate the economics first. When contesting is justified and approved, build an evidence package and submit it to Stripe. Works for any SaaS using Stripe and a user database with login or usage logs.
Use this skill when the user:
du_*) and asks to "counter" / "rebut" / "fight" itfraudulent, product_not_received, product_unacceptable, or subscription_canceledSTRIPE_SECRET_KEY=sk_live_... # Stripe restricted/secret key with disputes:write scope
DATABASE_URL=postgres://... # READ-ONLY connection to your app's user database (optional but recommended)
TERMS_URL=https://yoursite.com/terms # URL to your published cancellation/refund policy
EVIDENCE_DIR=~/disputes # Where to save the per-customer evidence foldersDatabase safety: all queries are SELECT-only. Never let this skill issue UPDATE/DELETE/INSERT.
The user provides any of:
du_xxxxx) — preferredch_xxxxx or py_xxxxx)Accepting a dispute can be the correct outcome. Never submit evidence merely because a case exists.
evidence_details.submission_count > 0. Separate initial purchases
from renewals and narrow to the same reason when the sample permits. Report wins,
losses, open cases, and sample size. State when no exact-match precedent exists.curl -s -u "$STRIPE_SECRET_KEY:" \
"https://api.stripe.com/v1/disputes/$DISPUTE_ID" | python3 -m json.toolExtract: amount, reason, charge, evidence_details.due_by, evidence_details.submission_count, status.
If submission_count > 0 the dispute has already been countered — STOP and warn the user.
# Charge → tells you the payment method, risk score, billing details, customer ID
curl -s -u "$STRIPE_SECRET_KEY:" "https://api.stripe.com/v1/charges/$CHARGE_ID"
# Customer → name, email, default payment source
curl -s -u "$STRIPE_SECRET_KEY:" "https://api.stripe.com/v1/customers/$CUSTOMER_ID"
# All invoices for the customer → look for previously-undisputed payments
curl -s -u "$STRIPE_SECRET_KEY:" \
"https://api.stripe.com/v1/invoices?customer=$CUSTOMER_ID&limit=100"
# Subscription (if recurring)
curl -s -u "$STRIPE_SECRET_KEY:" "https://api.stripe.com/v1/subscriptions/$SUB_ID"Prior undisputed payments on the same card are useful corroboration for fraudulent
claims. Always count them, but do not treat them as proof by themselves.
Adapt these queries to your schema. A useful evidence shape:
-- User profile and self-reported cancel reason
SELECT id, email, created_at, plan_tier, stripe_customer_id,
cancel_reason, cancelled_at, delete_reason
FROM users WHERE email ILIKE :email;
-- Login activity (timestamps + country + device)
SELECT created_at, country_code, device
FROM user_activity WHERE user_id = :uid ORDER BY created_at;
-- Things the customer created/used in your product
SELECT name, type, created_at, updated_at
FROM projects WHERE user_id = :uid AND deleted = false ORDER BY created_at;
-- Checkout / payment-related actions (proves intent)
SELECT timestamp, endpoint, payload FROM action_logs
WHERE user_id = :uid
AND endpoint ~* '(subscribe|checkout|stripe|upgrade|pay)'
ORDER BY timestamp DESC;For product_not_received claims, check the user's self-reported cancel_reason. If they
cancelled citing "Poor user experience" or anything admitting use, that field directly
contradicts the claim. Quote it verbatim, but do not infer a win rate from one fact.
FOLDER="$EVIDENCE_DIR/$(echo $CUSTOMER_NAME | tr '[:upper:] ' '[:lower:]-')-$(date +%Y-%m)"
mkdir -p "$FOLDER"
# Invoice PDFs (URLs come from the Stripe invoice objects)
curl -sL "$INVOICE_PDF_URL" -o "$FOLDER/invoice.pdf"Using Playwright (Node):
node -e "
const { chromium } = require('playwright');
(async () => {
const browser = await chromium.launch();
const page = await browser.newPage({ viewport: { width: 1280, height: 900 } });
await page.goto(process.env.TERMS_URL, { waitUntil: 'networkidle' });
await page.pdf({ path: process.argv[1], format: 'A4', printBackground: true });
await browser.close();
})();
" "$FOLDER/cancellation_policy.pdf"Build a concise, reviewable HTML activity log, then convert it to PDF with WeasyPrint:
from weasyprint import HTML
HTML('activity_log.html').write_pdf('activity_log.pdf')HTML must include <meta charset="UTF-8"> to avoid mangled characters in customer names/addresses.
A reviewable layout:
fraudulent by extension)cancel_reason against the stated dispute reason, if they contradict.Prefer concrete numbers over adjectives. "29 login sessions, 3 named projects, 29,960 credits consumed" is more useful than "used extensively."
open "$FOLDER"Display the rebuttal text, the evidence files, and your win-probability assessment. Wait for explicit user approval.
Files go to files.stripe.com, NOT api.stripe.com — different host:
curl -s -u "$STRIPE_SECRET_KEY:" \
-F "purpose=dispute_evidence" \
-F "file=@$FOLDER/activity_log.pdf" \
https://files.stripe.com/v1/filesReturns {"id": "file_xxx", ...}. Capture the id — that's what you reference in evidence fields.
One file_id per dispute. Stripe rejects with 400 "That file is already attached to something else" if you try to reuse a file_id across disputes (especially for service_documentation). When fighting N disputes for the same customer, upload N copies of every shared PDF — same content, fresh file_id each time.
submit=true is final)curl -s -u "$STRIPE_SECRET_KEY:" \
-X POST "https://api.stripe.com/v1/disputes/$DISPUTE_ID" \
-d "evidence[uncategorized_text]=$REBUTTAL_TEXT" \
-d "evidence[uncategorized_file]=$ACTIVITY_LOG_FILE_ID" \
-d "evidence[receipt]=$INVOICE_FILE_ID" \
-d "evidence[cancellation_policy]=$TERMS_FILE_ID" \
-d "evidence[cancellation_policy_disclosure]=$CANCEL_DISCLOSURE_TEXT" \
-d "evidence[refund_policy]=$TERMS_FILE_ID" \
-d "evidence[refund_policy_disclosure]=$REFUND_DISCLOSURE_TEXT" \
-d "evidence[cancellation_rebuttal]=$CANCEL_REBUTTAL_TEXT" \
-d "evidence[access_activity_log]=$ACCESS_LOG_SUMMARY" \
-d "evidence[service_date]=$SERVICE_START_DATE" \
-d "evidence[product_description]=$PRODUCT_DESCRIPTION" \
-d "evidence[customer_email_address]=$CUSTOMER_EMAIL" \
-d "evidence[customer_name]=$CUSTOMER_NAME" \
-d "evidence[customer_purchase_ip]=$PURCHASE_IP" \
-d "evidence[billing_address]=$BILLING_ADDRESS" \
-d "submit=true" \
"https://api.stripe.com/v1/disputes/$DISPUTE_ID"Verify the response:
status should be under_reviewevidence_details.has_evidence should be trueevidence_details.submission_count should be 1fraudulentGoal: prove the cardholder made the purchase.
normalproduct_not_receivedGoal: prove delivery + use.
product_unacceptableGoal: show the product matched its description and the customer used it.
product_not_received PLUS your terms-of-service language about quality / refund policysubscription_canceledGoal: prove the customer never cancelled (or cancelled after the renewal).
cancel_at_period_end=false at the renewal dateuncategorized_text[Customer name] created a [Product name] account on [date] via [auth method] and subscribed to [plan] ($[amount]/[interval]) using the same [card brand]. The first [N] payment(s) were never disputed. The customer actively used the service: [N] login sessions from [country] on [device], [N] items created ([list]), and [N] [units] consumed. The disputed charge is the [renewal/initial] payment on [date]. The subscription was [status] and remains [active/cancelled]. The customer never contacted support to cancel or request a refund. Our cancellation and refund policies are published at [TERMS_URL]. This is not a fraudulent transaction — it is a legitimate purchase from the cardholder who [made/has made] [N] other undisputed payments on this account.
cancellation_policy_disclosureOur cancellation policy is disclosed at [TERMS_URL]. Subscribers may cancel at any time and retain access through the end of their billing cycle. This customer never cancelled.
refund_policy_disclosureOur refund policy is disclosed at [TERMS_URL]. We offer a [N]-day money-back guarantee. The customer did not request a refund within that window, nor at any time.
files.stripe.com, NOT api.stripe.comsubmit=true is finalevidence_details.due_by (unix timestamp). After that you can no longer submitCustomer signs up, uses product briefly, cancels within hours citing "Poor user experience" in your in-app cancel form, then files a chargeback days later claiming "product not received."
The cancel form's reason directly contradicts the chargeback claim. Quote it word-for-word in the rebuttal, while still applying the fee and historical-outcome decision gate.
Always check users.cancel_reason (or your equivalent) FIRST when the dispute reason is product_not_received or product_unacceptable.
© OpenClaudia, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/stripe-dispute of OpenClaudia/openclaudia-skills.
Open the folder on GitHubat commit 28bf209
Stripe Dispute next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Stripe Dispute this skillOpenClaudia/openclaudia-skills | 713 | — | ~3.3k | Automated safety check: Pass | MIT | |
| PCI DSS Compliancewshobson/agents | 40k | 11 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Privacy Pagamenticcplugins/awesome-claude-code-plugins | 970 | — | ~845 | Automated safety check: Pass | Apache-2.0 | |
| Firecrawl Build Onboardingfirecrawl/firecrawl | 190k | 1 repos | ~1.4k | Automated safety check: Notes | ISC | |
| Minimax PDFpoco-ai/poco-claw | 1.4k | 6 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Get API Docs with chubandrewyng/context-hub | 14k | 1 repos | ~775 | Automated safety check: Pass | MIT |
wshobson/agents
Reference for building payment systems that meet PCI DSS: the 12 requirements, merchant levels, data that must never be stored, tokenization and encryption.
ccplugins/awesome-claude-code-plugins
Protegge dati di pagamento e abbonamenti quando un sito/app gestisce checkout, carte, subscription o fatturazione.
firecrawl/firecrawl
Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.
poco-ai/poco-claw
A skill your agent uses when visual quality and design identity matter for a PDF.
andrewyng/context-hub
Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.
fossasia/eventyay
A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.
OpenClaudia/openclaudia-skills
Build an interactive competitive-traffic report for any company and its rivals — monthly visits (SimilarWeb), organic search traffic and Domain Rating (Ahrefs) — as one self-contained HTML page with…
OpenClaudia/openclaudia-skills
Score how hard a keyword is to rank for in the AI-search era — page-level URL Rating of real competitors (not just domain DR), Ahrefs keyword difficulty, and whether a given site already ranks or is…
OpenClaudia/openclaudia-skills
Audit EVERY Google Search Console property at once — rank all sites by clicks and impressions with period-over-period deltas, then diff keywords per site to surface what is newly ranking, rising…
OpenClaudia/openclaudia-skills
Fetch website traffic estimates (monthly visits, traffic sources, top countries, keywords, engagement, ranks) for any domain from SimilarWeb.
OpenClaudia/openclaudia-skills
Manages Ahrefs API usage in Python using ahrefs-python library.
OpenClaudia/openclaudia-skills
Design, plan, and analyze A/B tests with statistical rigor. An agent skill from OpenClaudia/openclaudia-skills.
Works with
Categories
Evaluate whether a Stripe dispute is economical to contest, then gather evidence and submit only when approved. Stripe Dispute is an agent skill from OpenClaudia/openclaudia-skills. Evaluate whether a Stripe dispute is economical to contest, then gather evidence and submit only when approved.
Stripe Dispute fits situations like: stripe disputes; counter-disputes; evidence packages; stripe dispute IDs.
Run `npx skills add OpenClaudia/openclaudia-skills --skill stripe-dispute -a claude-code`. Or copy the skill folder (skills/stripe-dispute in OpenClaudia/openclaudia-skills) into .claude/skills/stripe-dispute in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OpenClaudia/openclaudia-skills --skill stripe-dispute -a codex`. Or copy the skill folder (skills/stripe-dispute in OpenClaudia/openclaudia-skills) into .agents/skills/stripe-dispute in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OpenClaudia/openclaudia-skills --skill stripe-dispute -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stripe-dispute, .gemini/skills/stripe-dispute, .github/skills/stripe-dispute and .opencode/skills/stripe-dispute in your project.
Going by SKILL.md and its folder, Stripe Dispute needs the command-line tools its instructions call (curl, python3 and node) and credentials named STRIPE_SECRET_KEY. Our summary lists: Python 3; A credential in STRIPE_SECRET_KEY.
SKILL.md names 2 domains. In commands or code: api.stripe.com and files.stripe.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Stripe Dispute is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Stripe Dispute: PCI DSS Compliance (wshobson/agents, 40k stars), Privacy Pagamenti (ccplugins/awesome-claude-code-plugins, 970 stars), Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars) and Minimax PDF (poco-ai/poco-claw, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OpenClaudia (a GitHub organization) maintains it in OpenClaudia/openclaudia-skills, which has 713 GitHub stars. The repository holds 74 skills in this directory. The repository was last updated on September 18, 2026.
Source: OpenClaudia/openclaudia-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.