Plannotator Reference
backnotprop/plannotator
Reference for picking the right Plannotator tool or command for plan review, code review, annotating files and URLs, archived plan decisions and Guided Reviews.
A skill your agent uses when a deeper level of code review is requested.
$ npx skills add openshift-eng/ai-helpers --skill deep-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openshift-eng/ai-helpers deep-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/code-review/skills/deep-review .claude/skills/deep-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "deep-review" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/code-review/skills/deep-review into .claude/skills/deep-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openshift-eng/ai-helpers/tree/main/plugins/code-review/skills/deep-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openshift-eng/ai-helpers --skill deep-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openshift-eng/ai-helpers deep-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/code-review/skills/deep-review .agents/skills/deep-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "deep-review" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/code-review/skills/deep-review into .agents/skills/deep-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openshift-eng/ai-helpers --skill deep-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openshift-eng/ai-helpers deep-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/code-review/skills/deep-review .cursor/skills/deep-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "deep-review" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/code-review/skills/deep-review into .cursor/skills/deep-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openshift-eng/ai-helpers.git --path plugins/code-review/skills/deep-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openshift-eng/ai-helpers --skill deep-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openshift-eng/ai-helpers deep-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/code-review/skills/deep-review .gemini/skills/deep-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "deep-review" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/code-review/skills/deep-review into .gemini/skills/deep-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openshift-eng/ai-helpers deep-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openshift-eng/ai-helpers --skill deep-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/code-review/skills/deep-review .github/skills/deep-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "deep-review" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/code-review/skills/deep-review into .github/skills/deep-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openshift-eng/ai-helpers --skill deep-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openshift-eng/ai-helpers deep-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/code-review/skills/deep-review .opencode/skills/deep-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "deep-review" agent skill from https://github.com/openshift-eng/ai-helpers/tree/main/plugins/code-review/skills/deep-review into .opencode/skills/deep-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "deep-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
deep-reviewA skill your agent uses when a deeper level of code review is requested.
Deep Review is an agent skill from openshift-eng/ai-helpers. Use when a deeper level of code review is requested. Multi-agent panel code review with specialist reviewers and forced runtime reproducers for all BLOCKING bug findings. Optionally posts to GitHub/GitLab as a PENDING review.
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files (for example `references/pr-posting.md`, `references/reproducer-prompt.md` and `references/specialists/adversarial.md`).
It sits in Development, covering Code review. It works with GitHub and GitLab. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghglabrgFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comgitlab.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Deep Review loads about 3.8k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 1,679 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 1,679 words, ~3,807 tokens.
.claude/skills/deep-review/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.Review a branch's changes with parallel specialist subagent reviewers, each examining the code through a different lens. Verify every bug finding with a runtime reproducer. Optionally post to GitHub/GitLab as a PENDING review.
No PR/MR is required — the review works on any branch with commits ahead of its base.
Two execution modes:
--serial): All specialists run inline in the main agent,
one after another. Significantly cheaper because the codebase context
is derived once and shared across all specialists. Trade-off: reviews
run sequentially, and later specialists can see prior specialists'
findings (which may bias their analysis)./code-review:deep-review [flags] [pr-url-or-number]| Argument | Description |
|---|---|
--serial | Run all specialists inline instead of as parallel sub-agents |
--comment | Post the verdict as a PR comment after review. Requires a PR identifier |
--coderabbit | Include CodeRabbit as an external reviewer |
--codex | Include OpenAI Codex as an external reviewer |
-reviewer | Exclude a specialist (e.g., -writer,-qa). All enabled by default |
| pr identifier | GitHub/GitLab PR URL or bare PR number. Optional |
Examples:
/code-review:deep-review — all reviewers, review current branch/code-review:deep-review --serial — cheaper serial mode/code-review:deep-review -qa,-writer — skip QA and Technical Writer/code-review:deep-review --comment 42 — review PR #42, post verdict as comment/code-review:deep-review --coderabbit https://github.com/org/repo/pull/42/code-review:deep-review https://gitlab.com/org/repo/-/merge_requests/7All are enabled unless excluded with -:
| Specialist | Lens | Reproducer? |
|---|---|---|
| bugs | Functional bugs: missing calls, wrong logic, unhandled edge cases | Yes — mandatory |
| adversarial | Break the code: bad inputs, race conditions, boundary values | Yes — mandatory |
| security | Vulnerabilities, credential handling, dependency trust, supply chain integrity | When claiming a concrete exploit |
| architecture | Structural patterns, SOLID, cross-file impact, module boundaries | No |
| consistency | Duplicate helpers, convention drift, style match with existing code | No |
| qa | Test coverage gaps, missing edge-case tests, concrete test suggestions | No |
| writer | Documentation accuracy, staleness, consistency with code changes | No |
bugs adversarial security architecture consistency qa writer
\_______|__________|__________|___________|___________|____|
|
[reproduce] ← bug/security findings only
|
v
panel-arbiter
(final call)Split the argument string on whitespace. Flags (--serial,
--comment, --coderabbit, --codex) set modes. Tokens like
-writer,-qa exclude those specialists (validate against the
roster; unknown names warned and ignored). A PR URL or bare
integer is the PR identifier (for bare integers, detect platform
from git remote). Error if: all specialists excluded, --comment
without PR identifier, or multiple PR identifiers.
If a PR/MR URL or number was provided, parse it before checkout. Do not pass a raw URL as an ID:
github.com/.../pull/N): set
PLATFORM=github, OWNER, REPO, PR_NUMBER=Ngitlab.com/.../-/merge_requests/N): set
PLATFORM=gitlab, PROJECT (group/subgroup/repo path),
MR_IID=N. Prefer OWNER/REPO only when the project path
has exactly two segmentsgit remote -v
(GitHub → gh, GitLab → glab), then set PR_NUMBER or
MR_IID. Derive OWNER/REPO or PROJECT from the matching
remote URLCheck out locally (always quote shell arguments):
GitHub:
gh pr checkout "$PR_NUMBER" --repo "$OWNER/$REPO"GitLab:
glab mr checkout "$MR_IID" --repo "$PROJECT"If glab accepts the full MR URL as a single argument, that is
also fine — but never treat the URL string as $MR_IID for flags
that expect a numeric IID alone.
Hard failure on inaccessible PR/MR: If a PR/MR identifier was provided and checkout or metadata fetch fails (wrong URL, private repo, missing permissions, 404/403), error and exit immediately. Do not fall back to reviewing the current local branch — that silently reviews the wrong code.
Determine the base branch and remote:
gh pr view --json baseRefName or glab mr view --output json)git remote -v (do not hardcode
origin/upstream). Prefer the remote whose fetch URL matches
the PR/MR host and project; otherwise use the remote tracked by
the current branch (git branch -vv), then any remaining remote$BASE_REMOTE/$BASE_BRANCH.
Only fall back to probing main then master
(git ls-remote --heads "$REMOTE" main master) when no target
branch was provided or the target branch was not foundFetch and compute the merge base:
git fetch "$BASE_REMOTE" "$BASE_BRANCH"
MERGE_BASE=$(git merge-base "$BASE_REMOTE/$BASE_BRANCH" HEAD)If no base ref can be determined, error and exit.
Check that the branch has commits ahead of the base. If there are no changes, stop: "No changes found between HEAD and the base branch."
If a PR/MR exists, also fetch its description for context.
When reviewing a PR/MR, check for previous panel review comments:
GitHub:
gh pr view "$PR_NUMBER" --json comments --jq \
'.comments[] | select(.body | contains("Generated by /deep-review") or contains("Generated by /code-review:deep-review")) | {createdAt, body}'GitLab:
glab mr note list "$MR_IID" --repo "$PROJECT" 2>/dev/null \
| rg -n "Generated by /(code-review:)?deep-review" || trueIf prior panel reviews exist, extract their findings and pass them to all specialists and the arbiter as context. Specialists should:
Each specialist has its own prompt in references/specialists/:
| Specialist | Prompt |
|---|---|
| bugs | references/specialists/bugs.md |
| adversarial | references/specialists/adversarial.md |
| security | references/specialists/security.md |
| architecture | references/specialists/architecture.md |
| consistency | references/specialists/consistency.md |
| qa | references/specialists/qa.md |
| writer | references/specialists/writer.md |
Append the findings JSON schema to each specialist prompt:
[
{
"file": "src/example.py",
"line": 42,
"severity": "BLOCKING",
"title": "Short title",
"body": "Description of the issue",
"suggestion": "Recommended action or null",
"reproducer_needed": true
}
]Severity values: BLOCKING | SUGGESTION | NOTE
If no issues found, return an empty array and state what was checked.
Launch all enabled specialist sub-agents in a single message so
they run concurrently, using the Agent tool with
run_in_background: true.
Resolve specialist prompts from the skill directory (repository
root relative):
plugins/code-review/skills/deep-review/references/specialists/{specialist}.md.
Do not use a bare references/specialists/... path — agents may
not share the skill's working directory.
Each sub-agent gets:
plugins/code-review/skills/deep-review/references/specialists/{specialist}.md
for your review instructions."Sub-agents have full read access to the locally checked-out codebase. They explore the code on their own — read files, grep, run git commands, etc.
Sub-agents MUST NOT modify any files, and MUST NOT run any
remote-write git commands (git push, force-push variants,
push to protected branches, or pushes to any remote). They are
read-only reviewers.
Use subagent_type: "general-purpose". Do NOT set the model
parameter.
--serial)Run all enabled specialists inline in the main agent, one after another. Do not launch sub-agents for specialist dispatch. (Phase 4 reproducer sub-agents are still launched even in serial mode — the no-sub-agent constraint applies only to specialists.)
Then for each specialist in roster order, state the specialist name
as a heading, read
plugins/code-review/skills/deep-review/references/specialists/{specialist}.md
for review instructions, review through that lens, and produce
findings in the same JSON format. Context from earlier specialists'
file reads and findings carries over automatically.
Do NOT modify any files, and do NOT push to any remote. Serial mode is read-only, same as parallel.
If external reviewers were requested, launch them in parallel with (or before, in serial mode) the specialist dispatch.
CodeRabbit (--coderabbit):
timeout 300 coderabbit review --agent --base "$MERGE_BASE" 2>&1Codex (--codex):
timeout 300 codex review 2>&1External reviewer output is captured as-is and included in the arbiter's synthesis input as a peer specialist. If a command fails (non-zero exit, tool not found, timeout), record the error and continue — never block the panel on an external tool failure.
After all sub-agents and external reviewers return, verify all
enabled specialists produced findings (or an explicit "no issues"
with what was checked). A valid empty JSON array [] with an
explanation of what was checked is success — do not retry it.
If any specialist returned an error or a missing/malformed result,
re-dispatch it once. If the retry also fails, record the
failure and proceed.
External reviewer failures are non-blocking — note the error and continue.
For every BLOCKING finding with reproducer_needed: true, launch
a reproducer subagent (up to 5 in parallel). See
references/reproducer-prompt.md
for the prompt template and result processing rules.
Perform synthesis directly in the main agent (not a sub-agent).
<details> blocks for
specialist findings (each specialist collapsed with severity
counts). Sections: Disposition, Specialist Findings, Panel
Synthesis, Required Actions, Optional Follow-ups, Stats.
Footer: <sub>Generated by [/code-review:deep-review](https://github.com/openshift-eng/ai-helpers/tree/main/plugins/code-review/skills/deep-review)</sub>.
Include collapsible reproducer details for confirmed BLOCKING bugs.When --comment was passed, follow
references/pr-posting.md to post the
verdict to the PR and optionally create inline review comments.
$OWNER, $REPO, $PR_NUMBER / $PROJECT, $MR_IID must already
be set from Step 1.2.
A change passes when: no unresolved functional bugs, no unrefuted adversarial scenarios, no unmitigated vulnerabilities or supply chain risks, sound architecture, no duplicate helpers, adequate test coverage, documentation consistent with changes, and the panel arbiter has ratified the disposition.
gh/glab not authenticated: Review can still run on a
locally checked-out branch."event" in the initial review creation payload.git push, force-push, or push to protected branches
(main/master) or any other remote. Do not assume remote
names — discover them with git remote -v when needed for reads.© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (references) in plugins/code-review/skills/deep-review of openshift-eng/ai-helpers.
Open the folder on GitHubat commit a627176
Deep Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Deep Review this skillopenshift-eng/ai-helpers | 120 | — | ~3.8k | Automated safety check: Pass | Apache-2.0 | |
| Plannotator Referencebacknotprop/plannotator | 9.2k | — | ~6.3k | Automated safety check: Warn | Apache-2.0 | |
| Greploop Appsmichaelshimeles/skills | 1.3k | 1 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Miro Code Reviewmiroapp/miro-ai | 160 | — | ~4.8k | Automated safety check: Warn | MIT | |
| ReviewdogAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3k | Automated safety check: Pass | Custom licence | |
| Writing Styleumputun/cc-thingz | 484 | — | ~1.3k | Automated safety check: Pass | MIT |
backnotprop/plannotator
Reference for picking the right Plannotator tool or command for plan review, code review, annotating files and URLs, archived plan decisions and Guided Reviews.
michaelshimeles/skills
Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.
miroapp/miro-ai
A skill your agent uses when the user wants to create a visual code review on a Miro board from a pull/merge request (GitHub, GitLab, or any forge), local uncommitted changes, or a branch comparison…
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
umputun/cc-thingz
A skill your agent uses for technical communication - GitHub/GitLab tickets, PR/MR descriptions, issue comments, code review comments, commit messages.
sbusso/claudeclaw
Review and resolve PR issues with Qodo - get AI-powered code review issues and fix them interactively (GitHub, GitLab, Bitbucket, Azure DevOps)
openshift-eng/ai-helpers
Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.
openshift-eng/ai-helpers
Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.
openshift-eng/ai-helpers
Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.
openshift-eng/ai-helpers
Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.
openshift-eng/ai-helpers
Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.
openshift-eng/ai-helpers
Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file
Categories
A skill your agent uses when a deeper level of code review is requested. Deep Review is an agent skill from openshift-eng/ai-helpers. Use when a deeper level of code review is requested.
Deep Review fits situations like: A deeper level of code review is requested; tasks that involve Code review.
Run `npx skills add openshift-eng/ai-helpers --skill deep-review -a claude-code`. Or copy the skill folder (plugins/code-review/skills/deep-review in openshift-eng/ai-helpers) into .claude/skills/deep-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openshift-eng/ai-helpers --skill deep-review -a codex`. Or copy the skill folder (plugins/code-review/skills/deep-review in openshift-eng/ai-helpers) into .agents/skills/deep-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill deep-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deep-review, .gemini/skills/deep-review, .github/skills/deep-review and .opencode/skills/deep-review in your project.
Going by SKILL.md and its folder, Deep Review needs the command-line tools its instructions call (git, gh, glab and rg).
SKILL.md names 2 domains. In commands or code: github.com and gitlab.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Deep Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Deep Review: Plannotator Reference (backnotprop/plannotator, 9.2k stars), Greploop Apps (michaelshimeles/skills, 1.3k stars), Miro Code Review (miroapp/miro-ai, 160 stars) and Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.
Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.