Managing Workflow Secrets
bitwarden/ai-plugins
Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
$ npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install timothywarner-org/claude-code azure-bicep-skill --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/timothywarner-org/claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/azure-bicep-skill .claude/skills/azure-bicep-skill && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azure-bicep-skill" agent skill from https://github.com/timothywarner-org/claude-code/tree/main/.claude/skills/azure-bicep-skill into .claude/skills/azure-bicep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-bicep-skill", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/timothywarner-org/claude-code/tree/main/.claude/skills/azure-bicep-skillType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install timothywarner-org/claude-code azure-bicep-skill --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/timothywarner-org/claude-code.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/azure-bicep-skill .agents/skills/azure-bicep-skill && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azure-bicep-skill" agent skill from https://github.com/timothywarner-org/claude-code/tree/main/.claude/skills/azure-bicep-skill into .agents/skills/azure-bicep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-bicep-skill", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install timothywarner-org/claude-code azure-bicep-skill --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/timothywarner-org/claude-code.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/azure-bicep-skill .cursor/skills/azure-bicep-skill && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azure-bicep-skill" agent skill from https://github.com/timothywarner-org/claude-code/tree/main/.claude/skills/azure-bicep-skill into .cursor/skills/azure-bicep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-bicep-skill", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/timothywarner-org/claude-code.git --path .claude/skills/azure-bicep-skill--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install timothywarner-org/claude-code azure-bicep-skill --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/timothywarner-org/claude-code.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/azure-bicep-skill .gemini/skills/azure-bicep-skill && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azure-bicep-skill" agent skill from https://github.com/timothywarner-org/claude-code/tree/main/.claude/skills/azure-bicep-skill into .gemini/skills/azure-bicep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-bicep-skill", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install timothywarner-org/claude-code azure-bicep-skillInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/timothywarner-org/claude-code.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/azure-bicep-skill .github/skills/azure-bicep-skill && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azure-bicep-skill" agent skill from https://github.com/timothywarner-org/claude-code/tree/main/.claude/skills/azure-bicep-skill into .github/skills/azure-bicep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-bicep-skill", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install timothywarner-org/claude-code azure-bicep-skill --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/timothywarner-org/claude-code.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/azure-bicep-skill .opencode/skills/azure-bicep-skill && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azure-bicep-skill" agent skill from https://github.com/timothywarner-org/claude-code/tree/main/.claude/skills/azure-bicep-skill into .opencode/skills/azure-bicep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-bicep-skill", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azure-bicep-skillA skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
Azure Bicep Skill is an agent skill from timothywarner-org/claude-code. Use when authoring, reviewing, or refactoring Azure Bicep code. Triggers on Bicep module design, Azure Verified Modules (AVM) selection, landing zone IaC, .bicepparam parameter files, what-if deployment validation, bicepconfig.json linting, GitHub Actions Bicep CI with OIDC, Key Vault secret references, and any decision about Bicep file structure, naming, tagging, or scope (resourceGroup, subscription, managementGroup, tenant).
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/AVM-GUIDE.md`).
It sits in DevOps & Cloud, covering Infrastructure as code, Secrets management and Cloud architecture. It works with Bicep, Microsoft Azure and GitHub Actions. The repository describes itself as: Claude Code and Large-Context Reasoning (O'Reilly Live Learning). The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cb80eae. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (PowerShell), which the agent can run.
Shell commands in SKILL.md call:
azFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure Bicep Skill loads about 2.9k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 1,118 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from timothywarner-org/claude-code at commit cb80eae, republished under its MIT licence (© timothywarner-org). 1,118 words, ~2,924 tokens.
.claude/skills/azure-bicep-skill/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Microsoft's proven-practice guidance for production Bicep deployments, distilled. Use this skill whenever Bicep code is being authored, reviewed, or refactored, or when picking between custom modules and Azure Verified Modules.
Trigger this skill when you see any of the following:
.bicep or .bicepparam file being created, edited, or reviewedtargetScope), parameter typing, or output designDo not trigger for: pure ARM JSON work (recommend converting to Bicep first), Terraform-only workflows, Azure portal click-ops walkthroughs.
Azure Verified Modules are Microsoft-published, WAF-aligned, versioned Bicep modules in the public Bicep Registry. They have built-in support for diagnostics, managed identities, private endpoints, RBAC assignments, and tagging. Prefer them over hand-rolled modules.
Why: AVM modules are maintained by the product groups, tested across regions, and updated for breaking API changes. Reinventing them is technical debt you will pay forever.
// Preferred: AVM resource module, version-pinned
module storage 'br/public:avm/res/storage/storage-account:0.14.3' = {
name: 'storage-deployment'
params: {
name: storageAccountName
location: location
skuName: 'Standard_GRS'
tags: tags
}
}See references/AVM-GUIDE.md for the module catalog, the resource (res) vs pattern (ptn) distinction, and version-pinning strategy.
Bicep parameters should be self-documenting and self-validating.
@description('Cost center for chargeback. Must match Finance master list.')
@minLength(4)
@maxLength(8)
param costCenter string
@description('Environment tier. Drives SKU selection and retention policies.')
@allowed([
'dev'
'test'
'prod'
])
param environment string
@description('Admin password. Sourced from Key Vault via getSecret().')
@secure()
param sqlAdminPassword stringWhy: Decorators turn deployment-time mistakes into authoring-time errors. @allowed is your cheapest policy enforcement.
Never accept a secret as a plain parameter. Reference an existing Key Vault and pull the secret via getSecret():
resource kv 'Microsoft.KeyVault/vaults@2023-07-01' existing = {
name: keyVaultName
scope: resourceGroup(keyVaultRgName)
}
module sql 'br/public:avm/res/sql/server:0.10.0' = {
name: 'sql-deployment'
params: {
name: sqlServerName
location: location
administratorLoginPassword: kv.getSecret('sql-admin-password')
}
}Why: Secret values passed as parameters end up in deployment history, CLI scrollback, and CI logs. getSecret() keeps them inside the ARM control plane only.
See references/SECURITY.md for managed identity patterns and OIDC federation.
Follow Cloud Adoption Framework naming: <resource-type>-<workload>-<env>-<region>-<instance>. Use uniqueString() only for globally-scoped resources where collisions are real (storage accounts, Key Vaults, App Service plans hosting custom domains).
var namePrefix = 'kv-${workload}-${environment}-${location}'
var keyVaultName = '${namePrefix}-${take(uniqueString(resourceGroup().id), 4)}'
var mandatoryTags = {
Environment: environment
CostCenter: costCenter
Owner: ownerEmail
Workload: workload
ManagedBy: 'Bicep'
}See references/NAMING-AND-TAGGING.md for the full CAF table and tag governance.
targetScope, even when it's the defaultAlways declare targetScope at the top of the file. The default is resourceGroup, but stating it removes ambiguity for reviewers and prevents accidental scope mismatch when modules are reused.
targetScope = 'subscription'
@description('Landing zone resource group name.')
param resourceGroupName string
resource rg 'Microsoft.Resources/resourceGroups@2023-07-01' = {
name: resourceGroupName
location: location
tags: mandatoryTags
}dependsOnBicep infers dependencies from symbolic references. Manual dependsOn arrays are usually a sign of a missing reference or a circular design.
// Preferred: dependency is implicit via storage.outputs.resourceId
module diagnostics 'modules/diagnostics.bicep' = {
name: 'diag-deployment'
params: {
targetResourceId: storage.outputs.resourceId
logAnalyticsWorkspaceId: laws.outputs.resourceId
}
}Why: Explicit dependsOn masks the actual data flow and breaks when modules are reordered or refactored.
Outputs are read by humans and by downstream modules. They appear in deployment history. Output resource IDs, names, and endpoints. Never output a secret value. If a caller needs a secret, give them the Key Vault URI and let them call getSecret().
az deployment sub what-if `
--location eastus2 `
--template-file main.bicep `
--parameters main.bicepparamRead every Modify, Delete, and DeployIgnored line. what-if is the closest thing Bicep has to a dry-run, and it catches drift, accidental deletes, and parameter mistakes before they become incidents.
When generating or reviewing Bicep, walk this loop:
targetScope matches the intended deployment scope. Subscription scope for landing zones, resourceGroup for workload deployments.@description. Strings have @allowed or length constraints where the value space is bounded. Secrets are @secure() and sourced from Key Vault.roleAssignments parameter.bicep build (syntax), bicep lint (style, with bicepconfig.json), and az deployment <scope> what-if (deployment diff).what-if, requires manual approval for prod, and posts the diff to the PR.Preferred: run all four gates at once via the bundled script.
# All four gates: build + lint + AVM version-pin scan + what-if
./scripts/validate-bicep.ps1 `
-TemplateFile main.bicep `
-ParametersFile main.bicepparam `
-Scope subscription `
-Location eastus2
# Local authoring loop (skip the tenant call)
./scripts/validate-bicep.ps1 `
-TemplateFile main.bicep `
-ParametersFile main.bicepparam `
-SkipWhatIfThe scripts/validate-bicep.ps1 script wraps the four mandatory pre-deploy gates (build, lint, AVM version-pin scan, what-if) and exits non-zero on any failure. Use it as the local pre-commit check and as the CI gate. It is the executable counterpart of this skill's guidance.
Individual gates (when you need to run one in isolation):
# Syntax + transpile check
bicep build main.bicep
# Lint with project rules
bicep lint main.bicep
# Subscription-scope what-if
az deployment sub what-if `
--location eastus2 `
--template-file main.bicep `
--parameters main.bicepparam
# Subscription-scope deploy (only after what-if review)
az deployment sub create `
--location eastus2 `
--template-file main.bicep `
--parameters main.bicepparam
# PSRule for Azure (policy compliance, complementary to the gates above)
Invoke-PSRule -InputPath . -Module 'PSRule.Rules.Azure'| Anti-pattern | Why it's wrong | What to do instead |
|---|---|---|
| Hardcoded subscription ID or tenant ID | Breaks portability, leaks tenant info into source | Use subscription().subscriptionId and tenant().tenantId |
| Inline secret in parameter file | Secret hits git history and CI logs | Key Vault reference via getSecret() |
dependsOn array | Hides real data flow, breaks on refactor | Symbolic reference (module.outputs.x) |
| Custom module for a resource AVM covers | Reinventing maintained code | Use the AVM module, pin the version |
@secure() missing on secret params | Secret value rendered in deployment history | Add @secure(), source from Key Vault |
| Outputting a secret | Secret appears in deployment outputs | Output the Key Vault URI instead |
| JSON ARM where Bicep would work | Loses type safety, decorators, linting | Convert with bicep decompile then refactor |
No targetScope declaration | Ambiguous deployment scope | Declare it explicitly at the top of the file |
uniqueString() on every name | Names become unreadable in the portal | Use only for globally-scoped resources |
| Service principal with client secret | Long-lived credential, rotation burden | Managed identity, or OIDC federation for CI |
When generating Bicep for this environment, assume:
timothywarner-org, OIDC federated credentials, no stored secrets.getSecret() and managed identity.eastus2 unless specified.Environment, CostCenter, Owner, Workload, ManagedBy are mandatory.Deviation from these defaults requires an explicit justification in the response.
scripts/validate-bicep.ps1 - Runs all four pre-deploy gates (build, lint, AVM version-pin scan, what-if) in one shot. PowerShell 7+. Use locally before commit and in CI as a gate. See the Validation commands section above for invocation examples.references/AVM-GUIDE.md - Azure Verified Modules catalog, registry naming, version-pinning strategyAdditional reference files (NAMING-AND-TAGGING.md, SECURITY.md, CI-CD.md) and starter templates under assets/templates/ may be added as the skill matures. Until then, follow the inline guidance in this SKILL.md and the AVM guide.
© timothywarner-org, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts, references) in .claude/skills/azure-bicep-skill of timothywarner-org/claude-code.
Open the folder on GitHubat commit cb80eae
Azure Bicep Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure Bicep Skill this skilltimothywarner-org/claude-code | 224 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Managing Workflow Secretsbitwarden/ai-plugins | 155 | — | ~4k | Automated safety check: Pass | Custom licence | |
| Azure Architecture Autopilotgithub/awesome-copilot | 40k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills | 202 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Azure Preparemicrosoft/GitHub-Copilot-for-Azure | 255 | 1 repos | ~3.2k | Automated safety check: Pass | MIT | |
| Azure To AWSaws/agent-toolkit-for-aws | 2.8k | — | ~5.5k | Automated safety check: Pass | Apache-2.0 |
bitwarden/ai-plugins
Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…
github/awesome-copilot
Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.
thomast1906/github-copilot-agent-skills
Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.
microsoft/GitHub-Copilot-for-Azure
Prepare azd-based Azure projects for deployment: generates azure.yaml, infrastructure (Bicep/Terraform), and Dockerfiles for the Azure Developer CLI (azd) workflow.
aws/agent-toolkit-for-aws
Migrate workloads from Microsoft Azure to AWS. An agent skill from aws/agent-toolkit-for-aws.
giuseppe-trisciuoglio/developer-kit
Provides patterns to deploy ECS tasks and services with GitHub Actions CI/CD.
timothywarner-org/claude-code
Scaffold production-ready Python MCP servers using FastMCP. An agent skill from timothywarner-org/claude-code.
timothywarner-org/claude-code
Audit the CLAUDE.md hierarchy in a repo for drift between what each CLAUDE.md claims and what's actually on disk.
timothywarner-org/claude-code
Ship a Python generative-AI app to Azure the keyless way, using DefaultAzureCredential and azd.
timothywarner-org/claude-code
Score a Python generative-AI app's outputs on groundedness, relevance, coherence, and safety before it ships.
timothywarner-org/claude-code
Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments.
timothywarner-org/claude-code
Review uncommitted local changes in the current git working tree for bugs, smells, missing tests, and CLAUDE.md voice violations.
Works with
Categories
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code. Azure Bicep Skill is an agent skill from timothywarner-org/claude-code. Use when authoring, reviewing, or refactoring Azure Bicep code.
Azure Bicep Skill fits situations like: refactoring Azure Bicep code; bicep module design; azure Verified Modules (AVM) selection; landing zone IaC.
Run `npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a claude-code`. Or copy the skill folder (.claude/skills/azure-bicep-skill in timothywarner-org/claude-code) into .claude/skills/azure-bicep-skill in your project. Claude Code loads it when a task matches its description.
Run `npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a codex`. Or copy the skill folder (.claude/skills/azure-bicep-skill in timothywarner-org/claude-code) into .agents/skills/azure-bicep-skill in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-bicep-skill, .gemini/skills/azure-bicep-skill, .github/skills/azure-bicep-skill and .opencode/skills/azure-bicep-skill in your project.
Going by SKILL.md and its folder, Azure Bicep Skill needs PowerShell for the scripts in its folder and the command-line tools its instructions call (az). Our summary lists: PowerShell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Azure Bicep Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Azure Bicep Skill: Managing Workflow Secrets (bitwarden/ai-plugins, 155 stars), Azure Architecture Autopilot (github/awesome-copilot, 40k stars), APIOps Deployment for Azure APIM (thomast1906/github-copilot-agent-skills, 202 stars) and Azure Prepare (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
timothywarner-org (a GitHub organization) maintains it in timothywarner-org/claude-code, which has 224 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on July 20, 2026.
Source: timothywarner-org/claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.