Infrastructure Setup
pavel-molyanov/molyanov-ai-dev
Provides project infrastructure conventions and review criteria for local setup, Docker, Git hooks, CI/CD, service delivery, release artifacts, monitoring, backups, and operations.
Mass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills.
$ npx skills add uphiago/recon-skills --skill source-leak-hunt -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install uphiago/recon-skills source-leak-hunt --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/source-leak-hunt .claude/skills/source-leak-hunt && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "source-leak-hunt" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/source-leak-hunt into .claude/skills/source-leak-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-leak-hunt", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/uphiago/recon-skills/tree/main/recon/source-leak-huntType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add uphiago/recon-skills --skill source-leak-hunt -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install uphiago/recon-skills source-leak-hunt --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/recon/source-leak-hunt .agents/skills/source-leak-hunt && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "source-leak-hunt" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/source-leak-hunt into .agents/skills/source-leak-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-leak-hunt", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill source-leak-hunt -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install uphiago/recon-skills source-leak-hunt --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/recon/source-leak-hunt .cursor/skills/source-leak-hunt && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "source-leak-hunt" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/source-leak-hunt into .cursor/skills/source-leak-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-leak-hunt", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/uphiago/recon-skills.git --path recon/source-leak-hunt--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add uphiago/recon-skills --skill source-leak-hunt -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install uphiago/recon-skills source-leak-hunt --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/recon/source-leak-hunt .gemini/skills/source-leak-hunt && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "source-leak-hunt" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/source-leak-hunt into .gemini/skills/source-leak-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-leak-hunt", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install uphiago/recon-skills source-leak-huntInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add uphiago/recon-skills --skill source-leak-hunt -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/recon/source-leak-hunt .github/skills/source-leak-hunt && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "source-leak-hunt" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/source-leak-hunt into .github/skills/source-leak-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-leak-hunt", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill source-leak-hunt -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install uphiago/recon-skills source-leak-hunt --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/recon/source-leak-hunt .opencode/skills/source-leak-hunt && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "source-leak-hunt" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/source-leak-hunt into .opencode/skills/source-leak-hunt/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "source-leak-hunt", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
source-leak-huntMass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills.
Source Leak Hunt is an agent skill from uphiago/recon-skills. Mass scan for exposed env files, backups, and git configs.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl, grep
It sits in DevOps & Cloud, covering Backup and disaster recovery. It works with Git, PHP, Docker and SQL. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DB_PASSWORDAUTH_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires curl, grep
From compatibility in the SKILL.md frontmatter.
Source Leak Hunt loads about 2.2k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 427 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
s scanning for exposed sensitive files (`.env`, `.git/config`, `wp-config.php.bak`, `debug.log`, `backup.sql`, `phpinfo.for path in .env .git/config wp-config.php.bak debug.log backup.sql info.php phpinfo.php \.env.backup .env.local .env.production wp-config.php~ .git/HEAD .backup.sql \| `.env` | DB creds, API keys, app secrets | Critical || `.env.backup` / `.env.local` | Same as .env, alternate names | Critical |".env"".env.backup"".env.local"".env.production"PATTERNS[".env"]='DB_|APP_|_KEY|_SECRET|DATABASE|PASSWORD|TOKEN'Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 427 words, ~2,219 tokens.
.claude/skills/source-leak-hunt/SKILL.md (or your agent's skills folder).Mass scanning for exposed sensitive files (.env, .git/config, wp-config.php.bak, debug.log, backup.sql, phpinfo.php, Dockerfile, etc.) with content-based false positive filtering. Source leaks are the second most common finding (~7% of targets) after WordPress user enumeration.
skill_view(name='wp-mass-recon') confirms a target is alive.skill_view(name='js-secrets-extraction') for client-side secrets.terminal with curl.$OUTDIR/leaks/.# Quick scan single target (20 paths)
TARGET="https://example.com"
for path in .env .git/config wp-config.php.bak debug.log backup.sql info.php phpinfo.php \
.env.backup .env.local .env.production wp-config.php~ .git/HEAD .backup.sql \
docker-compose.yml Dockerfile .DS_Store robots.txt sitemap.xml; do
code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 --connect-timeout 5 "$TARGET/$path")
[[ "$code" == "200" ]] && echo "HTTP 200: $TARGET/$path"
sleep 0.2
done| Path | What It Exposes | Severity |
|---|---|---|
.env | DB creds, API keys, app secrets | Critical |
wp-config.php.bak | MySQL root password, salts | Critical |
.git/config | Repository URL, credentials | High |
debug.log | PHP errors, server paths, SQL queries | High |
backup.sql | Full database dump | Critical |
info.php / phpinfo.php | PHP config, disable_functions, server env | High |
docker-compose.yml | Service architecture, env vars | Medium |
Dockerfile | Build config, exposed ports | Low |
.env.backup / .env.local | Same as .env, alternate names | Critical |
wp-config.php~ | Vim swap of wp-config | Critical |
.DS_Store | Directory listing (macOS) | Low |
error_log | PHP error log (can be multi-MB, full of paths/queries) | High |
#!/bin/bash
URLS_FILE="$1" # One URL per line
OUTDIR="$OUTDIR/leaks"
mkdir -p "$OUTDIR"
PATHS=(
".env"
".git/config"
"wp-config.php.bak"
"debug.log"
"backup.sql"
"info.php"
"phpinfo.php"
".env.backup"
".env.local"
".env.production"
"wp-config.php~"
".git/HEAD"
"docker-compose.yml"
"Dockerfile"
".DS_Store"
"robots.txt"
"sitemap.xml"
"error_log"
"wp-content/debug.log"
".backup.sql"
)
# Content verification patterns (avoids SPA catch-all false positives)
declare -A PATTERNS
PATTERNS[".env"]='DB_|APP_|_KEY|_SECRET|DATABASE|PASSWORD|TOKEN'
PATTERNS["wp-config.php.bak"]='DB_NAME|DB_PASSWORD|AUTH_KEY'
PATTERNS[".git/config"]='\[core\]'
PATTERNS["debug.log"]='PHP|ERROR|WARNING|Stack trace'
PATTERNS["backup.sql"]='CREATE TABLE|INSERT INTO|DROP TABLE'
PATTERNS["info.php"]='PHP Version|phpinfo'
PATTERNS["phpinfo.php"]='PHP Version|phpinfo'
PATTERNS[".env.backup"]='DB_|APP_|_KEY|_SECRET'
PATTERNS[".env.local"]='DB_|APP_|_KEY|_SECRET'
PATTERNS[".env.production"]='DB_|APP_|_KEY|_SECRET'
PATTERNS["wp-config.php~"]='DB_NAME|DB_PASSWORD'
PATTERNS["error_log"]='PHP|ERROR|Stack trace'
scan_target() {
local url="$1"
local domain
domain=$(echo "$url" | sed 's|https\?://||' | sed 's|/.*||')
for path in "${PATHS[@]}"; do
local full_url="${url}/${path}"
local code
code=$(curl -sk -o /tmp/leak_check_$$.tmp -w "%{http_code}" --max-time 5 --connect-timeout 5 "$full_url" 2>/dev/null)
if [[ "$code" == "200" ]]; then
local content
content=$(head -c 2000 /tmp/leak_check_$$.tmp 2>/dev/null)
local pattern="${PATTERNS[$path]}"
if [[ -n "$pattern" ]] && echo "$content" | grep -qiE "$pattern"; then
echo "[LEAK] $full_url (VERIFIED: $path)"
echo "$full_url" >> "$OUTDIR/${domain}_leaks.txt"
cp /tmp/leak_check_$$.tmp "$OUTDIR/${domain}_${path//\//_}.content" 2>/dev/null
elif [[ -z "$pattern" ]]; then
# No pattern check — just log HTTP 200 (e.g., robots.txt)
local size=$(wc -c < /tmp/leak_check_$$.tmp)
if [[ "$size" -gt 50 ]]; then
echo "[INFO] $full_url (HTTP 200, ${size} bytes)"
echo "$full_url" >> "$OUTDIR/${domain}_leaks.txt"
fi
fi
fi
sleep 0.3
done
rm -f /tmp/leak_check_$$.tmp
}
export -f scan_target
export OUTDIR
export PATHS
# Run 30 parallel workers
cat "$URLS_FILE" | xargs -P 30 -I {} bash -c 'scan_target "{}"'
echo "[+] Done. Results in $OUTDIR/"# From .env files
grep -rhE '(DB_|APP_|_KEY|_SECRET|DATABASE|PASSWORD|TOKEN|SECRET)=' $OUTDIR/leaks/*.env*.content 2>/dev/null | sort -u
# From wp-config backups
grep -rhE 'DB_NAME|DB_USER|DB_PASSWORD|DB_HOST|AUTH_KEY' $OUTDIR/leaks/*wp-config* 2>/dev/null
# From .git/config
grep -rh 'url = ' $OUTDIR/leaks/*.git_config.content 2>/dev/null
# From SQL dumps
grep -rhE 'CREATE TABLE|INSERT INTO' $OUTDIR/leaks/*backup* $OUTDIR/leaks/*.sql* 2>/dev/null | head -20for f in $OUTDIR/leaks/*_leaks.txt; do
count=$(wc -l < "$f")
[[ "$count" -ge 3 ]] && echo "$(basename "$f" _leaks.txt): $count leaks"
done | sort -t: -k2 -rnerror_log files can be 1.7MB+. Fetch in chunks or use curl -r 0-5000 for sampling..git/HEAD returning 200 with a legitimate git hash. Verify .git/config first.<title>, or same keyword like "for sale" or "parked"). Add early-exit: if /robots.txt and /.env both return 200 with near-identical HTML, mark domain as parked and skip further source-leak checks..env leak MUST contain at least one of: DB_, APP_, _KEY, _SECRET, PASSWORD, TOKEN.wp-config.php.bak leak MUST contain DB_NAME and DB_PASSWORD..git/config leak MUST contain [core] section header.CREATE TABLE) or DML (INSERT INTO) statements.# bfac — multi-level backup file detection
bfac --url https://target.com \
--detection-technique all \
--level 3 \
--exclude-status-codes 404,500
# Wayback Machine — historical sensitive files
waybackurls https://target.com | grep -iE \
"\.(xls|xlsx|csv|sql|db|bak|backup|old|tar\.gz|tgz|zip|7z|rar|pdf|pem|key|crt|env|json|yml|yaml|conf|config|git|htpasswd|log|dump|DS_Store)" \
| sort -u > sensitive_wayback.txt
# Check which are still accessible
cat sensitive_wayback.txt | httpx -silent -mc 200 -o accessible_sensitive.txt
# Common backup patterns to probe
for ext in bak old backup zip tar.gz tgz sql dump; do
curl --max-time 30 --connect-timeout 10 -skI "https://target.com/backup.$ext" | head -1
curl --max-time 30 --connect-timeout 10 -skI "https://target.com/site.$ext" | head -1
curl --max-time 30 --connect-timeout 10 -skI "https://target.com/target.$ext" | head -1
sleep 0.3
done# Google Sheets — internal spreadsheets often left public
# Manual search:
# site:docs.google.com/spreadsheets "target.com"
# site:docs.google.com/spreadsheets "@target.com"
# site:docs.google.com/spreadsheets "password" "target.com"
# Google Drive files
# site:drive.google.com "target.com" "confidential"
# Firebase/Firestore URLs in public search results
# site:firebaseio.com "target.com"
# site:firestore.googleapis.com "target-app"
# GCP buckets
# site:storage.googleapis.com "target"
# site:storage.cloud.google.com "target"© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in recon/source-leak-hunt of uphiago/recon-skills.
Open the folder on GitHubat commit 1260244
Source Leak Hunt next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Source Leak Hunt this skilluphiago/recon-skills | 1.3k | — | ~2.2k | Automated safety check: Notes | MIT | |
| Infrastructure Setuppavel-molyanov/molyanov-ai-dev | 297 | — | ~1.9k | Automated safety check: Notes | MIT | |
| Deploying Postgres K8saiskillstore/marketplace | 430 | — | ~2k | Automated safety check: Pass | None | |
| Scanning Containers With Trivy In Cicdmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Frontmcp Production Readinessagentfront/frontmcp | 146 | — | ~6.5k | Automated safety check: Pass | Apache-2.0 | |
| Cloud Infra Supply Chainzhaji2333/CkSKILLS | 114 | — | ~688 | Automated safety check: Warn | MIT |
pavel-molyanov/molyanov-ai-dev
Provides project infrastructure conventions and review criteria for local setup, Docker, Git hooks, CI/CD, service delivery, release artifacts, monitoring, backups, and operations.
aiskillstore/marketplace
Deploys PostgreSQL on Kubernetes using the CloudNativePG operator with automated failover.
mukul975/Anthropic-Cybersecurity-Skills
Integrates Aqua Security's Trivy scanner into CI/CD pipelines to detect OS package and application dependency CVEs, Dockerfile misconfigurations, and issues in filesystems or git repositories, and…
agentfront/frontmcp
Pre-production audit, hardening, and go-live checklists for FrontMCP servers.
zhaji2333/CkSKILLS
当目标涉及云资产(对象存储/云元数据/Serverless)、容器/K8s、运维面板(宝塔/Grafana/Zabbix/Jenkins/GitLab/Nacos等)、消息队列/缓存中间件、CI/CD流水线、第三方回调集成、依赖组件CVE、信息泄露配置时调用。负责未授权访问、弱口令、云配置错误、供应链漏洞与敏感信息挖掘。
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
uphiago/recon-skills
Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.
uphiago/recon-skills
Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.
uphiago/recon-skills
Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
uphiago/recon-skills
A skill your agent uses when starting or restructuring an authorized external web and API assessment.
uphiago/recon-skills
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
uphiago/recon-skills
A skill your agent uses when protected HTTP routes return 401 or 403.
Categories
Mass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills. Source Leak Hunt is an agent skill from uphiago/recon-skills. Mass scan for exposed env files, backups, and git configs.
Source Leak Hunt fits situations like: tasks that involve Backup and disaster recovery.
Run `npx skills add uphiago/recon-skills --skill source-leak-hunt -a claude-code`. Or copy the skill folder (recon/source-leak-hunt in uphiago/recon-skills) into .claude/skills/source-leak-hunt in your project. Claude Code loads it when a task matches its description.
Run `npx skills add uphiago/recon-skills --skill source-leak-hunt -a codex`. Or copy the skill folder (recon/source-leak-hunt in uphiago/recon-skills) into .agents/skills/source-leak-hunt in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill source-leak-hunt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/source-leak-hunt, .gemini/skills/source-leak-hunt, .github/skills/source-leak-hunt and .opencode/skills/source-leak-hunt in your project.
Going by SKILL.md and its folder, Source Leak Hunt needs the command-line tools its instructions call (curl and git) and credentials named DB_PASSWORD and AUTH_KEY. Our summary lists: Docker; A credential in AUTH_KEY. Compatibility (from SKILL.md): Requires curl, grep.
SKILL.md contains no URLs. Its commands use curl and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Source Leak Hunt is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Source Leak Hunt: Infrastructure Setup (pavel-molyanov/molyanov-ai-dev, 297 stars), Deploying Postgres K8s (aiskillstore/marketplace, 430 stars), Scanning Containers With Trivy In Cicd (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Frontmcp Production Readiness (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,293 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.
Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.