Secrets Vault Manager
alirezarezvani/claude-skills
A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…
Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm).
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-secret-provider --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ak-dev-new-secret-provider .claude/skills/ak-dev-new-secret-provider && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ak-dev-new-secret-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-secret-provider into .claude/skills/ak-dev-new-secret-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-secret-provider", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-secret-providerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-secret-provider --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/ak-dev-new-secret-provider .agents/skills/ak-dev-new-secret-provider && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ak-dev-new-secret-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-secret-provider into .agents/skills/ak-dev-new-secret-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-secret-provider", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-secret-provider --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/ak-dev-new-secret-provider .cursor/skills/ak-dev-new-secret-provider && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ak-dev-new-secret-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-secret-provider into .cursor/skills/ak-dev-new-secret-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-secret-provider", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yaalalabs/agent-kernel.git --path .agents/skills/ak-dev-new-secret-provider--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-secret-provider --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/ak-dev-new-secret-provider .gemini/skills/ak-dev-new-secret-provider && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ak-dev-new-secret-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-secret-provider into .gemini/skills/ak-dev-new-secret-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-secret-provider", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-secret-providerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/ak-dev-new-secret-provider .github/skills/ak-dev-new-secret-provider && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ak-dev-new-secret-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-secret-provider into .github/skills/ak-dev-new-secret-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-secret-provider", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yaalalabs/agent-kernel ak-dev-new-secret-provider --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/ak-dev-new-secret-provider .opencode/skills/ak-dev-new-secret-provider && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ak-dev-new-secret-provider" agent skill from https://github.com/yaalalabs/agent-kernel/tree/develop/.agents/skills/ak-dev-new-secret-provider into .opencode/skills/ak-dev-new-secret-provider/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ak-dev-new-secret-provider", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ak-dev-new-secret-providerStep-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm).
Ak Dev New Secret Provider is an agent skill from yaalalabs/agent-kernel. Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm). Use this skill when you need a new managed secret store (e.g. AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, HashiCorp Vault) addressable by a short secret.provider.type name. Covers the SecretProvider contract, addressing, factory registration, configuration, optional dependencies, the SecretProviderContract test suite, deployment IAM wiring, and docs.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Test generation and Deployment. It works with Amazon Web Services, Azure Key Vault, Google Cloud and HashiCorp Vault. The repository describes itself as: The Operating System for Scalable Enterprise AI Agents - Run, orchestrate, and deploy Compliant Enterprise AI Agents at scale across frameworks, without lock-in, rewrites or… The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 97fa8d9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvmakeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OPENAI_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ak Dev New Secret Provider loads about 2.6k tokens when it runs. Until then it costs about 132 tokens; SKILL.md has 1,045 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yaalalabs/agent-kernel at commit 97fa8d9, republished under its Apache-2.0 licence (© yaalalabs). 1,045 words, ~2,581 tokens.
.claude/skills/ak-dev-new-secret-provider/SKILL.md (or your agent's skills folder).This guide walks through adding a built-in provider to the secret-resolution capability
(ak-py/src/agentkernel/secret/). Use AWSSMSecretProvider
(ak-py/src/agentkernel/secret/providers/aws_ssm.py) as the reference implementation, since it is
the only built-in that talks to a remote store. The ak-dev-architecture skill's Secret
Resolution section covers the manager, cache and resolution order this guide builds on.
| Provider | type value | Addressing | Extra |
|---|---|---|---|
| Environment (default) | env | the key is the variable name, read verbatim | — (stdlib) |
| AWS SSM Parameter Store | aws_ssm | /ak/{prefix}/{key.lower()}, GetParameter(WithDecryption=True) | agentkernel[aws] |
| Bring-your-own | dotted path, e.g. myapp.secrets.VaultProvider | whatever the subclass implements | the user's own |
A dotted path already lets a user plug in any SecretProvider subclass with no core change:
resolve_dotted(..., base=SecretProvider) imports it and calls its create. AWS Secrets
Manager ships this way in v1 (see docs/specs/749-secret-resolution/design.md, Non-goals). Add a
built-in only when the backend is broadly useful, has a stable SDK, and deserves a short name,
tested IAM wiring and docs. Otherwise, document the dotted-path route in
docs/docs/advanced/secrets.md (Custom providers) and stop there.
SecretProvider (secret/base.py) is small. The rules around it are what matter:
get_secret(key) -> Optional[str]: return the stored value, or None when the backend
does not hold it. A miss is not an error. Raise SecretError (secret/errors.py) only
when the backend failed (credentials, network, throttling, authorization), and never put the
value in the message.key is always an environment-variable-style name
(^[A-Z][A-Z0-9_]*$, e.g. OPENAI_API_KEY). Translating it to the backend's name (path, secret
id, lowercase) happens here and nowhere else. The manager transforms nothing.SecretManager owns the environment → cache → provider
order and SecretCache owns TTLs. A provider that caches breaks invalidate() and rotation.client property in aws_ssm.py).EnvSecretProvider returns os.environ.get(key) or None).create(cls, config: _SecretConfig) receives the whole secret block, not just
secret.provider, so the deployment-wide secret.prefix is shared by every backend. Validate
settings here and raise AKConfigError (core/util/factory.py) on unusable values, the way
AWSSMSecretProvider._normalize_prefix rejects an empty or nested prefix. It fires at the first
SecretManager.current(), so misconfiguration fails at startup, not on first read.ak-py/src/agentkernel/secret/providers/<name>.py, one class named <Backend>SecretProvider,
with a logger ak.secret.provider.<name>:
class VaultSecretProvider(SecretProvider):
"""HashiCorp Vault KV v2. Addressing: OPENAI_API_KEY → secret/data/ak/{prefix}/openai_api_key."""
_log = logging.getLogger("ak.secret.provider.vault")
def __init__(self, prefix: str) -> None:
""":raises AKConfigError: If prefix is empty."""
...
self._client: Optional[Any] = None
self._client_lock = Lock()
@classmethod
def create(cls, config: _SecretConfig) -> "VaultSecretProvider":
return cls(prefix=config.prefix)
def get_secret(self, key: str) -> Optional[str]:
""":raises SecretError: If Vault failed for any reason other than not-found."""
...Map exactly one backend error to None (the not-found code, like ParameterNotFound in
aws_ssm.py). Everything else becomes SecretError(...) from exc, including SDK transport
errors.
In secret/factory.py, add the short name to _BUILTIN_SECRET_PROVIDERS and add a branch in
SecretProviderFactory.get before the dotted-path fallback. Import the module lazily inside
require_extra so a missing SDK raises a clear install hint:
if key == "vault":
with require_extra("vault", "secret.provider.type: vault"):
from .providers.vault import VaultSecretProvider
return VaultSecretProvider.create(config)create takes the block explicitly and must never call AKConfig.get()
(test_get_never_reads_akconfig guards this).
secret.prefix already expresses the deployment scope. Derive the backend path
from it instead of adding a per-provider path field. Region and credentials come from the SDK's
own environment defaults (the boto3.client("ssm") precedent), not from new fields.prefix can't express (e.g. a Vault address or mount),
add a _Secret<Backend>Config model under _SecretProviderConfig in core/config.py, with
Field(description=...) on every field. Update the type field's description to list the new
short name.enabled flag: selecting the provider type is the opt-in.Add the SDK to an extra in ak-py/pyproject.toml, or reuse one that already carries it (aws
carries boto3 for any AWS backend). Match the extra name to the require_extra(...) call.
ak-py/tests/test_secret_providers.py, subclass SecretProviderContract
(secret/testing.py, which is deliberately not exported from agentkernel.secret). Override the
provider fixture and seed(provider, key, value). Seed through a fake SDK client, not the
network, the way TestAWSSMProviderContract seeds _FakeSSMClient.parameters. Leave
reads_environment = False unless the store is the environment.None, each failure class → SecretError with no value in the message, config validation
→ AKConfigError, and lazy/single client creation.ak-py/tests/test_secret_factory.py: short name (case-insensitive) builds
the provider, a missing extra raises before any settings check, and the provider receives the
whole block.ak-py/tests/test_secret_manager.py's
environment-always-wins assertions to include it.If the backend is a cloud store the Terraform modules can grant, mirror ssm_enabled in
ak-deployment/ak-aws/{serverless,containerized} (variables.tf, state.tf,
modules/*/main.tf). Use one bool defaulting to false, keep every resource count-gated so
the default plan is empty, and attach a read-only grant scoped to the prefix only to the tier that
runs the agent (agent runner in queue mode, request handler / REST service otherwise — never the
response or WS connection handler). Keep injecting AK_SECRET__PREFIX from the module's own prefix so the path and the grant
can't drift. Never create secret values in Terraform.
docs/docs/advanced/secrets.md: a ### <name> subsection under Providers (addressing, IAM,
extra, failure behavior) and the new value in the secret.provider.type row.ak-dev-architecture/SKILL.md, Secret Resolution: add the provider to the Providers bullet
and the factory mapping.ak-py/README.md: the extra, if new.ak-cloud-deploy skill (ak-py/src/agentkernel/skills/ak-cloud-deploy/SKILL.md), if
you added a deployment flag.docs/src/components/*/data.tsx): a tile in the Cloud &
infrastructure row of IntegrationsMarquee/data.tsx (role Secrets, href to the secrets
docs page, logo or react-icons/si glyph; a vendor already on the marquee for another role,
such as AWS Systems Manager, gets the new role appended to its title instead of a second tile),
and the store in the Secret Resolution card's tags and description under the Guard tab
in FeatureExplorer/data.tsx. Logo sourcing and the build check are in
ak-dev-sync-docs-from-branch, Docs-Site Landing and Features Pages.secret/providers/<name>.py: owns addressing, None on miss, SecretError on failure, no caching, thread-safe lazy clientcreate validates settings and raises AKConfigError at constructionrequire_extra + name in _BUILTIN_SECRET_PROVIDERS (secret/factory.py)secret.prefix reused; a _Secret<Backend>Config only if unavoidable (core/config.py)ak-py/pyproject.tomlSecretProviderContract subclass + provider-specific tests (tests/test_secret_providers.py)tests/test_secret_factory.py)ak-deployment/)docs/docs/advanced/secrets.md, architecture skill, ak-py/README.mdIntegrationsMarquee/data.tsx), Secret Resolution card tags (FeatureExplorer/data.tsx)cd ak-py && uv run pytest tests/test_secret_*.py and make lint-check-all clean© yaalalabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/ak-dev-new-secret-provider of yaalalabs/agent-kernel.
Open the folder on GitHubat commit 97fa8d9
Ak Dev New Secret Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ak Dev New Secret Provider this skillyaalalabs/agent-kernel | 192 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | |
| Secrets Vault Manageralirezarezvani/claude-skills | 28k | 1 repos | ~3.6k | Automated safety check: Notes | MIT | |
| Create Secretharness/harness-skills | 115 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| Kcli Cluster Deploymentkarmab/kcli | 653 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Integrating Secrets Managersjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT |
alirezarezvani/claude-skills
A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…
harness/harness-skills
Generate Harness Secret definitions and manage secrets via MCP v2 tools.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
jeremylongshore/tons-of-skills-marketplace
Manage this skill enables AI assistant to seamlessly integrate with various secrets managers like hashicorp vault and aws secrets manager.
aiskillstore/marketplace
Cloud infrastructure design and deployment patterns for AWS, Azure, and GCP.
yaalalabs/agent-kernel
Code quality standards, formatting, Python style rules (classes over script-style functions, configuration-field rules), commit conventions, and PR workflow for Agent Kernel development.
yaalalabs/agent-kernel
Step-by-step guide for adding a new built-in test evaluator provider to Agent Kernel (beyond DeepEval, Opik and JEV).
yaalalabs/agent-kernel
Step-by-step guide for adding a new guardrail provider to Agent Kernel.
yaalalabs/agent-kernel
Step-by-step guide for adding a new knowledge base backend to Agent Kernel.
yaalalabs/agent-kernel
Step-by-step guide for adding a new messaging platform integration to Agent Kernel.
yaalalabs/agent-kernel
Step-by-step guide for adding a new multimodal attachment storage backend to Agent Kernel.
Categories
Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm). Ak Dev New Secret Provider is an agent skill from yaalalabs/agent-kernel. Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm).
Ak Dev New Secret Provider fits situations like: you need a new managed secret store (e.g; tasks that involve Test generation; tasks that involve Deployment.
Run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a claude-code`. Or copy the skill folder (.agents/skills/ak-dev-new-secret-provider in yaalalabs/agent-kernel) into .claude/skills/ak-dev-new-secret-provider in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a codex`. Or copy the skill folder (.agents/skills/ak-dev-new-secret-provider in yaalalabs/agent-kernel) into .agents/skills/ak-dev-new-secret-provider in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ak-dev-new-secret-provider, .gemini/skills/ak-dev-new-secret-provider, .github/skills/ak-dev-new-secret-provider and .opencode/skills/ak-dev-new-secret-provider in your project.
Going by SKILL.md and its folder, Ak Dev New Secret Provider needs the command-line tools its instructions call (uv and make) and credentials named OPENAI_API_KEY. Our summary lists: Python 3; A credential in OPENAI_API_KEY.
SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Ak Dev New Secret Provider is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ak Dev New Secret Provider: Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars), Create Secret (harness/harness-skills, 115 stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and Kcli Cluster Deployment (karmab/kcli, 653 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yaalalabs (a GitHub organization) maintains it in yaalalabs/agent-kernel, which has 192 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 9, 2026.
Source: yaalalabs/agent-kernel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.