Supplier Corrective Action Request (SCAR) — escalate a supplier non-conformance to a formal corrective action request, define response requirements, evaluate the supplier's 8D response, and verify…

MITAuto-check passed

Install Supplier Scar

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill supplier-scar -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins supplier-scar --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/RBraga01/Quality-Engineering-Skills/skills/supplier-quality/supplier-scar .claude/skills/supplier-scar && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supplier-scar
GitHub stars
1.3k
Token cost
~2.7k tokens
SKILL.md length
1,392 words
Files
2 (incl. references)
Skills in repo
716
Repo updated
First seen
Licence
MIT

At a glance

Supplier Corrective Action Request (SCAR) — escalate a supplier non-conformance to a formal corrective action request, define response requirements, evaluate the supplier's 8D response, and verify…

  • Works in 6 steps: Escalation criteria: when does an NCR… → Write the SCAR → Evaluate the supplier's 8D response → …
  • An NCR escalates to a SCAR
  • SKILL.md covers When to use, Prerequisites, Workflow and Validation criteria, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Supplier Scar is an agent skill from hashgraph-online/awesome-codex-plugins. Supplier Corrective Action Request (SCAR) — escalate a supplier non-conformance to a formal corrective action request, define response requirements, evaluate the supplier's 8D response, and verify effectiveness. Use when an NCR escalates to a SCAR, when a supplier delivers repeated non-conformances, or when a field failure is traced to a supplier. Covers ISO 9001 §8.4 and IATF 16949 §8.4.1.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/scar-template.md`).

The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is MIT.

When your agent uses it

  • An NCR escalates to a SCAR
  • A supplier delivers repeated non-conformances
  • A field failure is traced to a supplier

Example prompts

  • “/supplier-scar”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Escalation criteria: when does an NCR become a SCAR?
  2. Write the SCAR
  3. Evaluate the supplier's 8D response
  4. Issue a SCAR response rejection
  5. Effectiveness verification
  6. Supplier performance tracking

What it can do on your machine

Read from SKILL.md and the folder at commit 3e1456a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supplier Scar loads about 2.7k tokens when it runs, and up to ~8.8k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 1,392 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 3e1456a, republished under its MIT licence (© hashgraph-online). 1,392 words, ~2,711 tokens.

Download SKILL.mdSave it as .claude/skills/supplier-scar/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
supplier-scar
description
Supplier Corrective Action Request (SCAR) — escalate a supplier non-conformance to a formal corrective action request, define response requirements, evaluate the supplier's 8D response, and verify effectiveness. Use when an NCR escalates to a SCAR, when a supplier delivers repeated non-conformances, or when a field failure is traced to a supplier. Covers ISO 9001 §8.4 and IATF 16949 §8.4.1.
license
MIT
metadata.author
RBraga01
metadata.version
1.1
metadata.iso-9001
8.4, 10.2
metadata.iatf-16949
8.4.1, 10.2.3
metadata.domain
quality-engineering
metadata.subdomain
supplier-quality
metadata.industries
automotive,electronics,aerospace,medical,general
metadata.status
approved
metadata.created
2026-06-06

Supplier Corrective Action Request (SCAR)

When to use

Use this skill when:

  • A supplier NCR requires a formal corrective action (beyond simple return/replacement)
  • A supplier has delivered the same non-conformance twice or more
  • A non-conformance has caused a production line stoppage, customer complaint, or field failure
  • A supplier's quality performance score falls below the defined threshold
  • An OEM customer issues a concern that is traced to a sub-supplier
  • Preparing a SCAR, evaluating a supplier's 8D response, or conducting an effectiveness review

Prerequisites

  • Non-conformance documented (NCR or equivalent) with: part number, description, quantity, measured evidence
  • Supplier code, contact name, and corrective action coordinator identified
  • SCAR response timeline agreed (typically 24h for D3, 30 days for full 8D)
  • Historical data: previous SCARs, PPM trend, quality score for this supplier

Workflow

Step 1 — Escalation criteria: when does an NCR become a SCAR?

Issue a SCAR when any of the following conditions are met:

TriggerDescription
Severity — CriticalNon-conformance affects safety, regulatory compliance, or field function
Severity — Customer impactNon-conformance reached the end customer or caused a production line stop
RecurrenceSame defect or same part rejected for the second time within 12 months
VolumeRejection of an entire lot or >5% of a delivery
Systemic riskEvidence that the supplier's process or system is inadequate (missing controls, no inspection, operator error on SC characteristic)
Customer escalationAn OEM customer has issued a concern traceable to this supplier

Do NOT issue a SCAR for every NCR — use NCR + return for minor first-occurrence issues and reserve SCAR for systemic or high-risk situations.


Step 2 — Write the SCAR

The SCAR document must contain:

Header:

  • SCAR number (unique, traceable)
  • Date issued
  • Supplier name, supplier code, contact person
  • Issued by (supplier quality engineer name)

Non-conformance description:

  • Part number and revision
  • Delivery reference (PO number, lot number, delivery note)
  • Quantity delivered / quantity non-conforming / % affected
  • Defect description in objective-evidence language (measured values vs. specification — not opinions)
  • Customer impact (if applicable): production stop, customer complaint, field return
  • Reference to the NCR (attach or link)

Response requirements: Specify exactly what the supplier must provide and by when:

DeliverableTypical deadline
D3 Immediate Containment Action (ICA)24–48 hours
D4 Root Cause (occurrence AND escape)7–14 days
D5–D6 Permanent Corrective Actions with evidence30 days
D7 Systemic prevention (PFMEA, CP, WI updates)30 days
Full 8D report30 days

Always require TWO root causes: why the defect was produced (occurrence) AND why it was not detected (escape).

Containment verification: State that the supplier must confirm:

  • All suspect stock at their facility has been identified and quarantined
  • All stock in transit has been recalled or placed on hold
  • All stock at your facility has been segregated (include quantity)
  • A containment verification plan is in place before any further shipments are accepted

Step 3 — Evaluate the supplier's 8D response

Use the 8D Evaluator methodology (skill: 8d-problem-solving) to review the supplier's response. Focus on the most common SCAR-specific failures:

D3 — Containment:

  • Is the containment in PAST TENSE? (If it says "we will inspect going forward" — reject)
  • Does it cover all locations (supplier, transit, your facility, customer)?
  • Is there a verification result (quantity sorted, quantity rejected, quantity cleared)?

D4 — Root cause:

  • Are BOTH causes identified: occurrence (why produced) AND escape (why not caught)?
  • Is the root cause supported by evidence, or is it opinion?
  • Reject: "human error", "operator oversight", "customer changed specs" — always ask why it was possible
  • Verify: if the supplier claims "operator error", ask why the error was not detected by the control plan

D5 — Permanent corrective action:

  • Does the PCA directly address the confirmed root cause?
  • Is "retrain the operator" the only action? If so, reject — training is not a systemic fix
  • Is there a poka-yoke or process change that makes the defect impossible or immediately detectable?

D7 — Systemic prevention:

  • Has the PFMEA been updated to reflect the failure mode and new controls?
  • Has the Action Priority (AP) been revised in the PFMEA after verified corrective action? The revised AP must be lower than the original or documented with justification — AP revision is only valid after D6 effectiveness is confirmed, not at planning stage.
  • Has the Control Plan been updated?
  • Have Work Instructions been updated?
  • Has horizontal deployment been considered (same process at other lines/plants)?

D6 — Verification:

  • Is there production data showing the PCA is effective?
  • What quantity was run? Over what period?
  • What is the measured improvement (before/after comparison)?

Step 4 — Issue a SCAR response rejection

If the supplier's 8D response does not meet the gate criteria, reject it formally:

Rejection notice must specify:

  • Which discipline(s) failed and why (specific, not generic)
  • What is required in the revised response
  • Revised deadline for resubmission

Do not accept a response that:

  • Has no evidence of D3 completion (only a plan)
  • States "human error" as the final root cause without systemic analysis
  • Lists only training as the PCA
  • Has no PFMEA or CP update in D7
  • Shows no production data in D6

Show full SKILL.md (577 more words)Show less
Step 5 — Effectiveness verification

30–90 days after PCA implementation, verify that the corrective action is effective:

Methods:

  • Monitor incoming quality data: zero recurrence of the same defect in the next X deliveries
  • Review updated PFMEA and Control Plan (request current revision, verify D4 failure mode is addressed)
  • On-site verification: audit the specific process step where the defect occurred (use VDA 6.3 P6 questions for that step)
  • Request production data showing Cpk improvement on the relevant characteristic

Close the SCAR when:

  • Zero recurrence of the same non-conformance for the agreed monitoring period (typically 3–6 months)
  • Updated PFMEA, CP, and WI documents received and verified
  • Effectiveness data reviewed and accepted

If recurrence occurs during monitoring:

  • Escalate to supplier management (not just quality coordinator)
  • Consider: production stop, new supplier qualification, customer notification
  • Issue a new SCAR referencing the previous one as evidence of systemic failure

Step 6 — Supplier performance tracking

Link every SCAR to the supplier's quality performance record:

  • PPM trend (Parts Per Million non-conforming)
  • SCAR open count and average response time
  • Closure rate (closed on time vs. overdue)
  • Recurrence rate (same defect within 12 months of a previous SCAR)

Suppliers with repeated SCARs or recurrences should be placed on:

  • Controlled shipping — every delivery inspected before acceptance (in automotive: CS1 = supplier-managed 100% sort; CS2 = customer-managed sort at supplier's cost)
  • Supplier improvement plan — formal APQP-style corrective programme
  • Qualification review — potential re-qualification or replacement

Warranty cost recovery / debit note risk: In automotive OEM supply chains, SCARs that result in field failures or warranty claims can trigger financial recovery. The OEM issues a warranty debit note to the Tier 1, who cascades it to the responsible sub-supplier via SCAR. Each SCAR must therefore document whether the non-conformance caused any field or warranty cost — this determines whether cost recovery applies. A SCAR without this assessment is incomplete for OEM reporting purposes. If warranty cost recovery is raised, escalate immediately to commercial and legal before responding to the OEM.


Validation criteria

A SCAR is closed when:

  • Full 8D submitted with both root causes confirmed (occurrence AND escape)
  • Permanent corrective action verified with production data (D6)
  • PFMEA, Control Plan, and Work Instructions updated and received (D7)
  • No recurrence of the same non-conformance during the agreed monitoring period
  • Closure signed off by Supplier Quality Engineer and documented in the supplier record

Common mistakes

  • Issuing a SCAR for every NCR — dilutes the severity signal; suppliers stop taking SCARs seriously
  • Accepting a D3 response that is a plan ("we will inspect") rather than a completed action
  • Closing the SCAR when the 8D is submitted rather than when effectiveness is verified
  • Accepting "human error" or "operator training" without requiring a systemic root cause
  • Not updating the supplier performance record — next engineer doesn't know the history
  • Allowing the SCAR to stay open indefinitely with no escalation — sets the precedent that deadlines are negotiable

Output Format

At the start of each use, ask the user:

"How would you like to receive the output? A — Structured Markdown (formatted tables and sections, ready to copy) B — Plain tables (simplified structure for Excel or Word) C — Narrative report (flowing text for a formal document or email)

Default: A."

Adapt all output sections to the chosen format. If the platform or session context already defines a format preference, skip this question.

Changelog

VersionDateAuthorChange
1.02026-06-06@RBraga01Initial release
1.12026-06-06@migmccAdded AP revision check in D7 evaluation; added warranty cost recovery / debit note risk in Step 6; added CS1/CS2 controlled shipping reference

© hashgraph-online, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/RBraga01/Quality-Engineering-Skills/skills/supplier-quality/supplier-scar of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • references/scar-template.md

Open the folder on GitHubat commit 3e1456a

Compare with similar skills

Supplier Scar next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supplier Scar compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supplier Scar this skillhashgraph-online/awesome-codex-plugins1.3k—~2.7kAutomated safety check: PassMIT
ActionsJetBrains/intellij-community21k—~341Automated safety check: PassCustom licence
Laravel Actionscoollabsio/coolify63k—~2.4kAutomated safety check: PassApache-2.0
Correctcursor/plugins11k3 repos~612Automated safety check: PassNone
ActionsBuilderIO/agent-native7.1k—~4.4kAutomated safety check: PassNone
CorrectionNxcoreAI/EverRoom3k—~290Automated safety check: PassCustom licence

Similar skills

  • Actions

    JetBrains/intellij-community

    Official

    Implement or change IntelliJ AnAction actions and registrations.

    21k GitHub stars~341 tokensUpdated today
    MobileAuto-check passed
  • Laravel Actions

    coollabsio/coolify

    Build, refactor, and troubleshoot Laravel Actions using lorisleiva/laravel-actions.

    63k GitHub stars~2.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Correct

    cursor/plugins

    Official

    Find the mistakes agents keep repeating in this repo and make each one impossible.

    11k GitHub starsUsed in 3 repos~612 tokens
    Auto-check passed
  • Actions

    BuilderIO/agent-native

    How to create and run agent actions. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Correction

    NxcoreAI/EverRoom

    Compute Room overview corrections—citation corrections as per-claim edits and general corrections as a single proposal.

    3k GitHub stars~290 tokensUpdated yesterday
    Research & ScienceAuto-check passed
  • Securing GitHub Actions Workflows

    mukul975/Anthropic-Cybersecurity-Skills

    Hardens GitHub Actions workflows against supply chain attacks, credential theft, and privilege escalation: pinning actions to SHA digests, minimizing GITHUBTOKEN permissions, protecting secrets…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 716 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated today
    Auto-check passed

Questions about Supplier Scar

What does Supplier Scar do?

Supplier Corrective Action Request (SCAR) — escalate a supplier non-conformance to a formal corrective action request, define response requirements, evaluate the supplier's 8D response, and verify…. Supplier Scar is an agent skill from hashgraph-online/awesome-codex-plugins. Supplier Corrective Action Request (SCAR) — escalate a supplier non-conformance to a formal corrective action request, define response requirements, evaluate the supplier's 8D response, and verify effectiveness.

When should I use Supplier Scar?

Supplier Scar fits situations like: an NCR escalates to a SCAR; A supplier delivers repeated non-conformances; A field failure is traced to a supplier.

How do I install Supplier Scar in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill supplier-scar -a claude-code`. Or copy the skill folder (plugins/RBraga01/Quality-Engineering-Skills/skills/supplier-quality/supplier-scar in hashgraph-online/awesome-codex-plugins) into .claude/skills/supplier-scar in your project. Claude Code loads it when a task matches its description.

How do I install Supplier Scar in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill supplier-scar -a codex`. Or copy the skill folder (plugins/RBraga01/Quality-Engineering-Skills/skills/supplier-quality/supplier-scar in hashgraph-online/awesome-codex-plugins) into .agents/skills/supplier-scar in your project. Codex loads it when a task matches its description.

Can I use Supplier Scar in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill supplier-scar -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supplier-scar, .gemini/skills/supplier-scar, .github/skills/supplier-scar and .opencode/skills/supplier-scar in your project.

What does Supplier Scar need to run?

SKILL.md names no scripts, command-line tools or credentials: Supplier Scar is instructions for the agent only.

Does Supplier Scar access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Supplier Scar safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supplier Scar use?

Supplier Scar is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supplier Scar use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.

What are the alternatives to Supplier Scar?

Skills that share tags, products or a category with Supplier Scar: Actions (JetBrains/intellij-community, 21k stars), Laravel Actions (coollabsio/coolify, 63k stars), Correct (cursor/plugins, 11k stars) and Actions (BuilderIO/agent-native, 7.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supplier Scar?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,267 GitHub stars. The repository holds 716 skills in this directory. The repository was last updated on October 10, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.