Agent skill

Trust Remote Builder

by johannesPettersson80 in johannesPettersson80/trust-platform

Runs truST builds and tests on the shared trust-builder machine.

Apache-2.0Auto-check passedTesting & QA

Install Trust Remote Builder

skills CLI
$ npx skills add johannesPettersson80/trust-platform --skill trust-remote-builder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install johannesPettersson80/trust-platform trust-remote-builder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/johannesPettersson80/trust-platform.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/trust-remote-builder .claude/skills/trust-remote-builder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
trust-remote-builder
GitHub stars
222
Token cost
~2k tokens
SKILL.md length
1,014 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs truST builds and tests on the shared trust-builder machine.

  • Works in 4 steps: stop the gate's leftover processes by PID; → rerun the preflight; → clean up; → …
  • VS Code extension tests
  • SKILL.md covers Getting the code there, Shared cargo targets, Disk and Running tests there, plus 2 more sections
  • Calls ssh, cargo and rsync

What it does

Trust Remote Builder is an agent skill from johannesPettersson80/trust-platform. Runs truST builds and tests on the shared trust-builder machine. Use when compiling, running cargo, just or npm gates, VS Code extension tests or Playwright on the builder, syncing local work there, managing shared cargo targets and disk space, or reporting remote proof.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Browser testing. It works with Visual Studio Code, npm, Playwright and Rust. The repository describes itself as: truST Platform — IEC 61131‑3 Structured Text tooling suite. The licence is Apache-2.0.

When your agent uses it

  • VS Code extension tests
  • Playwright on the builder
  • Syncing local work there
  • Managing shared cargo targets and disk space

Example prompts

  • “/trust-remote-builder”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. stop the gate's leftover processes by PID;
  2. rerun the preflight;
  3. clean up;
  4. retain the failure ledger; run again only within the user's current retry authorization.

What it can do on your machine

Read from SKILL.md and the folder at commit b7d8ffb. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ssh
    • cargo
    • rsync
    • git
    • just
    • rustc

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh, rsync and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Trust Remote Builder loads about 2k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 1,014 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from johannesPettersson80/trust-platform at commit b7d8ffb, republished under its Apache-2.0 licence (© johannesPettersson80). 1,014 words, ~1,975 tokens.

Download SKILL.mdSave it as .claude/skills/trust-remote-builder/SKILL.md (or your agent's skills folder).
name
trust-remote-builder
description
Runs truST builds and tests on the shared trust-builder machine. Use when compiling, running cargo, just or npm gates, VS Code extension tests or Playwright on the builder, syncing local work there, managing shared cargo targets and disk space, or reporting remote proof.

trust-builder

Hard rule (AGENTS.md): all logic is in Rust. Logic is anything whose result is stored, sent to a runtime or PLC, or decides an engineering or operator outcome. TypeScript only presents (drawing, layout, mouse interaction, view state) and forwards requests to Rust. Never add logic in TypeScript. Existing TypeScript logic is debt to move into Rust, not to extend.

Logic is proven on the builder by cargo runs. VS Code and Playwright runs prove only wiring and rendering.

trust-builder is an SSH alias (user johannes) for a shared Hetzner CPU machine. It runs:

  • cargo, just and npm;
  • the VS Code extension tests;
  • the release gates;
  • headless browser tests.

Two limits:

  • It has no GPU, so final WebGL or WebGPU visual proof needs real hardware.
  • It has no GitHub push credentials, so it fetches and validates only. Authorized pushes use the local checkout.

Use the local Raspberry Pi for editing, git and lightweight inspection. Every Cargo, just and npm build/test runs through SSH on the builder. Follow AGENTS.md's implementation-first batch cadence; this skill does not authorize intermediate checks or retries.

Getting the code there

  • main: the builder's copy is ~/projects/trust-platform. Fetch through that checkout's configured origin; check git remote -v first, and do not swap in the workstation's SSH URL.

  • Uncommitted or feature work: rsync the local checkout to its own builder copy:

    bash
    rsync -a --delete --exclude /target/ --exclude /fuzz/target/ --exclude '**/node_modules/' \
      --exclude /.venv-docs/ /path/to/local/checkout/ trust-builder:~/projects/<copy>/
    • Sync one folder to one folder, with matching trailing slashes. --delete aimed at a parent directory has wiped sibling folders before.
    • If the builder copy has changes of its own, stop and report them instead of overwriting.
    • --delete also removes files that exist only on the builder: formatted sources, built bundles and evidence. Copy those back before the next sync.
    • A file restored by rsync can keep an old mtime, so cargo may reuse a stale build. touch it.
  • Verification evidence batches (many audit or evidence reports): regenerate them in a clean, detached builder worktree. Validate every report there, then copy back only the validated reports.

Shared cargo targets

Several checkouts build into ~/.cache/codex-targets/<name> at the same time. An isolated task target can also live under the mounted volume's /mnt/HC_Volume_107089260/builder-storage/cargo-targets/ root. The shared path policy checks mount state, ownership and canonical paths; no symlink workaround. Use the same lease/removal scripts and preserve unrelated targets.

  • Run every cargo-producing command through the lease:

    bash
    ssh trust-builder 'cd ~/projects/<copy> && T=$HOME/.cache/codex-targets/trust-platform-gate && \
      scripts/with_cargo_target_lease.sh "$T" env CARGO_TARGET_DIR="$T" just test-all'
  • Delete a target only with scripts/remove_cargo_target_if_idle.sh TARGET. Exit 75 means another gate holds the target, so keep it. The lease lives in ~/.cache/codex-target-leases, outside the target, so recreating a target cannot bypass it.

  • Never glob-delete ~/.cache/codex-targets/*. A single empty lsof sample does not prove that a target is idle.

Disk

Run this preflight before broad gates:

bash
ssh trust-builder 'df -hT /home/johannes /tmp && du -xhd1 "$HOME/projects" 2>/dev/null | sort -h | tail -20 && du -xhd1 "$HOME/.cache" 2>/dev/null | sort -h | tail -20'
  • Also inspect df for the selected target and task TMPDIR; the example above only covers the home filesystem and /tmp. Confirm the intended volume is mounted before using it.
  • Capacity:
    • allow about 25 GB for Clippy, tests or npm output on the filesystem holding that output;
    • the release guard requires 80 GiB on the selected target filesystem for cold just test-all;
    • inspect active task-owned builds and coordinate overlapping large runs on the same filesystem. A target lease protects against deletion, not disk consumption by other targets;
    • record actual free space and known concurrent growth. If headroom is insufficient, postpone the new run or use an approved target root with capacity. Do not lower guard thresholds or delete another session's outputs to make a preflight pass.
  • Cleaning up: delete only generated outputs, never a source worktree. Examples are an isolated copy's target/, fuzz/target/ and ~/.cache/sccache. Use the idle-target script for shared targets.
  • Runtime test binaries: cargo test --all builds about 290 runtime test binaries of up to 450 MB each, so it can fill the disk. When space is short, run the runtime tests in batches that delete their binaries.
  • Out of space: these errors are infrastructure failures, not test results: No space left on device, Disk quota exceeded, mold: failed to write and couldn't create a temp dir. Then:
    1. stop the gate's leftover processes by PID;
    2. rerun the preflight;
    3. clean up;
    4. retain the failure ledger; run again only within the user's current retry authorization. Report the original failure as infrastructure failure, not a failed behavior assertion.
Show full SKILL.md (314 more words)Show less

Running tests there

  • TMPDIR: /tmp is a quota tmpfs that other jobs fill. If you see odd Chrome or Xvfb failures ("Missing X server", canvases missing edges), /tmp is probably full; echo x > /tmp/.q tests it. Run tests with TMPDIR under home, for example TMPDIR=$HOME/tmp-<task>.
  • VS Code tests need an X display:
    • start Xvfb by PID: Xvfb :<n> -screen 0 1920x1080x24 -nolisten tcp &;
    • set DISPLAY=:<n>, and kill Xvfb by PID afterwards;
    • TRUST_VSCODE_TEST_GREP selects suites by title (a regular expression);
    • ST_LSP_TEST_SERVER=<path>/trust-lsp reuses a built language server.
  • Killing processes: kill by PID or by your own process group, never with pkill -f or killall.
  • CPU contention: never run two timing-sensitive suites at once on the builder. Check active workloads and available memory before choosing build parallelism; honor the builder's Cargo job configuration unless the task needs a documented override. More Cargo jobs do not speed up a single-threaded test, so inspect the active phase before attributing a delay to CPU limits.

CI parity

Source parity is not CI parity. Before you call a result CI-equivalent:

  • Toolchain: use the workflow's exact toolchain and command. When CI floats on stable, refresh it just before the final gate. Record rustc -Vv and cargo -V.
  • Clippy: run the CI shape, cargo clippy --all-targets --all-features -- -D warnings.
  • trust-runtime candidates: also run ./scripts/check_runtime_cross_target_warnings.sh --install-missing --require-cross.
  • Windows: the builder does not prove Windows console encoding, locale, TCP close or filesystem behaviour. For those, the Windows GitHub job is authoritative.

Reporting proof

For a new evidence batch, check hostname and pwd inside the same SSH command, and record:

  • the exact command, inside ssh trust-builder '…';
  • the remote path and its revision, or the local tree it was synced from;
  • the result with counts and duration;
  • the toolchain versions, for CI-equivalent claims;
  • every gate that did not run, and why.

Keep these states apart:

  • the local checkout;
  • the builder copy;
  • the GitHub branch;
  • the published release.

© johannesPettersson80, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .codex/skills/trust-remote-builder of johannesPettersson80/trust-platform.

Open the folder on GitHubat commit b7d8ffb

Compare with similar skills

Trust Remote Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Trust Remote Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Trust Remote Builder this skilljohannesPettersson80/trust-platform222—~2kAutomated safety check: PassApache-2.0
Write SpecLiberatedPixelCup/Universal-LPC-Spritesheet-Character-Generator1.8k—~719Automated safety check: PassGPL-3.0
Prepare Rslint npm Releaseweb-infra-dev/rslint461—~1.5kAutomated safety check: PassMIT
Project Docs Maintainerswimmwatch/cloakbrowser-mcp164—~569Automated safety check: PassMIT
RStudio Selenium to Playwright Migrationrstudio/rstudio5.1k—~3.6kAutomated safety check: PassCustom licence
Playwright Component Testingmellowagain/gitarena1151 repos~2.6kAutomated safety check: PassMIT

Similar skills

  • Write Spec

    LiberatedPixelCup/Universal-LPC-Spritesheet-Character-Generator

    Write a browser Mocha, Node, or Playwright visual spec for this repo.

    1.8k GitHub stars~719 tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Prepare Rslint npm Release

    web-infra-dev/rslint

    Prepare a stable release PR for the unified rslint npm packages by updating package versions and rule/TypeScript release metadata.

    461 GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Project Docs Maintainer

    swimmwatch/cloakbrowser-mcp

    Maintain, organize, consolidate, or audit the cloakbrowser-mcp documentation set only when the user explicitly requests project documentation maintenance or an authorized public change requires it.

    164 GitHub stars~569 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Converts RStudio Python Selenium electron tests into TypeScript Playwright tests, checking each against a live RStudio before counting it as migrated.

    5.1k GitHub stars~3.6k tokensUpdated today
    Testing & QAAuto-check passed
  • Playwright Component Testing

    mellowagain/gitarena

    Set up component testing with Playwright using a story gallery — scaffold stories and a gallery dev page driven by the built-in mount fixture, no dedicated component-testing runtime.

    115 GitHub starsUsed in 1 repo~2.6k tokens
    Testing & QAAuto-check passed
  • Playwright Core

    testdino-hq/playwright-skill

    Battle-tested Playwright patterns for writing and debugging reliable E2E, API, component, visual, accessibility, and security tests.

    390 GitHub starsUsed in 1 repo~1.4k tokens
    Testing & QAAuto-check passed

More from johannesPettersson80/trust-platform

  • Trust CI Release Gates

    johannesPettersson80/trust-platform

    Prepares and ships truST changes - changelog and version updates, CI parity, pre-push checks, the exact-SHA release-candidate guard, merge, tag and release verification.

    222 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Trust Test Authoring

    johannesPettersson80/trust-platform

    Routes truST behaviour changes from the written specification to a native executable test.

    222 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • St Lsp Solid

    johannesPettersson80/trust-platform

    Keeps truST's architecture simple and well separated, and runs the automated architecture checks.

    222 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Trust Hmi Contracts

    johannesPettersson80/trust-platform

    Guides work on truST's HMI - the HMI Builder editor, page files, the runtime display at /hmi, bindings, commands and writes, authorization, alarms and trends, the plant library and the HMI tests.

    222 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Trust Lsp Iec

    johannesPettersson80/trust-platform

    Guides IEC 61131-3 Structured Text language work in truST - lexer, parser, types, semantics, standard functions and function blocks, OOP, namespaces and editor features - checked against the standard.

    222 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Trust Vscode Quality

    johannesPettersson80/trust-platform

    Builds and verifies truST's VS Code extension - commands, webviews, snippets, debug flows, Control Studio, HMI Builder, Devices & Connections and the test harness.

    222 GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Categories

Questions about Trust Remote Builder

What does Trust Remote Builder do?

Runs truST builds and tests on the shared trust-builder machine. Trust Remote Builder is an agent skill from johannesPettersson80/trust-platform. Runs truST builds and tests on the shared trust-builder machine.

When should I use Trust Remote Builder?

Trust Remote Builder fits situations like: VS Code extension tests; playwright on the builder; syncing local work there; managing shared cargo targets and disk space.

How do I install Trust Remote Builder in Claude Code?

Run `npx skills add johannesPettersson80/trust-platform --skill trust-remote-builder -a claude-code`. Or copy the skill folder (.codex/skills/trust-remote-builder in johannesPettersson80/trust-platform) into .claude/skills/trust-remote-builder in your project. Claude Code loads it when a task matches its description.

How do I install Trust Remote Builder in Codex?

Run `npx skills add johannesPettersson80/trust-platform --skill trust-remote-builder -a codex`. Or copy the skill folder (.codex/skills/trust-remote-builder in johannesPettersson80/trust-platform) into .agents/skills/trust-remote-builder in your project. Codex loads it when a task matches its description.

Can I use Trust Remote Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add johannesPettersson80/trust-platform --skill trust-remote-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/trust-remote-builder, .gemini/skills/trust-remote-builder, .github/skills/trust-remote-builder and .opencode/skills/trust-remote-builder in your project.

What does Trust Remote Builder need to run?

Going by SKILL.md and its folder, Trust Remote Builder needs the command-line tools its instructions call (ssh, cargo, rsync, git, just and rustc).

Does Trust Remote Builder access the network?

SKILL.md contains no URLs. Its commands use ssh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Trust Remote Builder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Trust Remote Builder use?

Trust Remote Builder is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Trust Remote Builder use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Trust Remote Builder?

Skills that share tags, products or a category with Trust Remote Builder: Write Spec (LiberatedPixelCup/Universal-LPC-Spritesheet-Character-Generator, 1.8k stars), Prepare Rslint npm Release (web-infra-dev/rslint, 461 stars), Project Docs Maintainer (swimmwatch/cloakbrowser-mcp, 164 stars) and RStudio Selenium to Playwright Migration (rstudio/rstudio, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Trust Remote Builder?

johannesPettersson80 (a GitHub user) maintains it in johannesPettersson80/trust-platform, which has 222 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 11, 2026.

Source: johannesPettersson80/trust-platform on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.