Agent skill

Soak

by nubjs in nubjs/nub

Manages the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools.

MITAuto-check: warningsSecurity

Install Soak

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add nubjs/nub --skill soak -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nubjs/nub soak --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/soak .claude/skills/soak && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
soak
GitHub stars
4.4k
Token cost
~1.3k tokens
SKILL.md length
646 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Manages the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools.

  • Works in 3 steps: Edit SOAK_DAYS in… → pnpm run soak:fix (rewrites… → pnpm run soak + pnpm run test:scripts —…
  • A task touches minimumReleaseAge
  • SKILL.md covers Commands (package.json scripts…, Change the window (one place), Skip the soak for ONE package… and The cargo soak needs nightly —…, plus 1 more section
  • Calls pnpm and cargo

What it does

Soak is an agent skill from nubjs/nub. Manages the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools. Use when a task touches minimumReleaseAge, min-release-age, min-publish-age, external-tools.json, renovate.json, or taze cooldowns, or when investigating why a freshly published version won't install.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security. It works with pnpm. The repository describes itself as: The fast all-in-one Node.js toolkit. The licence is MIT.

When your agent uses it

  • A task touches minimumReleaseAge
  • Min-release-age
  • Min-publish-age
  • External-tools.json

Example prompts

  • “Use the soak skill to manage the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window…”
  • “/soak”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Edit SOAK_DAYS in scripts/soak/constants.mts.
  2. pnpm run soak:fix (rewrites cargo/npmrc/yaml; taze follows by import).
  3. pnpm run soak + pnpm run test:scripts — existing exclusion annotations encode the old window and will be flagged; re-date or remove them…

What it can do on your machine

Read from SKILL.md and the folder at commit 568e73a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Soak loads about 1.3k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 646 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:14
    | `.npmrc` | `min-release-age` | days |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nubjs/nub at commit 568e73a, republished under its MIT licence (© nubjs). 646 words, ~1,301 tokens.

Download SKILL.mdSave it as .claude/skills/soak/SKILL.md (or your agent's skills folder).
name
soak
description
Manages the repo's supply-chain soak window (SOAK_DAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools. Use when a task touches minimumReleaseAge, min-release-age, min-publish-age, external-tools.json, renovate.json, or taze cooldowns, or when investigating why a freshly published version won't install.

The soak window

One rule: a release must be at least SOAK_DAYS old before this repo adopts it. The delay gives the ecosystem time to catch a malicious or yanked release before we ever install it. The window is defined exactly once — read the current value from scripts/soak/constants.mts and never hardcode it elsewhere. Every surface derives from or is parity-checked against it:

SurfaceKeyUnits
.cargo/config.tomlglobal-min-publish-age"N days"
tools/pnpm-workspace.yamlminimumReleaseAgeminutes
.npmrcmin-release-agedays
tools/taze.config.mtsmaturityPeriodimports SOAK_DAYS
external-tools.jsonsoakBypass annotationsdays
.github/renovate.jsonminimumReleaseAge (explicit — an extends: preset doesn't count)"N days"

Commands (package.json scripts — the code lives in scripts/soak/)

  • pnpm run soak — parity-check every surface (CI-gated in docs-links)
  • pnpm run soak:fix — rewrite drifted windows, prune expired exclusions
  • pnpm run deps:update — bump npm (taze) + cargo deps through the window
  • pnpm run tools:check / tools:fix / tools:install — validate / prune-expired-bypasses / install the SRI-pinned external tools (external-tools.json)
  • pnpm run test:scripts — the scripts' own unit tests

The gates fail closed on invalid states (missing, malformed, or wrong-arithmetic annotations) and WARN on expired ones — stale is not unsafe, and nobody has to watch for it: the scheduled soak-autofix workflow runs soak:fix + tools:fix daily and commits the pruning as a bot PR.

A soak change is done when pnpm run soak and pnpm run test:scripts both exit 0 — the same gates CI runs. Re-run them after every fix.

Change the window (one place)

  1. Edit SOAK_DAYS in scripts/soak/constants.mts.
  2. pnpm run soak:fix (rewrites cargo/npmrc/yaml; taze follows by import).
  3. pnpm run soak + pnpm run test:scripts — existing exclusion annotations encode the old window and will be flagged; re-date or remove them, then re-run until both pass.

Opt out entirely: set SOAK_DAYS = 0 and run the same two steps — cargo, pnpm/nub (minimumReleaseAge: 0), npm, and taze all treat zero as disabled. There is deliberately no env-var bypass: opting out is a committed, reviewable change, never a silent one.

Skip the soak for ONE package (dated, temporary)

Add to minimumReleaseAgeExclude in tools/pnpm-workspace.yaml with the annotation on the line above (block list only — flow [..] is rejected because a comment line can't attach to an inline entry):

yaml
# published: YYYY-MM-DD | removable: YYYY-MM-DD
- 'name@1.2.3'

removable = published + SOAK_DAYS; published must be the real registry publish date (the placeholders above are schematic — copying them verbatim is rejected). Once removable passes, pnpm run soak warns until the pin is pruned (soak:fix or the soak-autofix workflow does it). Bare names / @scope/* globs are standing trust and need no annotation. External tools use the same shape via a soakBypass object in external-tools.json.

Show full SKILL.md (238 more words)Show less

The cargo soak needs nightly — the repo still must not pin one

min-publish-age is an [unstable] cargo feature: a stable cargo ignores it silently. The repo deliberately ships no rust-toolchain.toml, because a repo-root toolchain file outranks rustup default and would silently redirect the version-pinned CI jobs (the MSRV Check legs) and build released binaries on nightly.

The nightly is instead requested per-invocation, at the only step that picks versions: scripts/soak/update-deps.mts runs cargo +nightly update. Everything else — every CI job, every shipped binary — builds on stable. If you need the cargo soak somewhere new, call cargo +nightly there; do not add a toolchain file.

Keep the nightly current — a merely-old one silently disables the window. Cargo treats an [unstable] key it does not implement as a warning and exits 0, so an old nightly resolves with NO window while looking successful. Measured both sides: nightly 2026-03-21 (cargo 1.96.0-nightly) has no such -Z and skips the window silently; nightly 2026-07-27 (cargo 1.99.0-nightly) supports -Z min-publish-age and visibly holds a too-fresh release back (available: v0.2.189, published 7 days ago). deps:update detects the warning and fails with the fix (rustup update nightly) — if you see it, the lockfile changes it just made are unsoaked.

Maintaining this skill

scripts/soak/ is the law; this file only documents it — when they disagree, fix this file. Keep it concise (goal + constraints, not step enumeration), and keep the window value in constants.mts rather than restating it here.

© nubjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/soak of nubjs/nub.

Open the folder on GitHubat commit 568e73a

Compare with similar skills

Soak next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Soak compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Soak this skillnubjs/nub4.4k—~1.3kAutomated safety check: WarnMIT
npm Supply Chain Securitybodadotsh/npm-security-best-practices859—~1kAutomated safety check: WarnMIT
Interlinked Supply ChainQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT
Memstack Security Dependency Auditcwinvestments/memstack423—~3.1kAutomated safety check: PassProprietary
Dependency AwarenessGoldziher/ai-rulez158—~250Automated safety check: PassMIT
Package Security Checkinstructa/agent-skills139—~1.8kAutomated safety check: PassNone

Similar skills

  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    859 GitHub stars~1k tokensUpdated 8 days ago
    SecurityAuto-check: warnings
  • Interlinked Supply Chain

    QuentinCody/interlinked-cli

    Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

    178 GitHub stars~2.8k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • A skill your agent uses when the user says 'dependency audit', 'npm audit', 'pip audit', 'cargo audit', 'security vulnerabilities', 'outdated packages', 'supply chain', or needs to scan project…

    423 GitHub stars~3.1k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Dependency Awareness

    Goldziher/ai-rulez

    Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

    158 GitHub stars~250 tokensUpdated today
    SecurityAuto-check passed
  • Package Security Check

    instructa/agent-skills

    Run a reusable JavaScript supply-chain security baseline with pnpm-first hardening, release-age gating, lifecycle-script controls, exotic dependency checks, CI install checks, and optional incident…

    139 GitHub stars~1.8k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Supply-chain security controls for the @cipherstash/stack monorepo.

    157 GitHub stars~5.2k tokensUpdated today
    DevelopmentAuto-check: warnings

More from nubjs/nub

All 31 skills in this repo
  • Cpu Reduction

    nubjs/nub

    Diagnose and clear CPU, memory, and disk contention on the maintainer's dev host.

    4.4k GitHub stars~2.8k tokensUpdated yesterday
    Auto-check passed
  • Reclaim disk on the maintainer's Mac when the volume is full or filling — ENOSPC, "no space left on device", a failed build or agent harness, or a routine sweep of Rust build residue.

    4.4k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Nub Charts

    nubjs/nub

    Build a performance chart for nubjs.com — the SVG bar figures in blog posts, docs pages and social posts (a runtime augmentation against plain node, an install or dispatch comparison, a cross-tool…

    4.4k GitHub stars~4.6k tokensUpdated yesterday
    Auto-check passed
  • Audit Thread

    nubjs/nub

    A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…

    4.4k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Linux Vm Test

    nubjs/nub

    Run ad-hoc Nub tests and debugging probes on real local Linux guests.

    4.4k GitHub stars~986 tokensUpdated yesterday
    Auto-check passed
  • Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.

    4.4k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Soak

What does Soak do?

Manages the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools. Soak is an agent skill from nubjs/nub. Manages the repo's supply-chain soak window (SOAKDAYS) — checks and fixes the derived surfaces, bumps or disables the window, adds dated per-package exclusions, and bumps pinned external tools.

When should I use Soak?

Soak fits situations like: A task touches minimumReleaseAge; min-release-age; min-publish-age; external-tools.json.

How do I install Soak in Claude Code?

Run `npx skills add nubjs/nub --skill soak -a claude-code`. Or copy the skill folder (.claude/skills/soak in nubjs/nub) into .claude/skills/soak in your project. Claude Code loads it when a task matches its description.

How do I install Soak in Codex?

Run `npx skills add nubjs/nub --skill soak -a codex`. Or copy the skill folder (.claude/skills/soak in nubjs/nub) into .agents/skills/soak in your project. Codex loads it when a task matches its description.

Can I use Soak in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nubjs/nub --skill soak -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/soak, .gemini/skills/soak, .github/skills/soak and .opencode/skills/soak in your project.

What does Soak need to run?

Going by SKILL.md and its folder, Soak needs the command-line tools its instructions call (pnpm and cargo).

Does Soak access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Soak safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Soak use?

Soak is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Soak use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Soak?

Skills that share tags, products or a category with Soak: npm Supply Chain Security (bodadotsh/npm-security-best-practices, 859 stars), Interlinked Supply Chain (QuentinCody/interlinked-cli, 178 stars), Memstack Security Dependency Audit (cwinvestments/memstack, 423 stars) and Dependency Awareness (Goldziher/ai-rulez, 158 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Soak?

nubjs (a GitHub organization) maintains it in nubjs/nub, which has 4,372 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 7, 2026.

Source: nubjs/nub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.