Agent skill

Network Traffic Annotations

by nwjs in nwjs/chromium.src

Guide for writing and managing Network Traffic Annotations in Chromium.

BSD-3-ClauseAuto-check passed

Install Network Traffic Annotations

skills CLI
$ npx skills add nwjs/chromium.src --skill network-traffic-annotations -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nwjs/chromium.src network-traffic-annotations --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/skills/network-traffic-annotations .claude/skills/network-traffic-annotations && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
network-traffic-annotations
GitHub stars
160
Token cost
~1.6k tokens
SKILL.md length
762 words
Files
2
Skills in repo
64
Repo updated
First seen
Licence
BSD-3-Clause

At a glance

Guide for writing and managing Network Traffic Annotations in Chromium.

  • Works in 4 steps: Build Chrome → Run the Auditor → Update Summary Files → …
  • Updating code that makes network requests
  • SKILL.md covers Where to add, Authoring Process, Annotation Tag Content and Template, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Network Traffic Annotations is an agent skill from nwjs/chromium.src. Guide for writing and managing Network Traffic Annotations in Chromium. Use this skill when adding or updating code that makes network requests.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

The repository describes itself as: Chromium codebase with NW.js modifications. Based on https://chromium.googlesource.com/chromium/src.git. The licence is BSD-3-Clause.

When your agent uses it

  • Updating code that makes network requests

Example prompts

  • “/network-traffic-annotations”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Build Chrome
  2. Run the Auditor
  3. Update Summary Files
  4. Update Platform List

What it can do on your machine

Read from SKILL.md and the folder at commit a9e8946. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are cpp, bash and xml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Network Traffic Annotations loads about 1.6k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 762 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nwjs/chromium.src at commit a9e8946, republished under its BSD-3-Clause licence (© nwjs). 762 words, ~1,648 tokens.

Download SKILL.mdSave it as .claude/skills/network-traffic-annotations/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
network-traffic-annotations
description
Guide for writing and managing Network Traffic Annotations in Chromium. Use this skill when adding or updating code that makes network requests.

Network Traffic Annotations

Network traffic annotations provide transparency into Chrome’s network communication by documenting the intent, payload, and control mechanisms of each network request.

Where to add

Add annotations at the most rational point of origin for a request. This is typically where:

  1. The origin of the user’s intent or internal requirement is stated.
  2. The controls (settings or policies) to stop or limit the request are enforced.
  3. The data being sent is specified.

Authoring Process

When adding a network annotation, you MUST follow these steps in sequence:

  1. Verify pre-conditions.
  2. Give the user an overview of the process.
  3. Gather requirements: start by reading the .cc file. Anything you're not sure of, ask the user explicitly and directly. You MUST ask the user for anything you're not sure of.
  4. Explicitly ask the user to verify the accuracy of annotation's content.
  5. Write the annotation based on the requirements you've gathered
  6. Run the auditor.py script
  7. Ask the user to review the contents one last time before they upload it for review.

Annotation Tag Content

Each annotation is defined using net::DefineNetworkTrafficAnnotation("unique_id", R"(...)"). The second argument is a text-encoded NetworkTrafficAnnotation protobuffer, as defined in chrome/browser/privacy/traffic_annotation.proto.

To determine the annotation's contents, start by reading the source code of the file the annotation is in. If you need more information, or you are unsure what to enter for a particular field, you MUST ask the user for more information before proceeding.

Essential Semantics Fields
  • sender: The component or feature triggering the request (e.g., "Safe Browsing").
  • description: Plaintext explanation of the request and its value proposition. This is meant for a technical audience, but not Chrome/Chromium developers. Avoid obscure or internal code names.
  • trigger: The specific user action that triggers the request.
  • user_data: The nature of the data being sent (use enums from chrome/browser/privacy/traffic_annotation.proto).
  • destination:
    • GOOGLE_OWNED_SERVICE for Google endpoints
    • WEBSITE for a website the user is visiting
    • OTHER for any other endpoint
      • If you use OTHER, explain it in the destination_other string field.
  • contacts: A list of emails for points-of-contact (individuals, or a team alias). You MUST ask the user which email they want to use. contacts is a repeated field.
  • last_reviewed: Date of last review in YYYY-MM-DD format. Use today's date, e.g. using the date command.
Essential Policy Fields
  • cookies_allowed: YES or NO.
  • setting: How a user can enable/disable the feature in settings. If there is no setting, explain why.
  • chrome_policy: The enterprise policy that disables this request, and what value to use to disable the request. Recently-added policies may need to be wrapped in subProto1 { ... } so auditor.py can parse them. You can find policy definitions in components/policy/resources/templates/policies.yaml and components/policy/resources/templates/policy_definitions/.
  • policy_exception_justification: If no enterprise policy exists to disable this request, explain why.

The traffic annotation MUST contain either chrome_policy or policy_exception_justification, but not both.

Show full SKILL.md (296 more words)Show less

Template

cpp
  constexpr net::NetworkTrafficAnnotationTag traffic_annotation =
      net::DefineNetworkTrafficAnnotation("...", R"(
          semantics {
            sender: "..."
            description: "..."
            trigger: "..."
            destination: WEBSITE/GOOGLE_OWNED_SERVICE/OTHER
            data: "..."
            user_data {
              type: ...
            }
            last_reviewed: "YYYY-MM-DD"
            internal {
              contacts {
                email: "..."
              }
              contacts {
                email: "..."
              }
            }
          }
          policy {
            cookies_allowed: NO/YES
            setting: "..."
            chrome_policy {
              [POLICY_NAME] {
                  [POLICY_NAME]: ...
              }
            }
            policy_exception_justification: "..."
          }
        )");

Running the Auditor

After adding or updating an annotation, you MUST verify it using the auditor.py script. Explain to the user what you're about to do, and why you're doing it.

2. Build Chrome

You MUST ask the user which directory to use as the build path before proceeding.

Ensure you have a fresh build of the chrome target. For instance with autoninja -C out/<build_path> chrome, replacing out/<build_path> with the build path.

3. Run the Auditor

Use the same build_path where you just built chrome.

bash
vpython3 tools/traffic_annotation/scripts/auditor/auditor.py --build-path=out/<build_path>
Pre-conditions

The auditor.py script cannot run under these conditions. If any of these conditions are true, auditor.py will fail with an explanation of why. If any of these are tru, you MUST abort immediately and inform the user:

  • You are not running inside a Git repository.
  • You are not running on Linux or Windows.

If you abort, the user has two options:

  • Patch their change into a Git repository (on Linux/Windows), so they can run auditor.py locally.
  • Upload their CL to Gerrit, and do a CQ dry run.

Inform the user of their options, and don't do anything else.

4. Update Summary Files

The auditor will inform you if you need to update tools/traffic_annotation/summary/annotations.xml or grouping.xml.

5. Update Platform List

For new annotations, auditor.py creates an entry in annotations.xml. The entry is populated with a "default" list of target platforms, which may or may not be accurate.

xml
 <item id="..." ... os_list="linux,windows,android,chromeos" ... />

Update os_list to match the actual list of target platforms. It should be based on BUILD.gn files; or, if you can't figure it out from BUILD.gn files, ask the user directly.

The only valid platforms for os_list are:

  • linux
  • windows
  • chromeos
  • android

macOS and iOS are not a valid platforms in this context. If the user mentions macOS or iOS, just ignore it.

© nwjs, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in agents/skills/network-traffic-annotations of nwjs/chromium.src.

  • SKILL.md
  • OWNERS

Open the folder on GitHubat commit a9e8946

Compare with similar skills

Network Traffic Annotations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Network Traffic Annotations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Network Traffic Annotations this skillnwjs/chromium.src160—~1.6kAutomated safety check: PassBSD-3-Clause
Istio Traffic Managementwshobson/agents40k9 repos~1.7kAutomated safety check: PassMIT
Secrets Managementdavila7/claude-code-templates32k12 repos~2kAutomated safety check: PassMIT
Arize Annotationgithub/awesome-copilot40k1 repos~2.7kAutomated safety check: NotesMIT
Project ManagerRightNow-AI/openfang18k—~960Automated safety check: PassApache-2.0
Content Management Systemsgithub/awesome-copilot40k1 repos~1.3kAutomated safety check: PassMIT

Similar skills

  • Configure Istio traffic management including routing, load balancing, circuit breakers, and canary deployments.

    40k GitHub starsUsed in 9 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    32k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Arize Annotation

    github/awesome-copilot

    Official

    Creates and manages annotation configs (categorical, continuous, freeform label schemas) and annotation queues (human review workflows) on Arize.

    40k GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: notes
  • Project Manager

    RightNow-AI/openfang

    Project management expert for Agile, estimation, risk management, and stakeholder communication

    18k GitHub stars~960 tokensUpdated 3 mo ago
    Product & Project ManagementAuto-check passed
  • Content Management Systems

    github/awesome-copilot

    Official

    Workflow for building and modifying content management systems across WordPress, Shopify, Wix, Squarespace, Drupal, WooCommerce, Joomla, HubSpot CMS Hub, Webflow, Adobe Experience Manager, and…

    40k GitHub starsUsed in 1 repo~1.3k tokens
    Sales & SupportAuto-check passed
  • Wireframe Annotated

    nexu-io/open-design

    An annotated / redline lo-fi wireframe — a desktop landing/marketing page drawn as flat greyboxes inside a browser chrome frame, overlaid with numbered annotation pins (①②③④⑤) in a single accent…

    100k GitHub stars~960 tokensUpdated today
    Frontend & DesignAuto-check passed

More from nwjs/chromium.src

All 64 skills in this repo
  • Analyzing SQL Traces

    nwjs/chromium.src

    Extracts raw trace data from Perfetto traces, runs arbitrary SQL queries for custom follow-up analysis, and applies expert cognitive principles (Tiered Flow Analysis, Semantic Mismatch, Redundancy)…

    160 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Autonomous multi-agent performance optimization loop for Chromium and V8.

    160 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • Automated Tracing

    nwjs/chromium.src

    Automated Tracing & Performance Telemetry in Chromium using Perfetto and Telemetry benchmarks.

    160 GitHub stars~1.5k tokensUpdated 4 days ago
    Auto-check passed
  • Chrome Releases

    nwjs/chromium.src

    Queries Chrome commit, version, release, and milestone metadata.

    160 GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed
  • Chromium Docs

    nwjs/chromium.src

    Search and reference Chromium documentation from the local docs index, including design docs, APIs, and development guides.

    160 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed
  • Gn Deps Debugging

    nwjs/chromium.src

    Diagnose Chromium GN dependency and include-visibility failures, including BUILD.gn deps/publicdeps, DEPS include rules, private headers, and circular dependencies.

    160 GitHub stars~1.5k tokensUpdated 4 days ago
    Auto-check passed

Questions about Network Traffic Annotations

What does Network Traffic Annotations do?

Guide for writing and managing Network Traffic Annotations in Chromium. src. Guide for writing and managing Network Traffic Annotations in Chromium.

When should I use Network Traffic Annotations?

Network Traffic Annotations fits situations like: updating code that makes network requests.

How do I install Network Traffic Annotations in Claude Code?

Run `npx skills add nwjs/chromium.src --skill network-traffic-annotations -a claude-code`. Or copy the skill folder (agents/skills/network-traffic-annotations in nwjs/chromium.src) into .claude/skills/network-traffic-annotations in your project. Claude Code loads it when a task matches its description.

How do I install Network Traffic Annotations in Codex?

Run `npx skills add nwjs/chromium.src --skill network-traffic-annotations -a codex`. Or copy the skill folder (agents/skills/network-traffic-annotations in nwjs/chromium.src) into .agents/skills/network-traffic-annotations in your project. Codex loads it when a task matches its description.

Can I use Network Traffic Annotations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nwjs/chromium.src --skill network-traffic-annotations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/network-traffic-annotations, .gemini/skills/network-traffic-annotations, .github/skills/network-traffic-annotations and .opencode/skills/network-traffic-annotations in your project.

What does Network Traffic Annotations need to run?

SKILL.md names no scripts, command-line tools or credentials: Network Traffic Annotations is instructions for the agent only.

Does Network Traffic Annotations access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Network Traffic Annotations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Network Traffic Annotations use?

Network Traffic Annotations is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Network Traffic Annotations use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Network Traffic Annotations?

Skills that share tags, products or a category with Network Traffic Annotations: Istio Traffic Management (wshobson/agents, 40k stars), Secrets Management (davila7/claude-code-templates, 32k stars), Arize Annotation (github/awesome-copilot, 40k stars) and Project Manager (RightNow-AI/openfang, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Network Traffic Annotations?

nwjs (a GitHub organization) maintains it in nwjs/chromium.src, which has 160 GitHub stars. The repository holds 64 skills in this directory. The repository was last updated on October 3, 2026.

Source: nwjs/chromium.src on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.