Agent skill

Supply Chain

by padamson in padamson/playwright-rust

Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops.

Apache-2.0Auto-check passedTesting & QA

Install Supply Chain

skills CLI
$ npx skills add padamson/playwright-rust --skill supply-chain -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install padamson/playwright-rust supply-chain --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/padamson/playwright-rust.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/supply-chain .claude/skills/supply-chain && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supply-chain
GitHub stars
157
Token cost
~722 tokens
SKILL.md length
338 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops.

  • Works in 5 steps: Bump version = "X.Y.Z" in workspace… → Run cargo vet regenerate unpublished —… → If cargo vet still fails (the chain may… → …
  • Tasks that involve Supply chain security
  • SKILL.md covers When bumping our own version, When external dependencies… and Security advisories (cargo…
  • Calls cargo

What it does

Supply Chain is an agent skill from padamson/playwright-rust. Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops.

Its SKILL.md is about 720 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Supply chain security and Browser testing. It works with Rust and Playwright. The repository describes itself as: Rust language bindings for Microsoft Playwright. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Supply chain security
  • Tasks that involve Browser testing

Example prompts

  • “/supply-chain”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Bump version = "X.Y.Z" in workspace Cargo.toml
  2. Run cargo vet regenerate unpublished — automatically removes
  3. If cargo vet still fails (the chain may break when prior versions
  4. Verify cargo vet, cargo audit, cargo deny check all pass
  5. Commit Cargo.toml, Cargo.lock, supply-chain/imports.lock, and

What it can do on your machine

Read from SKILL.md and the folder at commit 6559897. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supply Chain loads about 722 tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 338 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~722

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from padamson/playwright-rust at commit 6559897, republished under its Apache-2.0 licence (© padamson). 338 words, ~722 tokens.

Download SKILL.mdSave it as .claude/skills/supply-chain/SKILL.md (or your agent's skills folder).
name
supply-chain
description
Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops.
metadata.internal
true

Supply Chain & Release Hygiene

The project uses three complementary supply-chain tools:

  • cargo audit — vulnerability advisories from RustSec
  • cargo deny — license, duplicate, and source policy
  • cargo vet — explicit audit chain for every dependency

All three run in CI on every push and every dependabot PR. Treat their output as load-bearing — a real cargo audit failure is a security advisory and warrants a patch release; a cargo vet failure usually means an audit chain needs re-stitching after a version change.

When bumping our own version

supply-chain/imports.lock is generated, never hand-edited. The header comment says # cargo-vet imports lock. The [[unpublished.playwright-rs]] entries handle the chicken-and-egg window between bumping Cargo.toml and publishing to crates.io: an entry like version = "0.12.1" audited_as = "0.12.0" tells vet "treat the in-tree version as audited at the prior released version's level."

Proper sequence when bumping Cargo.toml:

  1. Bump version = "X.Y.Z" in workspace Cargo.toml
  2. Run cargo vet regenerate unpublished — automatically removes entries for now-published versions and adds a new [[unpublished]] entry chained to the prior version
  3. If cargo vet still fails (the chain may break when prior versions get published and lose their [[unpublished]] placeholder), bump the [[exemptions.playwright-rs]] version = "..." line in supply-chain/config.toml to the latest published version. The exemption is the anchor that the unpublished entries chain to.
  4. Verify cargo vet, cargo audit, cargo deny check all pass
  5. Commit Cargo.toml, Cargo.lock, supply-chain/imports.lock, and any supply-chain/config.toml exemption bump together

When external dependencies update (dependabot PRs)

Dependabot PRs that bump external crates often surface "missing [safe-to-deploy]" or "missing [safe-to-run]" failures from cargo vet. Resolve by either:

  • Running cargo vet diff <crate> <old> <new> and cargo vet certify to record an explicit audit (preferred for small, reviewable diffs), or
  • Adding an exemption in supply-chain/config.toml (acceptable for well-known crates with negligible delta — match the existing exemption style).

Security advisories (cargo audit failures)

A new RUSTSEC-YYYY-NNNN advisory against a transitive dependency warrants a patch release even if functional behavior is unchanged. The typical fix is cargo update -p <vulnerable-crate> to a patched version, plus a CHANGELOG ### Security entry referencing the advisory.

© padamson, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/supply-chain of padamson/playwright-rust.

Open the folder on GitHubat commit 6559897

Compare with similar skills

Supply Chain next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supply Chain compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supply Chain this skillpadamson/playwright-rust157—~722Automated safety check: PassApache-2.0
Playwright Component Testingmellowagain/gitarena1151 repos~2.6kAutomated safety check: PassMIT
Trust Remote BuilderjohannesPettersson80/trust-platform222—~2kAutomated safety check: PassApache-2.0
Playwright Tracemellowagain/gitarena1151 repos~1.2kAutomated safety check: PassMIT
Hydra Devstreamband/hydra-srt147—~995Automated safety check: PassApache-2.0
Openlark API Field Verifyfoxzool/openlark106—~2.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Playwright Component Testing

    mellowagain/gitarena

    Set up component testing with Playwright using a story gallery — scaffold stories and a gallery dev page driven by the built-in mount fixture, no dedicated component-testing runtime.

    115 GitHub starsUsed in 1 repo~2.6k tokens
    Testing & QAAuto-check passed
  • Trust Remote Builder

    johannesPettersson80/trust-platform

    Runs truST builds and tests on the shared trust-builder machine.

    222 GitHub stars~2k tokensUpdated today
    Testing & QAAuto-check passed
  • Playwright Trace

    mellowagain/gitarena

    Inspect Playwright trace files from the command line — list actions, view requests, console, errors, snapshots and screenshots.

    115 GitHub starsUsed in 1 repo~1.2k tokens
    Testing & QAAuto-check passed
  • Hydra Dev

    streamband/hydra-srt

    Run HydraSRT development workflows: mix q quality gate, Elixir unit/E2E tests, native Rust tests, web Vitest/Playwright, and make dev.

    147 GitHub stars~995 tokensUpdated 24 days ago
    Testing & QAAuto-check passed
  • OpenLark API 字段核对技能。用于新增/重构飞书 API 后,核对 Rust 实现的请求体/响应体字段是否与飞书官方文档一致。通过 playwright 渲染飞书 SPA 文档页面,提取真实的请求/响应字段定义,对比代码实现找出不符项。触发关键词:字段核对、字段验证、字段不符、文档核对、核对请求字段、核对响应字段、飞书文档字段、推断字段、user 级接口、用户级接口字段

    106 GitHub stars~2.3k tokensUpdated yesterday
    Testing & QAAuto-check: notes
  • Web Application Testing

    anthropics/skills

    Official

    Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.

    180k GitHub starsUsed in 51 repos~966 tokens
    Testing & QAAuto-check passed

More from padamson/playwright-rust

  • Playwright Rs Usage

    padamson/playwright-rust

    Procedural reference for using playwright-rs in Rust browser-automation code — object model (Browser/Context/Page/Locator), the locator!() macro, builder pattern for options, auto-wait semantics…

    157 GitHub stars~5.5k tokensUpdated today
    Auto-check passed
  • Doctest Conventions

    padamson/playwright-rust

    Conventions for authoring rustdoc doctests in playwright-rust — the norun annotation, module-level placement, hidden scaffolding lines, and how doctests are exercised in CI vs pre-commit.

    157 GitHub stars~749 tokensUpdated today
    Auto-check passed
  • Release Process

    padamson/playwright-rust

    End-to-end release runbook for playwright-rust — version bump, supply-chain refresh, per-crate CHANGELOGs, tag-prefix routing for the three workspace crates, the safer push-then-tag workflow that…

    157 GitHub stars~4.1k tokensUpdated today
    Auto-check passed

Works with

Questions about Supply Chain

What does Supply Chain do?

Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops. Supply Chain is an agent skill from padamson/playwright-rust. Procedure for keeping playwright-rust's cargo audit / cargo deny / cargo vet checks green when bumping the project's own version, when external crates change, and when a security advisory drops.

When should I use Supply Chain?

Supply Chain fits situations like: tasks that involve Supply chain security; tasks that involve Browser testing.

How do I install Supply Chain in Claude Code?

Run `npx skills add padamson/playwright-rust --skill supply-chain -a claude-code`. Or copy the skill folder (.claude/skills/supply-chain in padamson/playwright-rust) into .claude/skills/supply-chain in your project. Claude Code loads it when a task matches its description.

How do I install Supply Chain in Codex?

Run `npx skills add padamson/playwright-rust --skill supply-chain -a codex`. Or copy the skill folder (.claude/skills/supply-chain in padamson/playwright-rust) into .agents/skills/supply-chain in your project. Codex loads it when a task matches its description.

Can I use Supply Chain in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add padamson/playwright-rust --skill supply-chain -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supply-chain, .gemini/skills/supply-chain, .github/skills/supply-chain and .opencode/skills/supply-chain in your project.

What does Supply Chain need to run?

Going by SKILL.md and its folder, Supply Chain needs the command-line tools its instructions call (cargo).

Does Supply Chain access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Supply Chain safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supply Chain use?

Supply Chain is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supply Chain use?

About 722 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Supply Chain?

Skills that share tags, products or a category with Supply Chain: Playwright Component Testing (mellowagain/gitarena, 115 stars), Trust Remote Builder (johannesPettersson80/trust-platform, 222 stars), Playwright Trace (mellowagain/gitarena, 115 stars) and Hydra Dev (streamband/hydra-srt, 147 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supply Chain?

padamson (a GitHub user) maintains it in padamson/playwright-rust, which has 157 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 9, 2026.

Source: padamson/playwright-rust on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.