Agent skill

Supercheck Integrations Extensions

by supercheck-io in supercheck-io/supercheck

Work on the Supercheck recorder extension and app bridge, Chrome or Edge publishing, Polar billing and entitlements, customer support chat, or other third-party integration boundaries.

AGPL-3.0Auto-check passedData & Analytics

Install Supercheck Integrations Extensions

skills CLI
$ npx skills add supercheck-io/supercheck --skill supercheck-integrations-extensions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install supercheck-io/supercheck supercheck-integrations-extensions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/supercheck-io/supercheck.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/integrations-extensions .claude/skills/supercheck-integrations-extensions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supercheck-integrations-extensions
GitHub stars
215
Token cost
~1.6k tokens
SKILL.md length
583 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Work on the Supercheck recorder extension and app bridge, Chrome or Edge publishing, Polar billing and entitlements, customer support chat, or other third-party integration boundaries.

  • Tasks that involve DataFrames
  • SKILL.md covers Recorder architecture, Polar billing, Customer support chat and… and Verify
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Customer support

What it does

Supercheck Integrations Extensions is an agent skill from supercheck-io/supercheck. Work on the Supercheck recorder extension and app bridge, Chrome or Edge publishing, Polar billing and entitlements, customer support chat, or other third-party integration boundaries.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Data & Analytics, covering DataFrames and Customer support. It works with Playwright. The repository describes itself as: Open-Source Testing, Monitoring, and AI SRE — as Code. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve DataFrames
  • Tasks that involve Customer support

Example prompts

  • “/supercheck-integrations-extensions”

What it can do on your machine

Read from SKILL.md and the folder at commit 0c077d0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are mermaid).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supercheck Integrations Extensions loads about 1.6k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 583 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from supercheck-io/supercheck at commit 0c077d0, republished under its AGPL-3.0 licence (© supercheck-io). 583 words, ~1,558 tokens.

Download SKILL.mdSave it as .claude/skills/supercheck-integrations-extensions/SKILL.md (or your agent's skills folder).
name
supercheck-integrations-extensions
description
Work on the Supercheck recorder extension and app bridge, Chrome or Edge publishing, Polar billing and entitlements, customer support chat, or other third-party integration boundaries.

Supercheck integrations and extensions

Recorder architecture

The recorder is an Apache-2.0 browser extension built from Playwright CRX and vendored Playwright source. Supercheck-specific app integration lets users record browser interactions and save generated Playwright tests.

mermaid
sequenceDiagram
  participant App as Supercheck app
  participant Page as Trusted page API
  participant CS as Content script
  participant BG as Extension worker
  App->>Page: validated connection/recording request
  Page->>CS: exact-origin window message
  CS->>BG: validated extension message
  BG-->>CS: state or generated recording
  CS-->>Page: sender-bound response
  Page-->>App: validated result
Source and build map
PathResponsibility
recorder/srcPlaywright CRX library/client/server implementation
recorder/playwrightVendored build-required Playwright source and licenses
recorder/examples/recorder-crxSupercheck recorder extension
recorder/examples/todomvc-crxLibrary example
recorder/testsUnit, extension, and browser suites
app/src/components/recorderApp UI and auto-connect bridge
app/src/app/api/extensionExtension-facing API
app/src/app/api/recordingsRecording persistence API
Security contract
  • The page bridge/content script accepts only event.source === window, parsed allowed origins, expected protocol/hostname, and schema-valid messages.
  • Allow HTTPS Supercheck origins, exact HTTP localhost development, and the exact configured self-hosted origin—never arbitrary HTTP/HTTPS pages.
  • Use window.location.origin or another verified exact origin as postMessage target; never * for privileged data.
  • Bind return/callback URLs to the verified sender origin and restrict navigated/recorded target protocols.
  • Inject the page API only on trusted Supercheck pages. Do not add broad externally_connectable access.
  • Keep extension permissions/host permissions minimal and validate all background/content/page boundaries independently.
  • Retry only idempotent API methods and preserve authentication/error behavior without exposing tokens.
Licensing and release
  • Preserve recorder/LICENSE, recorder/NOTICE, recorder/playwright/LICENSE, recorder/playwright/NOTICE, and upstream file headers.
  • Do not relicense Playwright-derived recorder files as AGPL. App, worker, CLI, and docs remain AGPL-3.0-only.
  • The vendored source must be enough for a clean reproducible build without another private checkout.
  • Build lint, vendored bundles, generated types, CRX library, recorder/TodoMVC examples, and test extension.
  • Run unit security and browser suites. Local browser fixture limitations must be disclosed; CI/Linux and manual installed-extension acceptance remain release gates.
  • Chrome and Edge store descriptions/assets/certification are separate. Edge submission copy must not describe the product as a Chrome extension.
  • Store publishing requires manual account/2FA/reviewer gates and uses canonical listing IDs/URLs from current public docs.
Show full SKILL.md (295 more words)Show less

Polar billing

mermaid
flowchart LR
  ORG[Organization] --> CUSTOMER[Organization-scoped customer]
  CUSTOMER --> SUB[Subscription lifecycle]
  CHECKOUT[Checkout] --> SUB
  WEBHOOK[Verified webhook] --> LEDGER[Idempotent local state]
  USAGE[Durable usage event] --> PROVIDER[Polar meter/event]
  SUB --> ENT[Server-side entitlements]
  • Polar customer identity is organization-scoped, using the current organization external identity. Never collapse multiple organizations under a user-scoped customer.
  • Checkout and customer portal requests authenticate the user, resolve the organization, authorize billing management (normally organization owner), and use configured product/price references.
  • Webhooks verify signatures, deduplicate by provider event identity, tolerate retries/reordering, and update local state transactionally/idempotently.
  • Subscription status, plan, period, cancellation, and entitlement behavior come from durable server state synchronized from verified provider events.
  • Entitlements and limits are enforced server-side. UI labels/buttons are not authorization.
  • Usage is durably recorded server-side before or atomically with provider delivery and retried safely without duplicate billing.
  • Use whole-cent currency arithmetic and explicit units. Never rely on floating-point money or silently mix credits/events/cents.
  • Polling stops on success, terminal failure, cancellation/navigation, and timeout.
  • Never automatically mutate live products/prices, attach overage prices, migrate customers, or make paid actions without explicit authorization and invoice/recovery analysis.
  • Provider product IDs, prices, tax settings, limits, and UI are drift-prone; verify them in the provider environment.
Billing acceptance
  • Test organization isolation, shared-user/multiple-org customer identity, checkout, webhook replay/reordering, upgrade/downgrade, cancellation, expiry, recovery, portal, invoice, usage retries, and entitlement transitions.
  • Automated/local tests do not replace sandbox/live provider acceptance and invoice inspection.

Customer support chat and third parties

  • Load support scripts only when configured and under applicable consent/privacy policy.
  • Keep tokens and identity-verification secrets server-side. Do not send tenant secrets, auth tokens, sensitive route data, or private incident content to chat by default.
  • Verify inbound signatures, validate payloads, rate-limit callbacks, and make processing idempotent.
  • Provider plan, branding, pricing, privacy, and hosting claims change; verify current terms before product decisions.

Verify

  • Test every trust boundary and cross-tenant denial.
  • Test provider retries, malformed/signed-invalid callbacks, cancellation, cleanup, and redaction.
  • Separate source/unit evidence from browser store, provider account, invoice, and production acceptance.

© supercheck-io, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/integrations-extensions of supercheck-io/supercheck.

Open the folder on GitHubat commit 0c077d0

Compare with similar skills

Supercheck Integrations Extensions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supercheck Integrations Extensions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supercheck Integrations Extensions this skillsupercheck-io/supercheck215—~1.6kAutomated safety check: PassAGPL-3.0
Python Executorcortega26/chile-hub1132 repos~1.5kAutomated safety check: PassMIT
Verifier Webpolarsource/polar10k—~3kAutomated safety check: NotesMIT
Chdb Datastorevemetric/vemetric3942 repos~1.4kAutomated safety check: PassApache-2.0
Polar Python SDKpolarsource/polar10k—~1.8kAutomated safety check: PassApache-2.0
AnakinscraperAnakin-Inc/anakin4.5k—~859Automated safety check: PassAGPL-3.0

Similar skills

  • Python Executor

    cortega26/chile-hub

    Execute Python code in a safe sandboxed environment via [inference.sh](https://inference.sh).

    113 GitHub starsUsed in 2 repos~1.5k tokens
    Data & AnalyticsAuto-check passed
  • Verifier Web

    polarsource/polar

    Evidence-capture protocol for verifying web/dashboard/backoffice/checkout changes in the Polar local stack by driving the real UI with Playwright.

    10k GitHub stars~3k tokensUpdated today
    Data & AnalyticsAuto-check: notes
  • Chdb Datastore

    vemetric/vemetric

    A skill your agent uses when the user has tabular data (pandas DataFrame, parquet, csv, Arrow, json) and wants to filter, group, aggregate, join, or speed up slow pandas.

    394 GitHub starsUsed in 2 repos~1.4k tokens
    Data & AnalyticsAuto-check passed
  • Polar Python SDK

    polarsource/polar

    Integrate Polar billing in server-side Python applications using the versioned Polar and PolarAsync clients.

    10k GitHub stars~1.8k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Anakinscraper

    Anakin-Inc/anakin

    Scrape any website into clean markdown or structured JSON. An agent skill from Anakin-Inc/anakin.

    4.5k GitHub stars~859 tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Polar Typescript SDK

    polarsource/polar

    Integrate Polar billing in server-side TypeScript applications using the versioned createPolar and createPolarCore clients.

    10k GitHub stars~2k tokensUpdated today
    Data & AnalyticsAuto-check passed

More from supercheck-io/supercheck

All 12 skills in this repo
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Supercheck Architecture

    supercheck-io/supercheck

    Work on Supercheck system architecture, Next.js routes and actions, React data hooks, Drizzle schemas and migrations, app-worker boundaries, or cross-package contracts.

    215 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Supercheck Code Review

    supercheck-io/supercheck

    Review Supercheck staged, unstaged, commit, branch, or pull-request changes for correctness, regressions, security, tenancy, architecture, tests, docs, licensing, and commit/merge/release readiness.

    215 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Supercheck Data Storage

    supercheck-io/supercheck

    Work on Supercheck PostgreSQL data, S3 or MinIO artifacts, signed URLs and asset proxying, retention cleanup, dashboard/report queries, exports, or audit logging.

    215 GitHub stars~942 tokensUpdated today
    Auto-check passed
  • Supercheck Execution Engine

    supercheck-io/supercheck

    Work on Supercheck BullMQ queues, schedulers, capacity management, Playwright or k6 execution, monitors, dynamic locations, cancellation, Redis, Kubernetes Jobs, gVisor, or app-worker execution…

    215 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Supercheck Feature Implementation

    supercheck-io/supercheck

    Implement a new or changed Supercheck feature end to end across schema, auth/RBAC, services, routes/actions, UI, queues/workers, CLI/recorder, tests, docs, and deployment contracts.

    215 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Questions about Supercheck Integrations Extensions

What does Supercheck Integrations Extensions do?

Work on the Supercheck recorder extension and app bridge, Chrome or Edge publishing, Polar billing and entitlements, customer support chat, or other third-party integration boundaries. Supercheck Integrations Extensions is an agent skill from supercheck-io/supercheck. Work on the Supercheck recorder extension and app bridge, Chrome or Edge publishing, Polar billing and entitlements, customer support chat, or other third-party integration boundaries.

When should I use Supercheck Integrations Extensions?

Supercheck Integrations Extensions fits situations like: tasks that involve DataFrames; tasks that involve Customer support.

How do I install Supercheck Integrations Extensions in Claude Code?

Run `npx skills add supercheck-io/supercheck --skill supercheck-integrations-extensions -a claude-code`. Or copy the skill folder (.agents/skills/integrations-extensions in supercheck-io/supercheck) into .claude/skills/supercheck-integrations-extensions in your project. Claude Code loads it when a task matches its description.

How do I install Supercheck Integrations Extensions in Codex?

Run `npx skills add supercheck-io/supercheck --skill supercheck-integrations-extensions -a codex`. Or copy the skill folder (.agents/skills/integrations-extensions in supercheck-io/supercheck) into .agents/skills/supercheck-integrations-extensions in your project. Codex loads it when a task matches its description.

Can I use Supercheck Integrations Extensions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add supercheck-io/supercheck --skill supercheck-integrations-extensions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supercheck-integrations-extensions, .gemini/skills/supercheck-integrations-extensions, .github/skills/supercheck-integrations-extensions and .opencode/skills/supercheck-integrations-extensions in your project.

What does Supercheck Integrations Extensions need to run?

SKILL.md names no scripts, command-line tools or credentials: Supercheck Integrations Extensions is instructions for the agent only.

Does Supercheck Integrations Extensions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Supercheck Integrations Extensions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supercheck Integrations Extensions use?

Supercheck Integrations Extensions is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supercheck Integrations Extensions use?

About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Supercheck Integrations Extensions?

Skills that share tags, products or a category with Supercheck Integrations Extensions: Python Executor (cortega26/chile-hub, 113 stars), Verifier Web (polarsource/polar, 10k stars), Chdb Datastore (vemetric/vemetric, 394 stars) and Polar Python SDK (polarsource/polar, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supercheck Integrations Extensions?

supercheck-io (a GitHub organization) maintains it in supercheck-io/supercheck, which has 215 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.

Source: supercheck-io/supercheck on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.