Agent Skillssupercheck-io/supercheck › supercheck-integrations-extensions

supercheck-integrations-extensions

GitHub

负责Supercheck浏览器录制扩展、应用桥接、Chrome/Edge发布及第三方集成的开发与维护。涵盖安全通信协议、许可证管理及构建流程,确保跨端集成与数据交互的合规性。

.agents/skills/integrations-extensions/SKILL.md supercheck-io/supercheck

Trigger Scenarios

开发或修改浏览器扩展功能 处理应用与扩展间的API通信 配置Chrome或Edge商店发布流程 集成第三方支付或聊天服务

Install

npx skills add supercheck-io/supercheck --skill supercheck-integrations-extensions -g -y
More Options

Non-standard path

npx skills add https://github.com/supercheck-io/supercheck/tree/main/.agents/skills/integrations-extensions -g -y

Use without installing

npx skills use supercheck-io/supercheck@supercheck-integrations-extensions

指定 Agent (Claude Code)

npx skills add supercheck-io/supercheck --skill supercheck-integrations-extensions -a claude-code -g -y

安装 repo 全部 skill

npx skills add supercheck-io/supercheck --all -g -y

预览 repo 内 skill

npx skills add supercheck-io/supercheck --list

SKILL.md

Frontmatter
{
    "name": "supercheck-integrations-extensions",
    "description": "Work on the Supercheck recorder extension and app bridge, Chrome or Edge publishing, Polar billing and entitlements, customer support chat, or other third-party integration boundaries."
}

Supercheck integrations and extensions

Recorder architecture

The recorder is an Apache-2.0 browser extension built from Playwright CRX and vendored Playwright source. Supercheck-specific app integration lets users record browser interactions and save generated Playwright tests.

sequenceDiagram
  participant App as Supercheck app
  participant Page as Trusted page API
  participant CS as Content script
  participant BG as Extension worker
  App->>Page: validated connection/recording request
  Page->>CS: exact-origin window message
  CS->>BG: validated extension message
  BG-->>CS: state or generated recording
  CS-->>Page: sender-bound response
  Page-->>App: validated result

Source and build map

Path Responsibility
recorder/src Playwright CRX library/client/server implementation
recorder/playwright Vendored build-required Playwright source and licenses
recorder/examples/recorder-crx Supercheck recorder extension
recorder/examples/todomvc-crx Library example
recorder/tests Unit, extension, and browser suites
app/src/components/recorder App UI and auto-connect bridge
app/src/app/api/extension Extension-facing API
app/src/app/api/recordings Recording persistence API

Security contract

  • The page bridge/content script accepts only event.source === window, parsed allowed origins, expected protocol/hostname, and schema-valid messages.
  • Allow HTTPS Supercheck origins, exact HTTP localhost development, and the exact configured self-hosted origin—never arbitrary HTTP/HTTPS pages.
  • Use window.location.origin or another verified exact origin as postMessage target; never * for privileged data.
  • Bind return/callback URLs to the verified sender origin and restrict navigated/recorded target protocols.
  • Inject the page API only on trusted Supercheck pages. Do not add broad externally_connectable access.
  • Keep extension permissions/host permissions minimal and validate all background/content/page boundaries independently.
  • Retry only idempotent API methods and preserve authentication/error behavior without exposing tokens.

Licensing and release

  • Preserve recorder/LICENSE, recorder/NOTICE, recorder/playwright/LICENSE, recorder/playwright/NOTICE, and upstream file headers.
  • Do not relicense Playwright-derived recorder files as AGPL. App, worker, CLI, and docs remain AGPL-3.0-only.
  • The vendored source must be enough for a clean reproducible build without another private checkout.
  • Build lint, vendored bundles, generated types, CRX library, recorder/TodoMVC examples, and test extension.
  • Run unit security and browser suites. Local browser fixture limitations must be disclosed; CI/Linux and manual installed-extension acceptance remain release gates.
  • Chrome and Edge store descriptions/assets/certification are separate. Edge submission copy must not describe the product as a Chrome extension.
  • Store publishing requires manual account/2FA/reviewer gates and uses canonical listing IDs/URLs from current public docs.

Polar billing

flowchart LR
  ORG[Organization] --> CUSTOMER[Organization-scoped customer]
  CUSTOMER --> SUB[Subscription lifecycle]
  CHECKOUT[Checkout] --> SUB
  WEBHOOK[Verified webhook] --> LEDGER[Idempotent local state]
  USAGE[Durable usage event] --> PROVIDER[Polar meter/event]
  SUB --> ENT[Server-side entitlements]
  • Polar customer identity is organization-scoped, using the current organization external identity. Never collapse multiple organizations under a user-scoped customer.
  • Checkout and customer portal requests authenticate the user, resolve the organization, authorize billing management (normally organization owner), and use configured product/price references.
  • Webhooks verify signatures, deduplicate by provider event identity, tolerate retries/reordering, and update local state transactionally/idempotently.
  • Subscription status, plan, period, cancellation, and entitlement behavior come from durable server state synchronized from verified provider events.
  • Entitlements and limits are enforced server-side. UI labels/buttons are not authorization.
  • Usage is durably recorded server-side before or atomically with provider delivery and retried safely without duplicate billing.
  • Use whole-cent currency arithmetic and explicit units. Never rely on floating-point money or silently mix credits/events/cents.
  • Polling stops on success, terminal failure, cancellation/navigation, and timeout.
  • Never automatically mutate live products/prices, attach overage prices, migrate customers, or make paid actions without explicit authorization and invoice/recovery analysis.
  • Provider product IDs, prices, tax settings, limits, and UI are drift-prone; verify them in the provider environment.

Billing acceptance

  • Test organization isolation, shared-user/multiple-org customer identity, checkout, webhook replay/reordering, upgrade/downgrade, cancellation, expiry, recovery, portal, invoice, usage retries, and entitlement transitions.
  • Automated/local tests do not replace sandbox/live provider acceptance and invoice inspection.

Customer support chat and third parties

  • Load support scripts only when configured and under applicable consent/privacy policy.
  • Keep tokens and identity-verification secrets server-side. Do not send tenant secrets, auth tokens, sensitive route data, or private incident content to chat by default.
  • Verify inbound signatures, validate payloads, rate-limit callbacks, and make processing idempotent.
  • Provider plan, branding, pricing, privacy, and hosting claims change; verify current terms before product decisions.

Verify

  • Test every trust boundary and cross-tenant denial.
  • Test provider retries, malformed/signed-invalid callbacks, cancellation, cleanup, and redaction.
  • Separate source/unit evidence from browser store, provider account, invoice, and production acceptance.

Version History

  • 974a753 Current 2026-09-22 16:21

Same Skill Collection

.agents/skills/architecture/SKILL.md
.agents/skills/code-review/SKILL.md
.agents/skills/data-storage/SKILL.md
.agents/skills/execution-engine/SKILL.md
.agents/skills/feature-implementation/SKILL.md
.agents/skills/infrastructure-deployment/SKILL.md
.agents/skills/monitoring-alerts/SKILL.md
.agents/skills/platform-features/SKILL.md
.agents/skills/security-auth/SKILL.md
.agents/skills/sre-operations/SKILL.md
.agents/skills/testing-qa/SKILL.md
.github/skills/code-review/SKILL.md
.github/skills/docker-compose-deployment/SKILL.md
.github/skills/feature-implementation/SKILL.md

Metadata

Files
0
Version
974a753
Hash
7076579a
Indexed
2026-09-22 16:21

- 위키
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-09-23 14:08
浙ICP备14020137号-1