Electronics Industry Sites Skillpack
Public Made by Adomby adom
One skill per popular electronics-industry website (ST, TI, Mouser, DigiKey, SnapEDA, Ultra Librarian, Arrow, Analog, Microchip, Nordic, CSE, Octopart, JLCPCB, datasheets.com): which access lane works (fetch, curl, pup, nb, API), the bot defense each one runs, the exact failure signatures, and the task recipes. Verified live, dated, and built to grow.
efe5584
16d ago
name: electronics-sites description: >- THE map of how electronics-industry websites treat AI clients, one sub-skill per site (ST, TI, Mouser, DigiKey, SnapEDA, Ultra Librarian, Arrow, Analog, Microchip, Nordic, Component Search Engine, Octopart, JLCPCB/LCSC, datasheets.com, generic manufacturer). Which access lane works (WebFetch, curl, pup, nb, official API), which bot defense each runs (Akamai, PerimeterX, Cloudflare), the exact failure signatures, and what a Chrome-for-Testing window leaks that a real browser does not. Read BEFORE fetching anything from a vendor or manufacturer domain, and the MOMENT a fetch to one times out, 403s, 473s, shows 'Just a moment', 'Access Denied', 'Access to this page has been denied', or ERR_HTTP2_PROTOCOL_ERROR. Trigger words: st.com, ti.com, mouser, digikey, snapeda, ultralibrarian, arrow, analog.com, microchip, nordicsemi, componentsearchengine, octopart, jlcpcb, lcsc, datasheets.com, vendor site blocked, manufacturer site timeout, datasheet download blocked, bot wall, cloudflare just a moment, akamai access denied, perimeterx, captcha on vendor site, which browser for this site, electronics website, electronics industry site skills.
Electronics Industry Site Skills
Nobody built skills for the electronics industry's websites, so an AI meets each one cold: a fetch to st.com times out, a pup window on DigiKey spins forever, Mouser answers HTTP 200 with a denial page, and the AI reports "the site is down" when the site is fine and only that CLIENT was refused. These vendors block anything that does not look like a person because they have not noticed the AI era yet. This pack records, per site, exactly how it behaves toward each lane we have, dated, with the evidence, so the next AI routes around the wall in one move instead of rediscovering it.
Every sub-skill has the same sections (domains, bot defense, lane matrix, failure signatures, recipes, API lane, gotchas, evidence). Verified live on 2026-09-14 from an Adom cloud container against a Windows desktop running Adom Bridge 2.1.104, pup 2.0.549 (Chrome for Testing 152, extension lane) and the Native Browser Extension 0.16.14 (Chrome 152).
Step 0, before any site: the Adom wiki
Every rung below costs a browser, a login or a captcha. The cheapest rung is the one that
needs none of them: search the wiki first. adom-wiki discover search --query <MPN> and
adom-wiki discover find <MPN>; a component page (usually adom/<mpn-lowercase>) ships the
datasheet, the reviewed symbol/footprint/.lbr, the manufacturer STEP in Z-up with FoV-on/off and
side-etched variants, the chip-outline cache and provenance. adom-wiki repo clone adom/<slug>
and reuse. Only when the page is missing or lacks the artifact you need do you go to the vendor
site, and when you come back with something new, publish it to that page (wiki-component skill)
so the next AI never repeats the trip. Verify component.mpn or the slug on a hit: search is loose.
2026-09-14 update: two causes that are NOT the page, found chasing analog.com
Two independent discoveries this date, each measured, that reframe the hardest Akamai sites:
1. WITHDRAWN: "the Chrome-for-Testing VERSION is a bot signal". An earlier revision of this pack
claimed that pinning CfT 148 against a Chrome 152 desktop is what made analog.com answer HTTP 403, and
that bumping to CfT 152 fixed it. That comparison was not controlled and the claim is withdrawn.
Every denied trial was a raw hand-rolled Chrome launch carrying a copied flag list; every passing trial
was pup itself. Those differ in infobar suppression, the feature-disable set and the identity shim, not
only in the build number. Re-measured 2026-09-14 with screenshots: analog.com renders fully in pup on
CfT 152 on the shared adom-you profile. The arm intended as a fresh jar was not one, because
isolated:true keeps that same profile (pup-bridge#112), so profile state is UNTESTED, not excluded. What IS established: these sites load when driven through pup's
own launch path, and WHICH element of that path is decisive has not been isolated. Keep the CfT pin
near the installed Chrome as cheap hygiene, not as an explanation. typeof bmak === "undefined" on a
denied page is a SYMPTOM, because the Access Denied page carries no sensor script at all. Keep CfT within ~1 milestone of the installed Chrome. Several sites
that were pup-BLOCKED on 148 (st.com among them) load on 152. Diagnostic on a denial: typeof bmak
undefined = rejected upstream (version or IP); object = the sensor ran and failed you (IP/behaviour).
2. Egress IP reputation: SUSPECTED, not established. The four-box comparison below was run with the BURST method, which we now know trips velocity rules on its own, so these readings are method-suspect and have not been reproduced paced. Treat as a hypothesis to re-test, not as fact: AdomLapper (corporate VPN egress) and winvm (Azure) LOAD analog.com; arav-rog and ConfRoomROG (bare office LAN) are DENIED. Identical browser, opposite result: the bare office NAT IP is Akamai-flagged. pup cannot fix this from inside the browser; the lever is a cleaner egress (VPN/residential/cloud) or nb on the user's own connection.
Cookie hygiene: a rejected Akamai visit writes _abck to a ~-1~ reject state that persists.
pup_clear_cookies {domain} / pup_clear_site_data {origins} before re-testing, or the stale verdict
masks a fix.
Fleet matrix (extension lane, CfT 152, 2026-09-14)
16 of 20 load on every box; the spread is the Akamai-hardened four (analog, avnet, arrow, digikey):
| Site | AdomLapper (VPN) | arav-rog (office) | ConfRoomROG (office) | winvm (Azure) |
|---|---|---|---|---|
| ST, Mouser*, TI, Microchip, Nordic, SnapEDA, UltraLib, CSE, Octopart, LCSC, JLCPCB, Newark, RS, Infineon, NXP | load | load | load | load |
| DigiKey | load | load | block | block |
| Arrow | load | block | block | block |
| Analog | load | block | block | load |
| Datasheets | load | load | load | block |
| Avnet | loads on a paced single visit; the matrix's 20-tab BURST tripped Akamai's velocity WAF (self-inflicted). Clear cookies + navigate once. |
*Mouser loads its home page but scores behaviour on crawls (DataDome) - use the API for data.
How to load ANY of these in pup (the procedure that got 20 of 20)
Measured 2026-09-14 on AdomLapper: all twenty sites in this pack loaded in pup, including the four a previous burst run had called blocked. Three conditions, all of them required:
- Match Chrome for Testing to the user's INSTALLED Chrome. Check
pup_readiness.chromeBuildIdagainst their Chrome. A stale CfT breaks Akamai's sensor outright (it never initialises) and no header work rescues it. - Go at human pace: ONE tab at a time, with a real settle (about 7 s). A burst of tabs trips velocity rules on Akamai sites (avnet, arrow, datasheets all "blocked" purely from bursting). This is the single most common self-inflicted block.
- Clear that domain's cookies before the visit. A previous denial writes a reject verdict that persists and will keep denying you long after the real cause is fixed.
Then use the default extension lane (no debug port) with the consumer identity on, which is what
pup_open_window already does. Only when all three conditions hold and a site STILL refuses is it
worth reaching for nb or the API lane.
The rule: a fetch failure on a vendor domain is a ROUTING signal
- One plain attempt only. WebFetch or curl once. It is the cheapest lane and it works on TI, community.st.com, datasheets.com (WebFetch), Octopart, JLCPCB, Infineon, Espressif.
- pup second (a real rendered Chrome, background, the durable adom-you profile). Passes Microchip, Nordic, CSE, Ultra Librarian, datasheets.com; renders vendor CDN PDFs.
- nb third and last (the user's real signed-in Chrome via nbrowser_*). Passes EVERYTHING we have tested, including the four that refuse pup (st.com after the first page, Mouser, DigiKey, SnapEDA, Analog, Arrow). Give a challenge page 9 seconds to clear before you read the DOM: a 6 s wait reads as empty and looks like a block that is not there.
- Numbers you will act on come from an API, never a scrape:
adom-parts-search show "<MPN>"(Mouser + DigiKey + JLCPCB backends, quota-limited: one search per question, never a loop).
Never retry the failing lane, never report "the site is timing out", never spoof a fingerprint. Switch lanes, then write down what you saw in that site's skill.
No account on a site? Register one for the user (John, 2026-09-19). These are free CAD/vendor
accounts, not bank logins: when a download needs a login the vault does not have, first check the
user's own browser (pup_import_browser_logins {}) and the other desktops (pup_vault_sync {peer});
if there is truly none, register with the Adom user's profile (work email, name, company), read the
verification mail through the Gmail connector, set a generated password in the same pup session and
credential_set it into the vault so the human never types it. The ST skill has the worked example.
Captchas: the AI drives them itself (John, 2026-09-19). A reCAPTCHA / Turnstile checkbox or image
grid on a download or login gate is YOUR job, not the user's: never toast, flash or wait for the human,
and never switch pup to the CDP lane for it. Trusted click on the checkbox with pup's fake cursor,
screenshot the grid, pick the tiles by vision, trusted-click them and Verify until the token fills,
then submit. On the extension lane the trusted-input verbs are tracked in adom/pup-bridge#120
(until they ship pup_input_dispatch answers lane_needs_cdp; say so plainly and take the next
lane or route). nbrowser_flash-and-wait is retired.
Symptom -> cause -> lane
| You see | It is | Do |
|---|---|---|
ERR_HTTP2_PROTOCOL_ERROR / chrome-error:// on the SECOND page of a domain in pup; curl: (92) HTTP/2 stream ... INTERNAL_ERROR in ~100 ms |
Akamai Bot Manager reset the stream after its sensor verdict (st.com, analog.com, arrow.com) | nb. Do not reload the pup tab; it stays dead for that domain |
Access Denied + Reference #18.xxxx |
Akamai deny page (analog, arrow to pup; microchip to curl) | nb (pup passes microchip; test, do not assume) |
Access to this page has been denied. with HTTP 200, or press and hold |
PerimeterX / HUMAN (mouser.com) | nb for the page, API for the data |
title Just a moment..., 263-char body, HTTP 403, cf-ray header; on digikey/snapeda a Verify you are human CHECKBOX (Turnstile) |
Cloudflare managed challenge (digikey, snapeda, CSE, nordic, datasheets.com, alldatasheet) | pup passes CSE / nordic / datasheets.com on its own; digikey + snapeda show the checkbox and never auto-clear in pup: use nb (clears in ~9 s, no click), or drive the checkbox yourself on the ext lane once adom/pup-bridge#120 ships |
| HTTP 473 | Akamai to a fetcher (newsroom.st.com) | pup or nb |
| WebFetch 60 s timeout on a vendor URL | the fetcher is being tarpitted, not an outage | pup, then nb |
captcha in the HTML but the page renders |
login / download gate (ultralibrarian, signed-in UL Pro too since 2026-09-19) | the AI drives it: trusted click + vision on the image grid (adom/pup-bridge#120); never hand it to the human |
| Chrome native "Sign in" dialog (Username / Password) on a download URL | HTTP Basic-Auth (the componentsearchengine.com family: st./ms./nxp./mouser.) | vault entry componentsearchengine.com + pup answering the challenge (adom/pup-bridge#119, not yet on the ext lane); nb answers it from the user's saved login |
renderCheck.ok:true but the body says This site can't be reached |
pup's render check does not flag chrome-error pages (adom/pup-bridge#109) | read the body yourself; switch lanes |
What pup leaks that a real browser does not (measured on st.com, 2026-09-14)
| Probe | pup (Chrome for Testing 148) | nb (installed Chrome 152) |
|---|---|---|
navigator.webdriver |
true | false |
Widevine (requestMediaKeySystemAccess('com.widevine.alpha')) |
NotSupportedError (CfT ships without the CDM) | available |
navigator.userAgentData.brands |
Not/A)Brand 99, Chromium 148 (no "Google Chrome") | Chromium 152, Not?A_Brand 24, Google Chrome 152 |
| User agent major | 148 (cached build, four majors behind) | 152 |
Notification.permission on first visit |
granted (pup pre-grants 32 permissions) | default |
Akamai _abck on first load |
||
| plugins / cores / memory / h2 | 5 / 16 / 32 GB / h2 | identical |
Both clients get the same unvalidated Akamai cookie; the verdict comes from the sensor telemetry, and webdriver + no Widevine + no Google Chrome brand is enough. A cold isolated pup profile and 15 s between requests changed nothing; the same navigation in nb returned 200. That is why the ladder ends at nb and why pup is still worth trying first on the sites that do not look this closely.
The matrix (lane 0 = curl; verified 2026-09-14)
| Site | Bot defense | WebFetch | curl | pup | nb | Use first |
|---|---|---|---|---|---|---|
| STMicroelectronics | Akamai Bot Manager | BLOCKED | BLOCKED | OK | OK | pup |
| Mouser Electronics | Akamai (AkamaiGHost) in front | untested | BLOCKED | OK | OK | pup |
| DigiKey | Cloudflare managed challenge ('Just a | BLOCKED | BLOCKED | OK | OK | pup |
| SnapEDA (SnapMagic) | Cloudflare managed challenge for non-h | untested | BLOCKED | OK | OK | pup |
| Texas Instruments | None observed | untested | OK | OK | OK | curl |
| Microchip Technology | Akamai | untested | BLOCKED | OK | OK | pup |
| Analog Devices (incl. Maxim, Linear) | Akamai Bot Manager | BLOCKED | BLOCKED | OK | OK | pup |
| Arrow Electronics | Akamai Bot Manager | untested | BLOCKED | OK | OK | pup |
| Nordic Semiconductor | Cloudflare in front of www: curl gets | untested | BLOCKED | OK | OK | pup |
| Ultra Librarian | Open to curl (nginx | untested | OK | OK | OK | curl |
| Component Search Engine (SamacSys) | Cloudflare | untested | BLOCKED | OK | OK | pup |
| datasheets.com | Cloudflare for curl only; the Anthropi | OK | BLOCKED | OK | OK | WebFetch |
| Octopart (and findchips) | Cloudflare in front | untested | OK | OK | untested | curl |
| JLCPCB parts and LCSC | Akamai | untested | OK | OK | untested | curl |
| NXP Semiconductors | Header-class at most; loads | OK | PARTIAL | OK | OK | WebFetch |
| Infineon Technologies | Header-class at most; loads | OK | OK | OK | OK | WebFetch |
| RS (RS Components / Allied) | None blocking observed 2026-09-14; loa | OK | PARTIAL | OK | OK | WebFetch |
| Newark / element14 (Farnell) | None blocking observed 2026-09-14; loa | OK | PARTIAL | OK | OK | WebFetch |
| Avnet | Akamai | untested | untested | OK | OK | pup |
| Other manufacturers (generic playbook) | Varies | untested | PARTIAL | untested | untested | nb |
Lane 0 readings for sites without a skill yet: infineon.com 200, renesas.com 200 (Cloudflare, passes), espressif.com 200, newark.com 200 (Akamai, passes), alldatasheet.com 403 (Cloudflare), samacsys.com 200 (Vercel). Add a skill when you touch one.
Skill map
| Skill | Site | One line |
|---|---|---|
| electronics-sites | (root) | The lane ladder, the symptom table, what pup leaks that a real browser does not, and the matrix below. |
| electronics-site-st | www.st.com | Manufacturer. |
| electronics-site-mouser | www.mouser.com | Distributor. |
| electronics-site-digikey | www.digikey.com | Distributor. |
| electronics-site-snapeda | www.snapeda.com | CAD library. |
| electronics-site-ti | www.ti.com | Manufacturer. |
| electronics-site-microchip | www.microchip.com | Manufacturer (incl. |
| electronics-site-analog | www.analog.com | Manufacturer. |
| electronics-site-arrow | www.arrow.com | Distributor. |
| electronics-site-nordic | www.nordicsemi.com | Manufacturer. |
| electronics-site-ultralibrarian | www.ultralibrarian.com | CAD library (also the engine behind many manufacturer CAD embeds). |
| electronics-site-componentsearchengine | componentsearchengine.com | CAD library (SamacSys / Supplyframe). |
| electronics-site-datasheets-com | www.datasheets.com | Aggregator (Supplyframe). |
| electronics-site-octopart | octopart.com | Aggregators (Nexar / Supplyframe). |
| electronics-site-jlcpcb | jlcpcb.com | Assembly-house parts library (JLCPCB SMT) and its distributor sibling LCSC. |
| electronics-site-nxp | www.nxp.com | Manufacturer. |
| electronics-site-infineon | www.infineon.com | Manufacturer (incl. |
| electronics-site-rs-online | www.rs-online.com | Distributor. |
| electronics-site-newark | www.newark.com | Distributor (Avnet-owned). |
| electronics-site-avnet | www.avnet.com | Distributor. |
| electronics-site-manufacturer | www.nxp.com | The generic approach for a manufacturer or distributor site that does not have its own skill yet, plus lane-0 readings for a few we have only curl-tested. |
| _template | (copy me) | The fixed section layout for a new site skill. |
Adding a site (this pack is built to grow)
Copy skills/_template/SKILL.md to skills/<site>/SKILL.md, run the ladder against the site, fill
every section with what you SAW (dated), list the new skill in install.sh, uninstall.sh and
package.json files[], bump the version, publish. Rules: one site per skill, ASCII punctuation only,
no fingerprint spoofing, credentials only ever typed into the site's own login form (or answered from
pup's vault). Captchas are driven by the AI (see above). This pack is THE global site-skill home;
chip-fetcher-sites inside adom/adom-chip-fetcher is deprecated and points here. Related: driving-sites
(nb login recipes, inside adom/nb-bridge), pup and adom-native-browser (the two browser lanes
themselves), adom-parts-search (the API lane).
---
name: electronics-sites
description: >-
THE map of how electronics-industry websites treat AI clients, one sub-skill per site (ST, TI, Mouser,
DigiKey, SnapEDA, Ultra Librarian, Arrow, Analog, Microchip, Nordic, Component Search Engine, Octopart,
JLCPCB/LCSC, datasheets.com, generic manufacturer). Which access lane works (WebFetch, curl, pup, nb,
official API), which bot defense each runs (Akamai, PerimeterX, Cloudflare), the exact failure
signatures, and what a Chrome-for-Testing window leaks that a real browser does not. Read BEFORE
fetching anything from a vendor or manufacturer domain, and the MOMENT a fetch to one times out,
403s, 473s, shows 'Just a moment', 'Access Denied', 'Access to this page has been denied', or
ERR_HTTP2_PROTOCOL_ERROR. Trigger words: st.com, ti.com, mouser, digikey, snapeda, ultralibrarian,
arrow, analog.com, microchip, nordicsemi, componentsearchengine, octopart, jlcpcb, lcsc, datasheets.com,
vendor site blocked, manufacturer site timeout, datasheet download blocked, bot wall, cloudflare
just a moment, akamai access denied, perimeterx, captcha on vendor site, which browser for this site,
electronics website, electronics industry site skills.
---
# Electronics Industry Site Skills
Nobody built skills for the electronics industry's websites, so an AI meets each one cold: a fetch to
st.com times out, a pup window on DigiKey spins forever, Mouser answers HTTP 200 with a denial page, and
the AI reports "the site is down" when the site is fine and only that CLIENT was refused. These
vendors block anything that does not look like a person because they have not noticed the AI era
yet. This pack records, per site, exactly how it behaves toward each lane we have, dated, with the
evidence, so the next AI routes around the wall in one move instead of rediscovering it.
Every sub-skill has the same sections (domains, bot defense, lane matrix, failure signatures, recipes,
API lane, gotchas, evidence). Verified live on 2026-09-14 from an Adom cloud container against a
Windows desktop running Adom Bridge 2.1.104, pup 2.0.549 (Chrome for Testing 152, extension lane) and the Native
Browser Extension 0.16.14 (Chrome 152).
## Step 0, before any site: the Adom wiki
Every rung below costs a browser, a login or a captcha. The cheapest rung is the one that
needs none of them: **search the wiki first.** `adom-wiki discover search --query <MPN>` and
`adom-wiki discover find <MPN>`; a component page (usually `adom/<mpn-lowercase>`) ships the
datasheet, the reviewed symbol/footprint/`.lbr`, the manufacturer STEP in Z-up with FoV-on/off and
side-etched variants, the chip-outline cache and provenance. `adom-wiki repo clone adom/<slug>`
and reuse. Only when the page is missing or lacks the artifact you need do you go to the vendor
site, and when you come back with something new, publish it to that page (wiki-component skill)
so the next AI never repeats the trip. Verify `component.mpn` or the slug on a hit: search is loose.
## 2026-09-14 update: two causes that are NOT the page, found chasing analog.com
Two independent discoveries this date, each measured, that reframe the hardest Akamai sites:
**1. WITHDRAWN: "the Chrome-for-Testing VERSION is a bot signal".** An earlier revision of this pack
claimed that pinning CfT 148 against a Chrome 152 desktop is what made analog.com answer HTTP 403, and
that bumping to CfT 152 fixed it. **That comparison was not controlled and the claim is withdrawn.**
Every denied trial was a raw hand-rolled Chrome launch carrying a copied flag list; every passing trial
was pup itself. Those differ in infobar suppression, the feature-disable set and the identity shim, not
only in the build number. Re-measured 2026-09-14 with screenshots: analog.com renders fully in pup on
CfT 152 on the shared adom-you profile. The arm intended as a fresh jar was not one, because
isolated:true keeps that same profile (pup-bridge#112), so profile state is UNTESTED, not excluded. What IS established: these sites load when driven through pup's
own launch path, and WHICH element of that path is decisive has not been isolated. Keep the CfT pin
near the installed Chrome as cheap hygiene, not as an explanation. `typeof bmak === "undefined"` on a
denied page is a SYMPTOM, because the Access Denied page carries no sensor script at all. Keep CfT within ~1 milestone of the installed Chrome. Several sites
that were pup-BLOCKED on 148 (st.com among them) load on 152. Diagnostic on a denial: `typeof bmak`
`undefined` = rejected upstream (version or IP); `object` = the sensor ran and failed you (IP/behaviour).
**2. Egress IP reputation: SUSPECTED, not established.** The four-box comparison below was run with
the BURST method, which we now know trips velocity rules on its own, so these readings are method-suspect
and have not been reproduced paced. Treat as a hypothesis to re-test, not as fact:
AdomLapper (corporate VPN egress) and winvm (Azure) LOAD analog.com; arav-rog and ConfRoomROG (bare
office LAN) are DENIED. Identical browser, opposite result: the bare office NAT IP is Akamai-flagged.
pup cannot fix this from inside the browser; the lever is a cleaner egress (VPN/residential/cloud) or
nb on the user's own connection.
**Cookie hygiene:** a rejected Akamai visit writes `_abck` to a `~-1~` reject state that persists.
`pup_clear_cookies {domain}` / `pup_clear_site_data {origins}` before re-testing, or the stale verdict
masks a fix.
## Fleet matrix (extension lane, CfT 152, 2026-09-14)
16 of 20 load on every box; the spread is the Akamai-hardened four (analog, avnet, arrow, digikey):
| Site | AdomLapper (VPN) | arav-rog (office) | ConfRoomROG (office) | winvm (Azure) |
|---|:--:|:--:|:--:|:--:|
| ST, Mouser*, TI, Microchip, Nordic, SnapEDA, UltraLib, CSE, Octopart, LCSC, JLCPCB, Newark, RS, Infineon, NXP | load | load | load | load |
| DigiKey | load | load | block | block |
| Arrow | load | block | block | block |
| Analog | load | block | block | load |
| Datasheets | load | load | load | block |
| Avnet | loads on a paced single visit; the matrix's 20-tab BURST tripped Akamai's velocity WAF (self-inflicted). Clear cookies + navigate once. | | | |
*Mouser loads its home page but scores behaviour on crawls (DataDome) - use the API for data.
## How to load ANY of these in pup (the procedure that got 20 of 20)
Measured 2026-09-14 on AdomLapper: all twenty sites in this pack loaded in pup, including the four a
previous burst run had called blocked. Three conditions, all of them required:
1. **Match Chrome for Testing to the user's INSTALLED Chrome.** Check `pup_readiness.chromeBuildId`
against their Chrome. A stale CfT breaks Akamai's sensor outright (it never initialises) and no
header work rescues it.
2. **Go at human pace: ONE tab at a time, with a real settle (about 7 s).** A burst of tabs trips
velocity rules on Akamai sites (avnet, arrow, datasheets all "blocked" purely from bursting). This
is the single most common self-inflicted block.
3. **Clear that domain's cookies before the visit.** A previous denial writes a reject verdict that
persists and will keep denying you long after the real cause is fixed.
Then use the default extension lane (no debug port) with the consumer identity on, which is what
`pup_open_window` already does. Only when all three conditions hold and a site STILL refuses is it
worth reaching for nb or the API lane.
## The rule: a fetch failure on a vendor domain is a ROUTING signal
1. **One plain attempt only.** WebFetch or curl once. It is the cheapest lane and it works on TI,
community.st.com, datasheets.com (WebFetch), Octopart, JLCPCB, Infineon, Espressif.
2. **pup second** (a real rendered Chrome, background, the durable adom-you profile). Passes
Microchip, Nordic, CSE, Ultra Librarian, datasheets.com; renders vendor CDN PDFs.
3. **nb third and last** (the user's real signed-in Chrome via nbrowser_*). Passes EVERYTHING we have
tested, including the four that refuse pup (st.com after the first page, Mouser, DigiKey, SnapEDA,
Analog, Arrow). Give a challenge page **9 seconds** to clear before you read the DOM: a 6 s wait
reads as empty and looks like a block that is not there.
4. **Numbers you will act on come from an API, never a scrape:** `adom-parts-search show "<MPN>"`
(Mouser + DigiKey + JLCPCB backends, quota-limited: one search per question, never a loop).
Never retry the failing lane, never report "the site is timing out", never spoof a fingerprint.
Switch lanes, then write down what you saw in that site's skill.
**No account on a site? Register one for the user (John, 2026-09-19).** These are free CAD/vendor
accounts, not bank logins: when a download needs a login the vault does not have, first check the
user's own browser (`pup_import_browser_logins {}`) and the other desktops (`pup_vault_sync {peer}`);
if there is truly none, register with the Adom user's profile (work email, name, company), read the
verification mail through the Gmail connector, set a generated password in the same pup session and
`credential_set` it into the vault so the human never types it. The ST skill has the worked example.
**Captchas: the AI drives them itself (John, 2026-09-19).** A reCAPTCHA / Turnstile checkbox or image
grid on a download or login gate is YOUR job, not the user's: never toast, flash or wait for the human,
and never switch pup to the CDP lane for it. Trusted click on the checkbox with pup's fake cursor,
screenshot the grid, pick the tiles by vision, trusted-click them and Verify until the token fills,
then submit. On the extension lane the trusted-input verbs are tracked in adom/pup-bridge#120
(until they ship `pup_input_dispatch` answers `lane_needs_cdp`; say so plainly and take the next
lane or route). `nbrowser_flash`-and-wait is retired.
## Symptom -> cause -> lane
| You see | It is | Do |
|---|---|---|
| `ERR_HTTP2_PROTOCOL_ERROR` / `chrome-error://` on the SECOND page of a domain in pup; `curl: (92) HTTP/2 stream ... INTERNAL_ERROR` in ~100 ms | Akamai Bot Manager reset the stream after its sensor verdict (st.com, analog.com, arrow.com) | nb. Do not reload the pup tab; it stays dead for that domain |
| `Access Denied` + `Reference #18.xxxx` | Akamai deny page (analog, arrow to pup; microchip to curl) | nb (pup passes microchip; test, do not assume) |
| `Access to this page has been denied.` with **HTTP 200**, or `press and hold` | PerimeterX / HUMAN (mouser.com) | nb for the page, API for the data |
| title `Just a moment...`, 263-char body, HTTP 403, `cf-ray` header; on digikey/snapeda a `Verify you are human` CHECKBOX (Turnstile) | Cloudflare managed challenge (digikey, snapeda, CSE, nordic, datasheets.com, alldatasheet) | pup passes CSE / nordic / datasheets.com on its own; digikey + snapeda show the checkbox and never auto-clear in pup: use nb (clears in ~9 s, no click), or drive the checkbox yourself on the ext lane once adom/pup-bridge#120 ships |
| HTTP 473 | Akamai to a fetcher (newsroom.st.com) | pup or nb |
| WebFetch 60 s timeout on a vendor URL | the fetcher is being tarpitted, not an outage | pup, then nb |
| `captcha` in the HTML but the page renders | login / download gate (ultralibrarian, signed-in UL Pro too since 2026-09-19) | the AI drives it: trusted click + vision on the image grid (adom/pup-bridge#120); never hand it to the human |
| Chrome native "Sign in" dialog (Username / Password) on a download URL | HTTP Basic-Auth (the componentsearchengine.com family: st./ms./nxp./mouser.) | vault entry `componentsearchengine.com` + pup answering the challenge (adom/pup-bridge#119, not yet on the ext lane); nb answers it from the user's saved login |
| `renderCheck.ok:true` but the body says `This site can't be reached` | pup's render check does not flag chrome-error pages (adom/pup-bridge#109) | read the body yourself; switch lanes |
## What pup leaks that a real browser does not (measured on st.com, 2026-09-14)
| Probe | pup (Chrome for Testing 148) | nb (installed Chrome 152) |
|---|---|---|
| `navigator.webdriver` | **true** | false |
| Widevine (`requestMediaKeySystemAccess('com.widevine.alpha')`) | **NotSupportedError** (CfT ships without the CDM) | available |
| `navigator.userAgentData.brands` | Not/A)Brand 99, Chromium 148 (no "Google Chrome") | Chromium 152, Not?A_Brand 24, Google Chrome 152 |
| User agent major | 148 (cached build, four majors behind) | 152 |
| `Notification.permission` on first visit | granted (pup pre-grants 32 permissions) | default |
| Akamai `_abck` on first load | ~-1~ (unvalidated) | ~-1~ (unvalidated) |
| plugins / cores / memory / h2 | 5 / 16 / 32 GB / h2 | identical |
Both clients get the same unvalidated Akamai cookie; the verdict comes from the sensor telemetry, and
webdriver + no Widevine + no Google Chrome brand is enough. A cold isolated pup profile and 15 s
between requests changed nothing; the same navigation in nb returned 200. That is why the ladder ends
at nb and why pup is still worth trying first on the sites that do not look this closely.
## The matrix (lane 0 = curl; verified 2026-09-14)
| Site | Bot defense | WebFetch | curl | pup | nb | Use first |
|---|---|---|---|---|---|---|
| [STMicroelectronics](skills/st/SKILL.md) | Akamai Bot Manager | BLOCKED | BLOCKED | OK | OK | pup |
| [Mouser Electronics](skills/mouser/SKILL.md) | Akamai (AkamaiGHost) in front | untested | BLOCKED | OK | OK | pup |
| [DigiKey](skills/digikey/SKILL.md) | Cloudflare managed challenge ('Just a | BLOCKED | BLOCKED | OK | OK | pup |
| [SnapEDA (SnapMagic)](skills/snapeda/SKILL.md) | Cloudflare managed challenge for non-h | untested | BLOCKED | OK | OK | pup |
| [Texas Instruments](skills/ti/SKILL.md) | None observed | untested | OK | OK | OK | curl |
| [Microchip Technology](skills/microchip/SKILL.md) | Akamai | untested | BLOCKED | OK | OK | pup |
| [Analog Devices (incl. Maxim, Linear)](skills/analog/SKILL.md) | Akamai Bot Manager | BLOCKED | BLOCKED | OK | OK | pup |
| [Arrow Electronics](skills/arrow/SKILL.md) | Akamai Bot Manager | untested | BLOCKED | OK | OK | pup |
| [Nordic Semiconductor](skills/nordic/SKILL.md) | Cloudflare in front of www: curl gets | untested | BLOCKED | OK | OK | pup |
| [Ultra Librarian](skills/ultralibrarian/SKILL.md) | Open to curl (nginx | untested | OK | OK | OK | curl |
| [Component Search Engine (SamacSys)](skills/componentsearchengine/SKILL.md) | Cloudflare | untested | BLOCKED | OK | OK | pup |
| [datasheets.com](skills/datasheets-com/SKILL.md) | Cloudflare for curl only; the Anthropi | OK | BLOCKED | OK | OK | WebFetch |
| [Octopart (and findchips)](skills/octopart/SKILL.md) | Cloudflare in front | untested | OK | OK | untested | curl |
| [JLCPCB parts and LCSC](skills/jlcpcb/SKILL.md) | Akamai | untested | OK | OK | untested | curl |
| [NXP Semiconductors](skills/nxp/SKILL.md) | Header-class at most; loads | OK | PARTIAL | OK | OK | WebFetch |
| [Infineon Technologies](skills/infineon/SKILL.md) | Header-class at most; loads | OK | OK | OK | OK | WebFetch |
| [RS (RS Components / Allied)](skills/rs-online/SKILL.md) | None blocking observed 2026-09-14; loa | OK | PARTIAL | OK | OK | WebFetch |
| [Newark / element14 (Farnell)](skills/newark/SKILL.md) | None blocking observed 2026-09-14; loa | OK | PARTIAL | OK | OK | WebFetch |
| [Avnet](skills/avnet/SKILL.md) | Akamai | untested | untested | OK | OK | pup |
| [Other manufacturers (generic playbook)](skills/manufacturer/SKILL.md) | Varies | untested | PARTIAL | untested | untested | nb |
Lane 0 readings for sites without a skill yet: infineon.com 200, renesas.com 200 (Cloudflare, passes),
espressif.com 200, newark.com 200 (Akamai, passes), alldatasheet.com 403 (Cloudflare), samacsys.com
200 (Vercel). Add a skill when you touch one.
## Skill map
| Skill | Site | One line |
|---|---|---|
| **electronics-sites** | (root) | The lane ladder, the symptom table, what pup leaks that a real browser does not, and the matrix below. |
| **electronics-site-st** | www.st.com | Manufacturer. |
| **electronics-site-mouser** | www.mouser.com | Distributor. |
| **electronics-site-digikey** | www.digikey.com | Distributor. |
| **electronics-site-snapeda** | www.snapeda.com | CAD library. |
| **electronics-site-ti** | www.ti.com | Manufacturer. |
| **electronics-site-microchip** | www.microchip.com | Manufacturer (incl. |
| **electronics-site-analog** | www.analog.com | Manufacturer. |
| **electronics-site-arrow** | www.arrow.com | Distributor. |
| **electronics-site-nordic** | www.nordicsemi.com | Manufacturer. |
| **electronics-site-ultralibrarian** | www.ultralibrarian.com | CAD library (also the engine behind many manufacturer CAD embeds). |
| **electronics-site-componentsearchengine** | componentsearchengine.com | CAD library (SamacSys / Supplyframe). |
| **electronics-site-datasheets-com** | www.datasheets.com | Aggregator (Supplyframe). |
| **electronics-site-octopart** | octopart.com | Aggregators (Nexar / Supplyframe). |
| **electronics-site-jlcpcb** | jlcpcb.com | Assembly-house parts library (JLCPCB SMT) and its distributor sibling LCSC. |
| **electronics-site-nxp** | www.nxp.com | Manufacturer. |
| **electronics-site-infineon** | www.infineon.com | Manufacturer (incl. |
| **electronics-site-rs-online** | www.rs-online.com | Distributor. |
| **electronics-site-newark** | www.newark.com | Distributor (Avnet-owned). |
| **electronics-site-avnet** | www.avnet.com | Distributor. |
| **electronics-site-manufacturer** | www.nxp.com | The generic approach for a manufacturer or distributor site that does not have its own skill yet, plus lane-0 readings for a few we have only curl-tested. |
| **_template** | (copy me) | The fixed section layout for a new site skill. |
## Adding a site (this pack is built to grow)
Copy `skills/_template/SKILL.md` to `skills/<site>/SKILL.md`, run the ladder against the site, fill
every section with what you SAW (dated), list the new skill in `install.sh`, `uninstall.sh` and
`package.json` `files[]`, bump the version, publish. Rules: one site per skill, ASCII punctuation only,
no fingerprint spoofing, credentials only ever typed into the site's own login form (or answered from
pup's vault). Captchas are driven by the AI (see above). This pack is THE global site-skill home;
`chip-fetcher-sites` inside adom/adom-chip-fetcher is deprecated and points here. Related: `driving-sites`
(nb login recipes, inside adom/nb-bridge), `pup` and `adom-native-browser` (the two browser lanes
themselves), `adom-parts-search` (the API lane).