webapp-testing
Test Local Web Apps with Playwright
Testing local interfaces requires reliable server startup, browser inspection, and artifact capture. This skill provides Playwright patterns and a server lifecycle helper.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "webapp-testing" from https://skillstore.io/skills/davila7-webapp-testing.md and its manifest at https://skillstore.io/api/skills/davila7-webapp-testing/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "webapp-testing". Inspect the dashboard and report available actions.
Expected outcome:
- Found 6 visible buttons, 4 links, and 2 form fields.
- Stable labels include Create report, Refresh data, and Open settings.
- Saved a full-page screenshot to the approved output directory.
Using "webapp-testing". Test sign-in validation with an empty password.
Expected outcome:
- The form stayed on the sign-in page.
- A password-required message appeared below the password field.
- No new browser console errors were observed.
Using "webapp-testing". Capture browser errors after opening the local application.
Expected outcome:
- The page loaded successfully.
- Captured one failed resource request and one application warning.
- Saved the console transcript for review.
Security Audit
High RiskTwo subprocess findings are confirmed because the helper executes supplied server strings and command arguments. The other 28 detections are benign local examples, artifact writes, or Markdown syntax. SKILL.md also discourages source review before execution, creating a high-severity prompt-injection and supply-chain risk.
Confirmed security concerns (1)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Network access (3)
๐ Filesystem access (4)
โ๏ธ External commands (23)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/davila7-webapp-testing/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/davila7-webapp-testing?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/davila7-webapp-testing?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/davila7-webapp-testing/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/davila7-webapp-testing.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
davila7. (2026). webapp-testing security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/davila7-webapp-testing/audits/9BibTeX citation
@techreport{davila7-davila7-webapp-testing-2026,
author = {davila7},
title = {webapp-testing security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/davila7-webapp-testing/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "webapp-testing security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "davila7"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/davila7-webapp-testing/audits/9"
identifiers:
- type: other
value: "skillstore:davila7-webapp-testing:audit:9"
description: "Skillstore immutable audit report identifier"
Compare variants
11 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
autumnsgrove-webapp-testing
2026-09-09
7spade-webapp-testing
2026-09-09
webapp-testing
2026-09-09
zhanlincui-webapp-testing
2026-09-09
artemisai-webapp-testing
2026-09-09
sickn33-webapp-testing
2026-09-09
azeem-2-webapp-testing
2026-09-09
cam10001110101-webapp-testing
2026-09-09
dyai2025-webapp-testing
2026-09-09
davila7-webapp-testing
2026-09-09
composiohq-webapp-testing
2026-09-09
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Debug a Local Frontend
Inspect the rendered interface, capture console messages, and verify interactions while a local development server runs.
Run Repeatable UI Checks
Automate a focused user workflow and collect screenshots or browser logs for defect investigation.
Inspect a Static Prototype
Open a local HTML file, identify useful selectors, exercise controls, and record visual results.
Try These Prompts
Open [local URL] with Playwright, wait for the page to settle, capture a full-page screenshot, and summarize visible errors.
Inspect [local URL] and list visible buttons, links, inputs, and stable selectors. Capture browser console warnings and errors.
Test this workflow on [local URL]: [steps]. Report each result, relevant console errors, and the saved screenshot locations.
Review these trusted startup commands: [commands]. Start each local service, wait for [ports], run [workflow], collect evidence, and stop every process.
Best Practices
- Review helper source and every command string before starting local processes.
- Wait for an appropriate page state before inspecting elements or performing actions.
- Close browsers and child processes, then store artifacts only in approved locations.
Avoid
- Do not pass untrusted text to the server helper because server strings reach a shell.
- Do not run tests against production systems or real user data without explicit authorization.
- Do not reuse fixed example selectors, paths, or waits without validating the current interface.
Frequently Asked Questions
What applications can this skill test?
What software is required?
Can it start multiple local services?
What evidence can it collect?
Is it intended for production testing?
Why do commands require review?
Developer Details
Author
davila7License
Complete terms in LICENSE.txt
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
c43861a65bb95efcae259cd161c9d6f4dc7eec6f
Maintenance freshness
7/25/2026
Usage
5 downloads ยท 245 views
File structure
๐ examples/
๐ console_logging.py
๐ element_discovery.py
๐ static_html_automation.py
๐ LICENSE.txt
๐ scripts/
๐ with_server.py
๐ SKILL.md