cherry-pr-test — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cherry-pr-test (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
Aggregate score unchanged between these scans.
The primary manifest — the file an agent reads to learn what this artifact does.
Automated PR testing workflow for Cherry Studio. Checks out a PR, launches the Electron app with Chrome DevTools Protocol, connects agent-browser, and runs interactive UI + code review tests.
gh CLI installed and authenticatedagent-browser installed (for CDP-based UI testing)pnpm installed with project dependencies (pnpm install)$ARGUMENTS may contain:
13955)https://github.com/CherryHQ/cherry-studio/pull/13955) gh pr list --repo CherryHQ/cherry-studio --state open --limit 10 \
--json number,title,author,createdAt,headRefName,changedFiles \
--template '{{range .}}#{{.number}} | {{.title}} | by {{.author.login}} | files: {{.changedFiles}}
{{end}}' gh pr view <NUMBER> --json title,body,headRefName,files gh pr checkout <NUMBER>Static analysis and app launch are independent — run them in parallel to save time.
#### Static Analysis (can run while app is starting)
pnpm typecheck 2>&1 | grep -E "error TS|exited with code"@deprecated / V2 DATA&UI REFACTORING headers. These files are blocked for feature changes until v2.0.0.
console.log usage (should use loggerService)Record all findings for the final report.
#### Launch App
pkill -f "cherry-studio.*Electron" 2>/dev/null
pkill -f "electron-vite" 2>/dev/null
lsof -ti :9222 | xargs kill 2>/dev/null
lsof -ti :5173 | xargs kill 2>/dev/null
sleep 3
# Escalate to SIGKILL only if processes remain
lsof -ti :9222 | xargs kill -9 2>/dev/null
lsof -ti :5173 | xargs kill -9 2>/dev/null--remote-debugging-port=9222): nohup pnpm debug > /tmp/cherry-debug.log 2>&1 & for i in $(seq 1 30); do
lsof -i :9222 2>/dev/null | grep LISTEN && break
sleep 2
done agent-browser connect 9222If connect fails, fall back to websocket URL from logs:
WS_URL=$(grep "DevTools listening" /tmp/cherry-debug.log | sed 's/.*ws:/ws:/')
agent-browser --cdp "$WS_URL" navigate http://localhost:5173 agent-browser tabYou should see the main Cherry Studio page at http://localhost:5173/. If multiple tabs are listed, use agent-browser tab <N> to select the main one.
may show a migration wizard (/migrationV2.html) before the main UI. Click through: 介绍(下一步) → 备份(我已备份,开始迁移) → 迁移(确定) → 完成(重启应用). After "重启应用", kill and relaunch the app (the restart button doesn't work in dev mode).
mkdir -p /tmp/pr-<NUMBER>Use this directory for all screenshots: /tmp/pr-<NUMBER>/<descriptive-name>.png
Based on the PR's changed files, navigate to the relevant pages and test. Use your judgement to decide what to test — the PR description and changed files should guide your testing strategy.
#### General Approach
agent-browser snapshot -i to discover interactive elementsagent-browser eval)#### Key Testing Points
After testing:
pkill -f "cherry-studio.*Electron" 2>/dev/null
pkill -f "electron-vite" 2>/dev/null
lsof -ti :9222 | xargs kill 2>/dev/null
lsof -ti :5173 | xargs kill 2>/dev/null
sleep 3
lsof -ti :9222 | xargs kill -9 2>/dev/null
lsof -ti :5173 | xargs kill -9 2>/dev/null default_branch=$(git symbolic-ref refs/remotes/origin/HEAD 2>/dev/null | sed 's@^refs/remotes/origin/@@')
git checkout "${default_branch:-main}"Generate a structured report with screenshots. Save the report as /tmp/pr-<NUMBER>/report.md alongside the screenshots.
# PR #<NUMBER> 测试报告
**PR 标题**: <title>
**作者**: @<author>
**分支**: <branch>
**修改文件数**: <count>
## 静态分析
| 检查项 | 结果 | 说明 |
|--------|------|------|
| TypeScript 类型检查 | ✅/❌ | ... |
| 受阻文件检查 | ✅/⚠️ | ... |
| console.log 使用 | ✅/❌ | ... |
## UI 测试
### <Test Case Name>
<description of what was tested and the result>

## 发现的问题
(if any)
## 结论
- 问题总数:N
- 建议:APPROVE / REQUEST_CHANGES / COMMENTIf the user requests, copy the report directory to a more accessible location (e.g., Desktop) for sharing.
The pnpm debug script passes --remote-debugging-port=9222 to Electron. If not working:
tail -50 /tmp/cherry-debug.loglsof -ti :9222 | xargs kill -9ps aux | grep electron-viteUse direct websocket URL:
WS_URL=$(grep "DevTools listening" /tmp/cherry-debug.log | grep 9222 | sed 's/.*\(ws:\/\/[^ ]*\)/\1/')
agent-browser --cdp "$WS_URL" tabElectron apps have multiple CDP targets (main window + webviews for mini-apps). If agent-browser connects to a webview instead of the main page:
# List all targets
agent-browser tab
# Switch to the main page (usually tab 0, URL contains localhost:5173)
agent-browser tab 0After opening/closing mini-apps, always verify you're on the right target with agent-browser tab.
On the v2 branch, the app may show a data migration wizard on first launch. This is not a bug — it's expected when dev data hasn't been migrated yet. Click through the wizard steps, then restart the app manually (kill + relaunch). The wizard only appears once; subsequent launches go straight to the main UI.
Wait longer (up to 30s on first launch). The app needs to:
After connecting, if agent-browser tab shows only about:blank:
agent-browser navigate http://localhost:5173
sleep 10
agent-browser tab~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.