webapp-testing — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited webapp-testing (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
要测试本地 Web 应用,请编写原生的 Python Playwright 脚本。
可用的辅助脚本:
scripts/with_server.py - 管理服务器生命周期(支持多个服务器)务必先使用 `--help` 运行脚本来查看用法。在尝试运行脚本并发现确实需要定制化解决方案之前,不要阅读源代码。这些脚本可能非常大,会污染您的上下文窗口。它们的存在是为了作为黑盒脚本直接调用,而不是被加载到您的上下文窗口中。
用户任务 → 是静态 HTML 吗?
├─ 是 → 直接读取 HTML 文件以识别选择器
│ ├─ 成功 → 使用选择器编写 Playwright 脚本
│ └─ 失败/不完整 → 按动态应用处理(见下文)
│
└─ 否(动态 webapp)→ 服务器是否已在运行?
├─ 否 → 运行:python scripts/with_server.py --help
│ 然后使用该辅助脚本 + 编写简化的 Playwright 脚本
│
└─ 是 → 侦察-然后-行动:
1. 导航并等待 networkidle
2. 截屏或检查 DOM
3. 从渲染状态中识别选择器
4. 使用发现的选择器执行操作要启动服务器,请先运行 --help,然后使用该辅助脚本:
单个服务器:
python scripts/with_server.py --server "npm run dev" --port 5173 -- python your_automation.py多个服务器(例如,后端 + 前端):
python scripts/with_server.py \
--server "cd backend && python server.py" --port 3000 \
--server "cd frontend && npm run dev" --port 5173 \
-- python your_automation.py要创建自动化脚本,只需包含 Playwright 逻辑(服务器会自动管理):
from playwright.sync_api import sync_playwright
with sync_playwright() as p:
browser = p.chromium.launch(headless=True) # 始终以无头模式启动 chromium
page = browser.new_page()
page.goto('http://localhost:5173') # 服务器已运行并就绪
page.wait_for_load_state('networkidle') # 关键:等待 JS 执行
# ... 你的自动化逻辑
browser.close() page.screenshot(path='/tmp/inspect.png', full_page=True)
content = page.content()
page.locator('button').all()❌ 不要 在动态应用上等待 networkidle 之前检查 DOM ✅ 务必 在检查前等待 page.wait_for_load_state('networkidle')
scripts/ 目录中是否有可用的脚本能提供帮助。这些脚本能可靠地处理常见的复杂工作流,而不会弄乱上下文窗口。使用 --help 查看用法,然后直接调用。sync_playwright()text=、role=、CSS 选择器或 IDpage.wait_for_selector() 或 page.wait_for_timeout()element_discovery.py - 在页面上发现按钮、链接和输入static_html_automation.py - 对本地 HTML 使用 file:// URLconsole_logging.py - 在自动化过程中捕获控制台日志~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.