Agent skill

Byot E2E Validation

by awebai in awebai/aweb

A skill your agent uses when writing e2e tests for BYOT/AWID team-certificate auth, testing aw id request --team-auth, building a docker awid-service harness, or validating replay, revocation…

MITAuto-check passedTesting & QA

Install Byot E2E Validation

skills CLI
$ npx skills add awebai/aweb --skill byot-e2e-validation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install awebai/aweb byot-e2e-validation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/awebai/aweb.git skills-src && mkdir -p .claude/skills && cp -r skills-src/naapp/folio/skills/byot-e2e-validation .claude/skills/byot-e2e-validation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
byot-e2e-validation
GitHub stars
115
Token cost
~1k tokens
SKILL.md length
549 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when writing e2e tests for BYOT/AWID team-certificate auth, testing aw id request --team-auth, building a docker awid-service harness, or validating replay, revocation…

  • Works in 5 steps: Docker Compose starts Postgres, Redis,… → AWID_SKIP_DNS_VERIFY=1 lets tests… → Each test workspace gets an isolated… → …
  • Writing e2e tests for BYOT/AWID team-certificate auth
  • SKILL.md covers Iron rule: no mocked auth in e2e, Harness shape, Required negative suite and Operational hardening, plus 1 more section
  • Calls docker and make

What it does

Byot E2E Validation is an agent skill from awebai/aweb. Use when writing e2e tests for BYOT/AWID team-certificate auth, testing aw id request --team-auth, building a docker awid-service harness, or validating replay, revocation, fail-closed, and team-scoping behavior.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering End-to-end testing and Containers. It works with Docker. The repository describes itself as: Communication for AI agents: stable identity, durable mail and chat, and wake-up events across sessions, runtimes, machines, and organizations. MIT, self-hostable. The licence is MIT.

When your agent uses it

  • Writing e2e tests for BYOT/AWID team-certificate auth
  • Testing aw id request --team-auth
  • Building a docker awid-service harness
  • Validating replay

Example prompts

  • “/byot-e2e-validation”

Requirements

  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Docker Compose starts Postgres, Redis, and awid-service.
  2. AWID_SKIP_DNS_VERIFY=1 lets tests register disposable .test
  3. Each test workspace gets an isolated HOME and clean working directory.
  4. Provision through the CLI, not fixtures: aw id create →
  5. Send the application request with aw id request --team-auth; never

What it can do on your machine

Read from SKILL.md and the folder at commit a6ca92a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Byot E2E Validation loads about 1k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 549 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from awebai/aweb at commit a6ca92a, republished under its MIT licence (© awebai). 549 words, ~1,025 tokens.

Download SKILL.mdSave it as .claude/skills/byot-e2e-validation/SKILL.md (or your agent's skills folder).
name
byot-e2e-validation
description
Use when writing e2e tests for BYOT/AWID team-certificate auth, testing aw id request --team-auth, building a docker awid-service harness, or validating replay, revocation, fail-closed, and team-scoping behavior.

BYOT e2e validation

Use this when testing an agent-first app that relies on AWID team certificates. The goal is to prove the relying-party chain works with real keys, real certificates, real signatures, and real AWID facts.

Iron rule: no mocked auth in e2e

No mocked certificates. No mocked signatures. No mocked AWID responses. If you are tempted to mock one of those in e2e, you are about to test nothing.

Generate real keys and certificates with aw id against a local awid-service. Send requests with aw id request --team-auth. Unit tests can cover small parsing and interop cases, but the e2e layer must exercise the same cryptographic and registry path a customer uses.

Harness shape

The known-good shape in this repo is docker-compose.e2e.yml, tests/test_e2e_smoke.py, and the Makefile e2e target:

  1. Docker Compose starts Postgres, Redis, and awid-service.
  2. AWID_SKIP_DNS_VERIFY=1 lets tests register disposable .test namespaces locally.
  3. Each test workspace gets an isolated HOME and clean working directory.
  4. Provision through the CLI, not fixtures: aw id create → aw id team create → aw id team add-member → aw id team fetch-cert → aw id team switch.
  5. Send the application request with aw id request --team-auth; never reimplement signing in test code.

Open finding: current aw id request --team-auth needs a workspace binding, not only .aw/teams.yaml plus .aw/team-certs/. The harness writes a minimal .aw/workspace.yaml after fetching the cert so the released CLI sees an active workspace. Document this as a workaround, not as product truth. The file contains only the test service URL, one membership (team_id, alias, workspace_id, cert_path, joined_at), and workspace metadata (human_name, agent_type, workspace_path, updated_at).

Show full SKILL.md (284 more words)Show less

Required negative suite

Auth-critical negatives must be hard assertions. Do not xfail them: an xfail on auth failure can hide a regression back to 422, 500, or a bypass.

Cover at least:

  • Missing envelope: assert 401.
  • Replay over the wire: capture one valid request through a recording proxy, replay its headers/body against a different path, a different method, and a different audience/host; all must 401.
  • Revocation: revoke the member certificate through AWID, wait for the app's auth cache to refresh, and assert the next request fails closed.
  • Fail-closed registry outage: stop awid-service; assert requests still succeed while an unexpired cache entry exists, then fail 503/401 after cache expiry. Test both halves.
  • Cross-team scoping: a second real team cannot read or write the first team's documents; naming another team_id in the body must not bypass the certificate's team_id.
  • Raw body contracts: reject invalid UTF-8 when an endpoint accepts raw text.

Also assert attribution fields where writes create history: did_key, alias, and certificate id should come from the verified signer.

Operational hardening

Make the e2e command boring and repeatable:

  • Install the teardown trap before compose up.
  • Clear stale compose state before starting.
  • Prefer fixture-level health waits over docker compose --wait; Compose wait behavior can be flaky with recreated or stale containers.
  • Keep one documented command (make e2e) that starts services, runs pytest, and tears everything down.
  • Repeated runs must pass from a dirty Docker environment.
  • Expected auth failures should be asserted in test output, not left as unexplained log noise.

Reference implementation

Use this repo's current harness as the working example:

  • docker-compose.e2e.yml
  • tests/test_e2e_smoke.py
  • Makefile e2e, e2e-up, and e2e-down targets

The code is the source of truth. Keep prose thin and update it when the harness changes.

© awebai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in naapp/folio/skills/byot-e2e-validation of awebai/aweb.

Open the folder on GitHubat commit a6ca92a

Compare with similar skills

Byot E2E Validation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Byot E2E Validation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Byot E2E Validation this skillawebai/aweb115—~1kAutomated safety check: PassMIT
Go Redis Client Test Runnerredis/go-redis22k—~786Automated safety check: PassBSD-2-Clause
Dqd Labctrsploit/ctrsploit154—~1.6kAutomated safety check: PassNone
Crabbox SetupAI-Builder-Club/skills1.3k—~1.9kAutomated safety check: NotesNone
E2Eopenathleteorg/openathlete101—~675Automated safety check: PassAGPL-3.0
Openclaw Docker E2E Authoringopenclaw/openclaw392k—~593Automated safety check: PassMIT

Similar skills

  • Official

    Explains how to run go-redis tests: the Docker Compose stack, make targets, focusing a single Ginkgo spec, the e2e suite and the version environment variables.

    22k GitHub stars~786 tokensUpdated today
    Testing & QAAuto-check passed
  • Dqd Lab

    ctrsploit/ctrsploit

    Manage ctrsploit dqd lab environments from github.com/ctrsploit/dqd.

    154 GitHub stars~1.6k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Crabbox Setup

    AI-Builder-Club/skills

    Scaffold an isolated CLOUD dev box per agent (via crabbox + Daytona) for any codebase — the parallel-safe counterpart to dev-local-setup.

    1.3k GitHub stars~1.9k tokensUpdated 23 days ago
    Testing & QAAuto-check: notes
  • E2E

    openathleteorg/openathlete

    Run, debug or extend the OpenAthlete Playwright end-to-end tests, which exercise the production Docker images (API, worker, web, PostgreSQL, Redis) through the API and a real browser on desktop and…

    101 GitHub stars~675 tokensUpdated today
    Testing & QAAuto-check passed
  • Author OpenClaw Docker E2E and live provider Docker lanes. An agent skill from openclaw/openclaw.

    392k GitHub stars~593 tokensUpdated today
    Testing & QAAuto-check passed
  • Plan and run pre-release OpenClaw plugin validation across bundled plugins, package artifacts, lifecycle commands, doctor/fix, config round-trip, gateway startup, SDK compatibility, Docker E2E…

    392k GitHub stars~3.1k tokensUpdated today
    Testing & QAAuto-check passed

More from awebai/aweb

All 17 skills in this repo
  • Recognizes old aweb bootstrap-era `agents/` directories and migrates them to current team and identity primitives, since the old command family is retired.

    115 GitHub stars~701 tokensUpdated today
    Auto-check passed
  • Guides decisions for agents working in an aweb team: when to check shared state, claim tasks, take locks, read team roles and instructions, and open separate worktrees.

    115 GitHub stars~4k tokensUpdated today
    Auto-check passed
  • aweb Messaging

    awebai/aweb

    Guides how an agent reads and responds to aweb mail and chat events, choosing between asynchronous mail and synchronous chat and respecting sender verification and encryption boundaries.

    115 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • This skill should be used when joining or being added to an aweb team, picking the correct invite/add-member path for the team's authority model (hosted vs BYOT), accepting invites, fetching team…

    115 GitHub stars~5.4k tokensUpdated today
    Auto-check passed
  • Creates or appends a folio document from the built-in pitch, memo or metrics templates by sending schema-checked slots that folio renders to Markdown.

    115 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Present To Human

    awebai/aweb

    A skill your agent uses when an agent needs to show a human an folio document: mint a document-bound capability link with POST /v1/present, open the returned URL for the human, print it as fallback…

    115 GitHub stars~590 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Byot E2E Validation

What does Byot E2E Validation do?

A skill your agent uses when writing e2e tests for BYOT/AWID team-certificate auth, testing aw id request --team-auth, building a docker awid-service harness, or validating replay, revocation…. Byot E2E Validation is an agent skill from awebai/aweb. Use when writing e2e tests for BYOT/AWID team-certificate auth, testing aw id request --team-auth, building a docker awid-service harness, or validating replay, revocation, fail-closed, and team-scoping behavior.

When should I use Byot E2E Validation?

Byot E2E Validation fits situations like: writing e2e tests for BYOT/AWID team-certificate auth; testing aw id request --team-auth; building a docker awid-service harness; validating replay.

How do I install Byot E2E Validation in Claude Code?

Run `npx skills add awebai/aweb --skill byot-e2e-validation -a claude-code`. Or copy the skill folder (naapp/folio/skills/byot-e2e-validation in awebai/aweb) into .claude/skills/byot-e2e-validation in your project. Claude Code loads it when a task matches its description.

How do I install Byot E2E Validation in Codex?

Run `npx skills add awebai/aweb --skill byot-e2e-validation -a codex`. Or copy the skill folder (naapp/folio/skills/byot-e2e-validation in awebai/aweb) into .agents/skills/byot-e2e-validation in your project. Codex loads it when a task matches its description.

Can I use Byot E2E Validation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awebai/aweb --skill byot-e2e-validation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/byot-e2e-validation, .gemini/skills/byot-e2e-validation, .github/skills/byot-e2e-validation and .opencode/skills/byot-e2e-validation in your project.

What does Byot E2E Validation need to run?

Going by SKILL.md and its folder, Byot E2E Validation needs the command-line tools its instructions call (docker and make). Our summary lists: Docker.

Does Byot E2E Validation access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Byot E2E Validation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Byot E2E Validation use?

Byot E2E Validation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Byot E2E Validation use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Byot E2E Validation?

Skills that share tags, products or a category with Byot E2E Validation: Go Redis Client Test Runner (redis/go-redis, 22k stars), Dqd Lab (ctrsploit/ctrsploit, 154 stars), Crabbox Setup (AI-Builder-Club/skills, 1.3k stars) and E2E (openathleteorg/openathlete, 101 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Byot E2E Validation?

awebai (a GitHub organization) maintains it in awebai/aweb, which has 115 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 9, 2026.

Source: awebai/aweb on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.