Web Application Testing
anthropics/skills
Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.
Choose and run unit, E2E, Caddyfile fixture, automation, and CI checks for caddy-security.
$ npx skills add greenpau/caddy-security --skill testing-and-ci -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install greenpau/caddy-security testing-and-ci --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/testing-and-ci .claude/skills/testing-and-ci && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "testing-and-ci" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/testing-and-ci into .claude/skills/testing-and-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-and-ci", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/greenpau/caddy-security/tree/main/.codex/skills/testing-and-ciType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add greenpau/caddy-security --skill testing-and-ci -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install greenpau/caddy-security testing-and-ci --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/testing-and-ci .agents/skills/testing-and-ci && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "testing-and-ci" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/testing-and-ci into .agents/skills/testing-and-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-and-ci", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill testing-and-ci -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install greenpau/caddy-security testing-and-ci --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/testing-and-ci .cursor/skills/testing-and-ci && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "testing-and-ci" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/testing-and-ci into .cursor/skills/testing-and-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-and-ci", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/greenpau/caddy-security.git --path .codex/skills/testing-and-ci--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add greenpau/caddy-security --skill testing-and-ci -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install greenpau/caddy-security testing-and-ci --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/testing-and-ci .gemini/skills/testing-and-ci && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "testing-and-ci" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/testing-and-ci into .gemini/skills/testing-and-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-and-ci", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install greenpau/caddy-security testing-and-ciInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add greenpau/caddy-security --skill testing-and-ci -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/testing-and-ci .github/skills/testing-and-ci && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "testing-and-ci" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/testing-and-ci into .github/skills/testing-and-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-and-ci", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill testing-and-ci -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install greenpau/caddy-security testing-and-ci --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/testing-and-ci .opencode/skills/testing-and-ci && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "testing-and-ci" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/testing-and-ci into .opencode/skills/testing-and-ci/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-and-ci", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
testing-and-ciChoose and run unit, E2E, Caddyfile fixture, automation, and CI checks for caddy-security.
Testing And CI is an agent skill from greenpau/caddy-security. Choose and run unit, E2E, Caddyfile fixture, automation, and CI checks for caddy-security. Use for coverage requirements, test evidence, failures, and report workflows; official OP conformance remains opt-in.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `agents/openai.yaml`, `references/composition-qualification.md` and `references/test-surfaces.md`).
It sits in Testing & QA, covering End-to-end testing. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
makegoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Testing And CI loads about 4.1k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 56 tokens; SKILL.md has 1,956 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 1,956 words, ~4,061 tokens.
.claude/skills/testing-and-ci/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Use headless Chrome for browser E2E tests, screenshots, developer-tools
network traces, and conformance visual evidence. Avoid Firefox unless the user
explicitly requests it for a browser-specific investigation. Prefer a pinned
Chrome for Testing distribution for reproducible external workflows; keep its
binary, driver, profiles, caches and artifacts under this repository's tmp/.
Preserve real browser interaction and TLS validation. Do not set
acceptInsecureCerts, ignore-certificate flags, disable web security, rewrite
Origin headers, or fabricate successful callbacks to make a conformance run pass.
Use this skill for caddy-security test selection, fixture maintenance, and CI
reproduction. Prefer the narrowest go test command while editing, then use
Makefile targets when the user asks for the repository workflow, report
artifacts, or CI-like validation.
The Go module is rooted at the repository top level. Most tests live in the
root security package and cover Caddyfile parsing, Caddyfile adaptation, and
runtime authcrunch config resolution.
Follow the repository scope.
Create and run tests in this module only; never run sibling suites to validate
work here or fix a failing test by editing the sibling. TEST_DIR and
QUICK_TEST_DIR must select this module's packages, and COVERAGE_DIR must not
point into another checkout. Existing local replacements are dependency inputs
only. Keep compatibility fixtures and reports here and report required upstream
test or implementation changes as separate work.
When writing or changing code, ensure both unit tests and E2E tests exist and exercise the changed behavior. Add or amend tests where coverage is missing; existing tests count when they demonstrably verify that behavior. Run the relevant unit and E2E tests before considering the code change complete.
Unit tests should check focused behavior and meaningful failure cases. E2E tests should exercise the affected user-visible flow through the assembled system. For authentication, authorization, and lifecycle changes, use actual Caddy provisioning, routes, and HTTP requests as appropriate. Bound network, process, and worker completion; clean up test-owned resources. Parser/adapt tests and sibling go-authcrunch tests do not replace this repository's E2E coverage. Report missing coverage or blocked validation explicitly.
Use lifecycleAddress for disposable Caddy listener addresses. It checks both
TCP and UDP availability because Caddy's default HTTPS server also starts a
QUIC listener; a TCP-only ephemeral-port check can select an occupied UDP port.
The occupied-QUIC-port regression also verifies release of the rejected TCP
reservation. Reservations are released before Caddy takes ownership.
Every Caddyfile directive change also requires new or amended adaptation test
cases in testdata/caddyfile_adapt/, even when the resulting JSON shape is
unchanged. Register new cases in TestCaddyfileAdaptAuthenticationToJSON in
caddyfile_adapt_test.go so the fixture is exercised. This is additional to
unit and E2E coverage; use the fixture mechanics below.
Documentation/skill-only edits use metadata, link, and source checks from skill-authoring; they do not require new runtime tests.
Follow Syntax maintenance when parser grammar or a dependency changes. Inventory standalone Caddyfiles, Go syntax comments, skill examples, and inline positive/negative tests. Adapt runnable examples with a binary built from the selected dependencies. Wrap fragments in their actual global/portal/policy/site scope; do not run syntax catalogues or intentionally invalid examples as complete configurations.
Adaptation verifies only the validation reached by that parser. Raw crypto, messaging, registration, ACL, and other deferred settings also need focused resolution/validation checks when their examples change. Do not provision a real deployment, contact an external provider, or change machine trust merely to audit syntax. Preserve intentional failure fixtures and legacy alias tests. Report external-module requirements and runtime checks separately from adapt success. Comment-only edits do not change parser behavior; use source review, formatting, and relevant existing tests instead of adding tests that mirror prose.
Use direct Go tests for quick feedback:
go test ./...
go test -run TestParseCaddyfileAuthorization ./...
go test -run TestCaddyfileAdaptAuthenticationToJSON ./...
go test -run TestResolveRuntimeAppConfig ./...Use make test for the repository report lifecycle. go.mod pins
github.com/greenpau/tested v1.1.0, invoked as go tool tested; it owns -json,
-coverprofile, child-process status, and coherent reports. Do not reintroduce
go test | tee, log-grep success detection, richgo, tparse, or go-test-report.
make test
make test TEST='TestParseCaddyfileAuthorization' TEST_DIR='.'
make qtest TEST='TestParseCaddyfileAuthorization'
make run-reports
make test-automation
make ci-checkLifecycle runs use -mod=readonly -race -count=1 -p 1 -parallel 2 -timeout 60m -v. The macOS/Linux resource guard bounds the whole process tree,
including compilers, browser/CLI children and report rendering. Read
test resource controls
when changing defaults or investigating an interrupted run. The default wall
limit is 4,200 seconds, allowing compilation/report time around the 60-minute
package limit. Keep live tested output enabled; the guard also prints progress
every ten seconds.
TEST is a regex (default .), TEST_DIR accepts package patterns (default
./...), and TEST_TIMEOUT overrides the quoted per-package limit.
MINIMUM_COVERAGE defaults to 1 percent as a nonzero-profile check, matching
go-authcrunch; it is not a substantial coverage target.
Go's timeout covers the entire package, including all sequential E2E parent tests. The Caddy journeys also have their own shorter child-process deadlines. If CI times out, inspect the captured test events and active test duration to distinguish an exhausted package budget from a stuck individual journey. Keep the job budget larger than the package budget so setup, builds and report upload can finish; the current workflow allows 75 minutes around the 60-minute Go package limit.
Reports land in .coverage. make qtest defaults to the root package (.) with
reports in .coverage/quick; override QUICK_TEST_DIR and TEST for another
scope. Use COVERAGE_DIR for separate evidence bundles; guarded runs in the same
checkout cannot overlap, even with different output directories. Let tested
refresh its managed files without deleting other bundles or investigation
notes. make run-reports regenerates presentations from recorded evidence
and preserves failures; make coverage aliases it without rerunning tests.
Use make build when validation needs bin/authcrunch or
bin/caddy-authenticator; it builds both and prints their versions. Formatting is separate:
make fmtcfg formats fixtures under testdata/caddyfile_adapt and
assets/config. Builds/tests do not rewrite licenses, version files, module
manifests, or Caddyfiles. make dep downloads/verifies pinned dependencies and
resolves tested; it may need network access but does not install global tools.
Read test surfaces and qualification evidence when selecting existing unit/E2E tests, extending a feature suite, or changing coverage collection. It maps conditional authentication, CodeQL, subprocesses, logging, persistent state, operator examples, OIDC, refresh, native/CLI clients, local identity, authorization paths, lifecycle, and Caddyfile fixtures to their actual tests and limits.
For interactions among login, refresh, OIDC, upstream OAuth, authorization, edge metadata and reload, read composition qualification. The feature owner's acceptance contract determines what must be exercised; a list of parser fixtures alone never proves a user flow works.
Root-package E2E helpers run the same instrumented test executable. The subprocess coverage contract owns collection before parent completion, isolated child directories, counter publication, killed-process limits, and the regression workflow. Read it when adding a subprocess or changing report collection.
When adding or changing a Caddyfile directive, add focused parser coverage in
the nearest caddyfile_*_test.go file. Include both the successful config shape
and a malformed input when the parser has a meaningful error path.
For a Caddyfile directive change, add or amend adaptation cases in
testdata/caddyfile_adapt/: <prefix>.Caddyfile, <prefix>.json, and
optionally <prefix>.env, and update the test case registration as needed.
If runtime defaults, replacements, credentials, UI,
OAuth, registration, or cookie behavior changes after adaptation, also add or
update <prefix>_resolved.json and include the prefix in
TestResolveRuntimeAppConfig.
After fixture edits, run the focused test first, then a broader command:
go test -run TestCaddyfileAdaptAuthenticationToJSON ./...
go test -run TestResolveRuntimeAppConfig ./...
go test ./...If *_tmp_input.json or *_tmp_output.json files remain after a failing
runtime resolution test, inspect them, fix the fixture or implementation, and
remove the generated temp files before finishing unless the user explicitly
wants debug artifacts kept.
.github/workflows/build.yml runs on pushes/PRs to main, manual dispatch,
and reusable workflow calls. Its test job skips main push events whose head
commit message starts with ops: released v: the release script atomically
pushes that commit and its tag, and release.yml runs the gate for the tag.
Ordinary pushes, PRs, manual runs, and release tag validation still run tests.
It selects Ubuntu 24.04 and Go 1.26.8 with
GOTOOLCHAIN=local, plus Node 24, Python 3 and NSS utilities. It checks the
runner's Google Chrome installation for browser E2E. It resolves a versioned
artifact identity, runs make dep and make ci-check, and checks that
validation did not modify tracked source or add untracked source files.
The reusable job sets TEST_MEMORY_MB=6144 (6 GiB) for the public Ubuntu runner;
release validation inherits that budget. Local resource defaults remain unchanged.
See test resource controls
for the runner capacity and the guard's physical-memory reserve.
After the gate is attempted, it always uploads .coverage/, including hidden
files and partial failure evidence, with 14-day retention. Missing artifacts
fail the upload and test failures remain failures. Actions are pinned to
immutable revisions and the test workflow has read-only contents permission.
For local CI reproduction, use:
make dep
make ci-checkRelease CI, tag selection, artifact naming, packaging checks, and publication scope belong to release-and-versioning. The release workflow calls this reusable gate before GoReleaser.
make ci-check serializes version validation, Python automation fixtures, the
full Go report lifecycle, and the binary build, even under make -j. The full
Go suite includes real-browser refresh E2E through Caddy. It serves the selected
go-authcrunch embedded UI rather than building or running tests in the sibling
checkout.
The existing make linter remains a placeholder and is not a gate.
When changing tested or its invocation, run make test-automation. It exercises
real Make/tested processes in disposable repositories: filtering, full/quick/
custom bundle isolation, assertion failures, compile failures, short timeouts,
and failed offline reports. A live-log handshake proves output reaches Make
before the selected Go test completes. Guard unit and Make E2E fixtures cover
accounting, process cleanup, resource refusal, cancellation, lock contention,
nonblocking output and Linux process-exit races. The subprocess fixture retains
exact descendant coverage through guarded test and report invocations.
Version fixtures exercise the public artifact command and validated GITHUB_OUTPUT values without publishing remotely.
Archive-checker unit fixtures cover missing targets, checksum failures, mixed
binaries, incorrect documents and Unix executable permissions. For GoReleaser
packaging changes, also run a real snapshot release and the archive checker per
the packaging workflow;
fixture tests cannot establish cross-compilation or actual archive assembly.
The CLA workflow may update assets/cla/signatures.json through GitHub
automation. Do not edit CLA signatures or consent files unless the user asks.
Go's ./... discovery does not honor .gitignore. Name temporary Go helpers
with a leading underscore, or put them in an underscore-prefixed directory,
so ignored working files do not become extra test/coverage packages. Confirm
the package list with go list -mod=readonly ./.... Keep source files in place
until both the covered test run and report generation finish: the coverage
renderer still reads them after tests exit. Preserve a failed bundle before
rerunning; do not remove source files or edit coverage profiles to repair it.
Treat these as generated outputs unless the user explicitly asks to preserve or commit them:
bin/authcrunch
bin/caddy-authenticator
.coverage/index.html
.coverage/summary.json
.coverage/junit.xml
.coverage/coverage.html
.coverage/coverage.out
.coverage/test_output.jsonl
.coverage/test_output.html
.coverage/stderr.log
.coverage/run.json
.coverage/manifest.json
.coverage/resource-usage.json
.coverage/resource-report-usage.json
.coverage/test-resource.lock
testdata/caddyfile_adapt/*_tmp_input.json
testdata/caddyfile_adapt/*_tmp_output.jsonThe manifest is published last for a coherent generation; a failed run can
leave only partial evidence. Inspect run.json, stderr.log, and
test_output.jsonl before rerunning so failures are not overwritten without
review. Also inspect resource-usage.json for budget or monitoring failures.
A running or aborted guard record prevents offline reporting from accepting older tested
evidence. Preserve interrupted bundles and rerun into a fresh directory.
Test output and coverage sources are unredacted; use synthetic fixtures.
Formatted Caddyfiles and JSON fixtures can be intentional source changes. Review the diff after explicit format or fixture updates. Skill-only edits use skill-authoring and the default skill-creator validator instead of running the Go suite.
© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in .codex/skills/testing-and-ci of greenpau/caddy-security.
Open the folder on GitHubat commit a48553d
Testing And CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Testing And CI this skillgreenpau/caddy-security | 2.3k | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Web Application Testinganthropics/skills | 180k | 51 repos | ~966 | Automated safety check: Pass | Apache-2.0 | |
| TDD WorkflowhellangleZ/burn-in-cceverywhere-ralph | 112 | 11 repos | ~2.4k | Automated safety check: Pass | None | |
| Uloop Replay Inputkurotu/VRCQuestTools | 373 | 3 repos | ~615 | Automated safety check: Pass | MIT | |
| Ui4 Convert Testspayloadcms/payload | 45k | — | ~3.5k | Automated safety check: Pass | MIT | |
| E2Estackia/rtp2httpd | 2.2k | — | ~517 | Automated safety check: Pass | GPL-2.0 |
anthropics/skills
Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.
hellangleZ/burn-in-cceverywhere-ralph
A skill your agent uses when writing new features, fixing bugs, or refactoring code.
kurotu/VRCQuestTools
Replay recorded PlayMode keyboard and mouse input. An agent skill from kurotu/VRCQuestTools.
payloadcms/payload
A skill your agent uses when UI changes are complete and e2e tests need updating.
stackia/rtp2httpd
Write, run, review, or debug rtp2httpd E2E tests and their harness in e2e/ and scripts/run-e2e.sh.
MotherofallVPNs/MoaV
Run and debug MoaV's end-to-end tests — real protocol connectivity (client-test.sh) and the moav CLI smoke test — against a LIVE server, via the self-hosted e2e workflow or a local test VPS.
greenpau/caddy-security
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
greenpau/caddy-security
Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.
greenpau/caddy-security
Build or review caddy-security Caddyfiles and select focused configuration skills.
greenpau/caddy-security
Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.
greenpau/caddy-security
Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.
greenpau/caddy-security
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.
Categories
Choose and run unit, E2E, Caddyfile fixture, automation, and CI checks for caddy-security. Testing And CI is an agent skill from greenpau/caddy-security. Choose and run unit, E2E, Caddyfile fixture, automation, and CI checks for caddy-security.
Testing And CI fits situations like: coverage requirements; report workflows; official OP conformance remains opt-in.
Run `npx skills add greenpau/caddy-security --skill testing-and-ci -a claude-code`. Or copy the skill folder (.codex/skills/testing-and-ci in greenpau/caddy-security) into .claude/skills/testing-and-ci in your project. Claude Code loads it when a task matches its description.
Run `npx skills add greenpau/caddy-security --skill testing-and-ci -a codex`. Or copy the skill folder (.codex/skills/testing-and-ci in greenpau/caddy-security) into .agents/skills/testing-and-ci in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill testing-and-ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/testing-and-ci, .gemini/skills/testing-and-ci, .github/skills/testing-and-ci and .opencode/skills/testing-and-ci in your project.
Going by SKILL.md and its folder, Testing And CI needs the command-line tools its instructions call (make and go). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Testing And CI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Testing And CI: Web Application Testing (anthropics/skills, 180k stars), TDD Workflow (hellangleZ/burn-in-cceverywhere-ralph, 112 stars), Uloop Replay Input (kurotu/VRCQuestTools, 373 stars) and Ui4 Convert Tests (payloadcms/payload, 45k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.
Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.