Web Application Testing
anthropics/skills
Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.
Record a site's XHR into a HAR, derive an HTTP client. An agent skill from Luciole-Studio/Misaka-Agent.
$ npx skills add Luciole-Studio/Misaka-Agent --skill har-derived-api-client -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Luciole-Studio/Misaka-Agent har-derived-api-client --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Luciole-Studio/Misaka-Agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/misaka/core/skills/assets/optional/web-development/har-derived-api-client .claude/skills/har-derived-api-client && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "har-derived-api-client" agent skill from https://github.com/Luciole-Studio/Misaka-Agent/tree/main/misaka/core/skills/assets/optional/web-development/har-derived-api-client into .claude/skills/har-derived-api-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "har-derived-api-client", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Luciole-Studio/Misaka-Agent/tree/main/misaka/core/skills/assets/optional/web-development/har-derived-api-clientType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Luciole-Studio/Misaka-Agent --skill har-derived-api-client -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Luciole-Studio/Misaka-Agent har-derived-api-client --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Luciole-Studio/Misaka-Agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/misaka/core/skills/assets/optional/web-development/har-derived-api-client .agents/skills/har-derived-api-client && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "har-derived-api-client" agent skill from https://github.com/Luciole-Studio/Misaka-Agent/tree/main/misaka/core/skills/assets/optional/web-development/har-derived-api-client into .agents/skills/har-derived-api-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "har-derived-api-client", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Luciole-Studio/Misaka-Agent --skill har-derived-api-client -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Luciole-Studio/Misaka-Agent har-derived-api-client --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Luciole-Studio/Misaka-Agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/misaka/core/skills/assets/optional/web-development/har-derived-api-client .cursor/skills/har-derived-api-client && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "har-derived-api-client" agent skill from https://github.com/Luciole-Studio/Misaka-Agent/tree/main/misaka/core/skills/assets/optional/web-development/har-derived-api-client into .cursor/skills/har-derived-api-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "har-derived-api-client", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Luciole-Studio/Misaka-Agent.git --path misaka/core/skills/assets/optional/web-development/har-derived-api-client--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Luciole-Studio/Misaka-Agent --skill har-derived-api-client -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Luciole-Studio/Misaka-Agent har-derived-api-client --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Luciole-Studio/Misaka-Agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/misaka/core/skills/assets/optional/web-development/har-derived-api-client .gemini/skills/har-derived-api-client && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "har-derived-api-client" agent skill from https://github.com/Luciole-Studio/Misaka-Agent/tree/main/misaka/core/skills/assets/optional/web-development/har-derived-api-client into .gemini/skills/har-derived-api-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "har-derived-api-client", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Luciole-Studio/Misaka-Agent har-derived-api-clientInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Luciole-Studio/Misaka-Agent --skill har-derived-api-client -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Luciole-Studio/Misaka-Agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/misaka/core/skills/assets/optional/web-development/har-derived-api-client .github/skills/har-derived-api-client && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "har-derived-api-client" agent skill from https://github.com/Luciole-Studio/Misaka-Agent/tree/main/misaka/core/skills/assets/optional/web-development/har-derived-api-client into .github/skills/har-derived-api-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "har-derived-api-client", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Luciole-Studio/Misaka-Agent --skill har-derived-api-client -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Luciole-Studio/Misaka-Agent har-derived-api-client --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Luciole-Studio/Misaka-Agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/misaka/core/skills/assets/optional/web-development/har-derived-api-client .opencode/skills/har-derived-api-client && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "har-derived-api-client" agent skill from https://github.com/Luciole-Studio/Misaka-Agent/tree/main/misaka/core/skills/assets/optional/web-development/har-derived-api-client into .opencode/skills/har-derived-api-client/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "har-derived-api-client", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
har-derived-api-clientRecord a site's XHR into a HAR, derive an HTTP client. An agent skill from Luciole-Studio/Misaka-Agent.
Har Derived API Client is an agent skill from Luciole-Studio/Misaka-Agent. Record a site's XHR into a HAR, derive an HTTP client.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `scripts/har_capture.py`, `scripts/har_capture_cdp.py` and `scripts/har_to_client.py`).
It sits in Testing & QA. It works with Playwright. The repository describes itself as: A multi-agent research system for the humanities and social sciences. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b94464a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
python3pipplaywrightFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
en.wikipedia.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Har Derived API Client loads about 2.6k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 1,084 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from Luciole-Studio/Misaka-Agent at commit b94464a, republished under its MIT licence (© Luciole-Studio). 1,084 words, ~2,574 tokens.
.claude/skills/har-derived-api-client/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Drive a website once with a real browser while recording its network traffic to a HAR file, then distill that HAR into the site's private JSON API so you can call it directly with plain HTTP — far cheaper and faster than browser-controlling the page on every request. Credit: trick by Jared Longster, popularized by Dax (thdxr). This captures and replays; it does NOT bypass auth, solve CAPTCHAs, or defeat bot-detection — if the site needs a logged-in session, you carry its headers/cookies forward, you don't forge them.
The scripts are stdlib-plus-Playwright: capture needs Playwright, derivation
is pure stdlib, replay needs only requests/httpx (or curl).
Covers every Hermes browser pathway: the default local browser_navigate
backend, plus the cloud/remote backends (Browserbase, Browser-Use, Firecrawl)
and any /browser connect CDP endpoint. There are two capture scripts — one
for a browser you launch, one for a browser you attach to over CDP — because
HAR recording works differently in each case (see How to Run).
<website>" — derive its API instead of scripting clicks.browser_navigate for the same query repeatedly — stop and derive the endpoint once./browser connect and want the API without re-renting the browser.pip install playwright then playwright install chromium~/.cache/ms-playwright, reuse it.)requests or httpx for the replay step (stdlib urllib also works).har_capture_cdp.py): a reachable CDP endpoint. On Hermes,
run /browser connect to print the active endpoint, or read BROWSER_CDP_URL
/ browser.cdp_url in config. Cloud backends expose it as cdpUrl/connectUrl.Scripts under this skill's scripts/, invoked through the terminal tool.
Pick the capturer by pathway — this is the part that trips people up:
| Browser pathway | How Hermes reaches it | Capturer |
|---|---|---|
Local browser_navigate (default, agent-browser/Playwright) | launched locally | har_capture.py |
Camofox (CAMOFOX_URL set) | local REST/CDP | har_capture_cdp.py if it exposes CDP, else drive it yourself |
| Browserbase / Browser-Use / Firecrawl (cloud) | CDP (cdpUrl) | har_capture_cdp.py |
/browser connect <url> / BROWSER_CDP_URL | CDP | har_capture_cdp.py |
Rule of thumb: if Hermes launched the browser, use har_capture.py; if it
connected to one over CDP, use har_capture_cdp.py. har_capture.py uses
Playwright's record_har_path, which only works on a locally-owned context.
har_capture_cdp.py attaches with connect_over_cdp() and assembles the HAR
from page.on("request"/"response") events, because record_har_path is
unavailable on a connected browser.
Then, for either path:
har_to_client.py — filters the HAR to XHR/fetch/JSON, groups by endpoint, and prints params, headers, bodies, and replay hints (User-Agent / cookie / auth).Resolve paths against this skill's directory. Canonical loop:
# 1a. Capture, LOCAL browser (Hermes launched it)
python3 scripts/har_capture.py "https://SITE/" out.har \
--action "fill:input[name=search]:my query" --action "sleep:3" --wait 2
# 1b. Capture, CDP browser (cloud backend or /browser connect)
# get the endpoint from /browser connect or BROWSER_CDP_URL
python3 scripts/har_capture_cdp.py "ws://HOST/devtools/browser/..." out.har \
--goto "https://SITE/" --action "fill:input[name=search]:my query" \
--action "sleep:3" --wait 2
# 2. Derive — read the endpoints out of the HAR
python3 scripts/har_to_client.py out.har --host SITE --max-body 400
# 3. Replay — write a tiny client from the printed endpoint (see Procedure)har_capture.py <url> <out.har> [--wait S] [--headed] [--action SPEC ...]
action SPEC: fill:SELECTOR:TEXT | press:SELECTOR:KEY | click:SELECTOR
goto:URL | sleep:SECONDS (run in order after page load)
use when Hermes LAUNCHED the browser (local browser_navigate default)
har_capture_cdp.py <cdp_url> <out.har> [--goto URL] [--wait S] [--action SPEC ...]
same action SPEC; attaches to an existing CDP browser and does NOT close it
use for cloud backends (Browserbase/Browser-Use/Firecrawl) & /browser connect
har_to_client.py <in.har> [--host SUBSTR] [--include-static] [--max-body N]
default: keeps only XHR/fetch/JSON; --host narrows to one domain
prints per endpoint: query params, non-boring req headers, req body sample,
response status/content-type + body sample
prints "### Replay hints": the browser User-Agent, cookie/auth presencehar_capture.py; reached over CDP → har_capture_cdp.py. On Hermes, /browser connect tells you the CDP endpoint when a cloud/remote backend is active.browser_navigate (or --headed capture) to see which selector to type into / click, and confirm a JSON XHR fires in devtools/network.terminal tool. Order --action to reach the request: fill the box, then sleep long enough for the debounced XHR, and always leave --wait at the end so late responses flush. Both capturers embed response bodies, so the derived client sees real payload shapes.har_to_client.py --host <domain>. Read off: the method, the URL/path template (numeric/UUID segments collapse to {id}), query params, request-body JSON, and the ### Replay hints block.terminal tool and confirm it returns the same data the browser saw. This is the payoff: no browser in the loop.argparse script over the derived call, e.g. search.py "frank herbert".Worked example (Wikipedia search-title, derived + replayed live):
import requests
r = requests.get(
"https://en.wikipedia.org/w/rest.php/v1/search/title",
params={"q": "frank herbert", "limit": 5},
headers={"accept": "application/json",
"User-Agent": "Mozilla/5.0 ... Chrome/131 Safari/537.36"}, # from HAR
timeout=15,
)
for p in r.json()["pages"]:
print(p["title"], "-", p.get("description"))python-requests/x.y. Always send the browser UA from the replay hints. This is the #1 reason a derived client fails when the browser succeeded.--action aborts before the HAR flushes — you get no file. If capture errors on a selector, the run produced nothing; fix the selector (use --headed to watch) and rerun. Don't debug a missing HAR.har_to_client.py prints "No API-looking entries". The data came in the HTML; scrape it or find the interaction that does fetch JSON.--action "sleep:3" after fill; typing alone won't have fired the request when the HAR closes.Cookie/Authorization header, and those expire. The derived client is only as durable as the credential; re-capture when it 401s. HARs contain live secrets — treat out.har as sensitive and delete it after deriving.record_har_content="embed" makes big HARs. Use --max-body to cap what's printed; the file itself can be large for media-heavy pages.har_capture.py on a cloud/CDP backend records nothing (it launches its own local browser instead of the one you meant). har_capture_cdp.py needs the endpoint; on Hermes get it from /browser connect or BROWSER_CDP_URL. Match the capturer to the pathway (How to Run table).HeadlessChrome/... User-Agent; some sites sniff the "Headless" token. Cloud backends (Browserbase/Browser-Use) send a real desktop-Chrome UA, so a client derived from a cloud capture replays more reliably. If a headless-derived client 403s where the browser didn't, swap the "Headless" UA for a normal Chrome UA string before assuming the endpoint changed.har_capture_cdp.py attaches to a browser it doesn't own and leaves it running — correct for cloud/remote sessions Hermes manages. Don't add a close; let the owning backend tear it down.End-to-end proof against a live site with no API key:
python3 scripts/har_capture.py "https://en.wikipedia.org/wiki/Main_Page" /tmp/wiki.har \
--action "fill:input[name=search]:dune messiah" --action "sleep:3" --wait 2
python3 scripts/har_to_client.py /tmp/wiki.har --host wikipedia.org --max-body 200Expect the derivation to print GET https://en.wikipedia.org/w/rest.php/v1/search/title
with q and limit params and a JSON pages response — then replay it with the
Procedure snippet and confirm matching titles come back over plain HTTP.
© Luciole-Studio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts) in misaka/core/skills/assets/optional/web-development/har-derived-api-client of Luciole-Studio/Misaka-Agent.
Open the folder on GitHubat commit b94464a
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Luciole-Studio/Misaka-Agent, which our catalogue first saw on October 7, 2026.
Har Derived API Client next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Har Derived API Client this skillLuciole-Studio/Misaka-Agent | 139 | 1 repos | ~2.6k | Automated safety check: Pass | MIT | |
| Web Application Testinganthropics/skills | 180k | 51 repos | ~966 | Automated safety check: Pass | Apache-2.0 | |
| Playwright CLIsanity-io/sanity | 6.4k | 18 repos | ~1.9k | Automated safety check: Pass | MIT | |
| playwright-cli Browser Automationgithub/gh-aw | 5.4k | 24 repos | ~2.8k | Automated safety check: Pass | MIT | |
| Write and Verify Playwright Testsappsmithorg/appsmith | 41k | — | ~2.9k | Automated safety check: Notes | Apache-2.0 | |
| Cucumber and Playwright E2E Testslanggenius/dify | 158k | — | ~682 | Automated safety check: Pass | Custom licence |
anthropics/skills
Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.
sanity-io/sanity
Automates browser interactions for web testing, form filling, screenshots, and data extraction.
github/gh-aw
Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.
appsmithorg/appsmith
Writes a Playwright end-to-end test from a prompt, runs it against a live Appsmith deployment and retries with fixes up to three times until it passes.
langgenius/dify
Guides changes and reviews of the Cucumber and Playwright end-to-end suite under `e2e/`: feature files, step definitions, support code, tags, locators and assertions.
langflow-ai/langflow
Write and review Playwright E2E tests for Langflow. An agent skill from langflow-ai/langflow.
Luciole-Studio/Misaka-Agent
Plan and run multi-agent video production pipelines. An agent skill from Luciole-Studio/Misaka-Agent.
Luciole-Studio/Misaka-Agent
AST-aware structural code search and rewrite via ast-grep. An agent skill from Luciole-Studio/Misaka-Agent.
Luciole-Studio/Misaka-Agent
Drug discovery: ChEMBL search, drug-likeness, interactions. An agent skill from Luciole-Studio/Misaka-Agent.
Luciole-Studio/Misaka-Agent
Workout planning, macros, and body metrics via wger/USDA. An agent skill from Luciole-Studio/Misaka-Agent.
Luciole-Studio/Misaka-Agent
Render MP4/WebM videos from HTML compositions. An agent skill from Luciole-Studio/Misaka-Agent.
Luciole-Studio/Misaka-Agent
Follow the money via public records and sanctions data. An agent skill from Luciole-Studio/Misaka-Agent.
Works with
Categories
Record a site's XHR into a HAR, derive an HTTP client. An agent skill from Luciole-Studio/Misaka-Agent. Har Derived API Client is an agent skill from Luciole-Studio/Misaka-Agent. Record a site's XHR into a HAR, derive an HTTP client.
Har Derived API Client fits situations like: testing & QA work in your project.
Run `npx skills add Luciole-Studio/Misaka-Agent --skill har-derived-api-client -a claude-code`. Or copy the skill folder (misaka/core/skills/assets/optional/web-development/har-derived-api-client in Luciole-Studio/Misaka-Agent) into .claude/skills/har-derived-api-client in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Luciole-Studio/Misaka-Agent --skill har-derived-api-client -a codex`. Or copy the skill folder (misaka/core/skills/assets/optional/web-development/har-derived-api-client in Luciole-Studio/Misaka-Agent) into .agents/skills/har-derived-api-client in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Luciole-Studio/Misaka-Agent --skill har-derived-api-client -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/har-derived-api-client, .gemini/skills/har-derived-api-client, .github/skills/har-derived-api-client and .opencode/skills/har-derived-api-client in your project.
Going by SKILL.md and its folder, Har Derived API Client needs Python for the scripts in its folder and the command-line tools its instructions call (python3, pip and playwright). Our summary lists: Python 3.
SKILL.md names 1 domain. In commands or code: en.wikipedia.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Har Derived API Client is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Har Derived API Client: Web Application Testing (anthropics/skills, 180k stars), Playwright CLI (sanity-io/sanity, 6.4k stars), playwright-cli Browser Automation (github/gh-aw, 5.4k stars) and Write and Verify Playwright Tests (appsmithorg/appsmith, 41k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Luciole-Studio (a GitHub organization) maintains it in Luciole-Studio/Misaka-Agent, which has 139 GitHub stars. The repository holds 76 skills in this directory. The repository was last updated on October 8, 2026.
Source: Luciole-Studio/Misaka-Agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.