Agent skill

Moav E2E

by MotherofallVPNs in MotherofallVPNs/MoaV

Run and debug MoaV's end-to-end tests — real protocol connectivity (client-test.sh) and the moav CLI smoke test — against a LIVE server, via the self-hosted e2e workflow or a local test VPS.

MITAuto-check: notesTesting & QA

Install Moav E2E

skills CLI
$ npx skills add MotherofallVPNs/MoaV --skill moav-e2e -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MotherofallVPNs/MoaV moav-e2e --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MotherofallVPNs/MoaV.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/moav-e2e .claude/skills/moav-e2e && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
moav-e2e
GitHub stars
448
Token cost
~1.9k tokens
SKILL.md length
724 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Run and debug MoaV's end-to-end tests — real protocol connectivity (client-test.sh) and the moav CLI smoke test — against a LIVE server, via the self-hosted e2e workflow or a local test VPS.

  • Validating a branch before release
  • SKILL.md covers How to run, Reading the result, Known failure modes → fixes and Client round-trip (moav-client…
  • Calls gh, docker and go; needs ADMIN_PASSWORD
  • Diagnosing a protocol that wont connect

What it does

Moav E2E is an agent skill from MotherofallVPNs/MoaV. Run and debug MoaV's end-to-end tests — real protocol connectivity (client-test.sh) and the moav CLI smoke test — against a LIVE server, via the self-hosted e2e workflow or a local test VPS. Use when validating a branch before release, diagnosing a protocol that won't connect, or checking that moav CLI commands still work after a change. Knows the domainless (no-cert) vs domain (full-protocol) modes, how to read the pass/warn/skip/fail matrix, and the known failure modes with their fixes.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering End-to-end testing and QA and bug reports. The licence is MIT.

When your agent uses it

  • Validating a branch before release
  • Diagnosing a protocol that wont connect
  • Checking that moav CLI commands still work after a change

Example prompts

  • “/moav-e2e”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 47e213e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • docker
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ADMIN_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Moav E2E loads about 1.9k tokens when it runs. Until then it costs about 126 tokens; SKILL.md has 724 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~126
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:57
    cp .env.example .env      # set DOMAIN, ACME_EMAIL, ADMIN_PASSWORD, SERVER_IP,
  • NoteRuns commands with sudoSKILL.md:68
    `sudo chown -R "$(id -u):$(id -g)" configs state outputs`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MotherofallVPNs/MoaV at commit 47e213e, republished under its MIT licence (© MotherofallVPNs). 724 words, ~1,883 tokens.

Download SKILL.mdSave it as .claude/skills/moav-e2e/SKILL.md (or your agent's skills folder).
name
moav-e2e
description
Run and debug MoaV's end-to-end tests — real protocol connectivity (client-test.sh) and the moav CLI smoke test — against a LIVE server, via the self-hosted e2e workflow or a local test VPS. Use when validating a branch before release, diagnosing a protocol that won't connect, or checking that moav CLI commands still work after a change. Knows the domainless (no-cert) vs domain (full-protocol) modes, how to read the pass/warn/skip/fail matrix, and the known failure modes with their fixes.

MoaV end-to-end testing

Two layers run against a live server (not mocks):

  • tests/client-test.sh (moav test <user> [--json] [-v]) — stands up a client-side tunnel per protocol and checks the exit IP. This is the protocol matrix.
  • tests/cli-smoke-test.sh — exercises the moav tool (help/status/users/doctor/cert/ export→import/user add+revoke/admin password/…), each hang-guarded.

The per-PR CI (ci.yml) only lints + unit-tests; it never brings the stack up. Full e2e is .github/workflows/e2e.yml on a self-hosted runner (a test VPS with a real test domain), because it builds ~25 images and needs real TLS certs. Human setup doc: docs/devdocs/E2E-TESTING.md.

How to run

Preferred: the self-hosted workflow
bash
# domainless — no cert, no Let's Encrypt dependency. Fast to iterate, validates the
# IP-only protocols + the client image build. START HERE when debugging.
gh workflow run e2e.yml -R MotherofallVPNs/moav --ref <branch> -f verbose=true -f domainless=true

# domain — full matrix incl. the TLS-domain protocols (Trojan/Hysteria2/AnyTLS/CDN).
# Reuses the cert across runs; DON'T run more than ~5/week (LE limit).
gh workflow run e2e.yml -R MotherofallVPNs/moav --ref <branch> -f verbose=true

# full — also build --local + a second domainless phase + image-removal uninstall (slow).
gh workflow run e2e.yml -R MotherofallVPNs/moav --ref <branch> -f full=true

Then get the run id and watch it (watch in the background so tool output stays out of context):

bash
sleep 8
gh run list -R MotherofallVPNs/moav --workflow e2e.yml --limit 1 --json databaseId,status
gh run watch <id> -R MotherofallVPNs/moav   # run in background; you're re-invoked on finish

The workflow must live on the default branch (main) for workflow_dispatch to show up; dispatch then runs the selected branch's copy.

Local (on the test VPS itself)
bash
cp .env.example .env      # set DOMAIN, ACME_EMAIL, ADMIN_PASSWORD, SERVER_IP,
                          # INITIAL_USERS=1, DEFAULT_PROFILES=all  (empty DOMAIN = domainless)
./moav.sh build
./moav.sh bootstrap --yes
./moav.sh start all
sleep 45
./moav.sh user add e2e-test
./moav.sh test e2e-test --json   # machine-readable matrix; add -v for per-protocol debug

If moav ran as root in containers but you invoke the CLI as non-root, reclaim ownership first: sudo chown -R "$(id -u):$(id -g)" configs state outputs.

Reading the result

moav test --json emits { overall_status, summary:{pass,fail,warn,skip}, tests:{<proto>:{status}} }.

  • pass — connected, confirmed a real exit IP. fail — should have worked, didn't → fails the run.
  • warn — reachable but not fully confirmed (throttled DNS tunnel, IPv6-only path, telemt w/o openssl). Does not fail.
  • skip — not in the bundle (disabled / no client binary). Does not fail.

The workflow's Evaluate step fails only on fail. A domainless run correctly shows the TLS-domain protocols (trojan/anytls/hysteria2/cdn) and DNS tunnels as skip (disabled), and Reality/Shadowsocks/XHTTP/WireGuard/AmneziaWG/telemt as pass.

Pull the matrix from a finished run:

bash
gh run view <id> -R MotherofallVPNs/moav --json conclusion,jobs \
  --jq '.conclusion, (.jobs[].steps[] | select(.conclusion=="failure") | "FAILED: \(.name)")'
gh run view <id> -R MotherofallVPNs/moav --log | \
  awk -F'\t' '$2=="Evaluate results"' | sed 's/^[^\t]*\t[^\t]*\t//' | grep -E ': (pass|fail|warn|skip)|Failed protocols'

Known failure modes → fixes

Fix the repo, don't paper over it in the test. Each of these was a real bug.

Symptom in the logCauseFix
sing-box: cannot execute: required file not foundPrebuilt sing-box is glibc-dynamic (/lib64/ld-linux-x86-64.so.2); client image is Alpine/muslDockerfile.client installs real glibc + the /lib64 loader symlink. Verify: docker run --rm moav-client sing-box version
Protocol error unchanged after a client fixmoav test reused a stale moav-client imagemoav test always rebuilds now; if editing older code, docker rmi moav-client first
too many certificates … retry after <date>LE 5/week per-domain limit — a run re-issued the certDomain runs reuse the moav_certs volume; only full wipes it. Blocked? use -f domainless=true.
certbot … exit 1 on first issueApex A record missing / port 80 closed / Cloudflare-proxied (HTTP-01 needs DNS-only)Fix DNS; diagnostics step dumps the certbot log
Skipping sing-box (not configured) → empty bundle (only README.html)Host CLI (non-root runner) can't read root-owned configs/Reclaim step chowns configs/state/outputs before the CLI runs; assert bundle has ≥1 non-README file
Bootstrap [y/N] then Bootstrap cancelled (/dev/tty: No such device)Re-bootstrap prompts; no TTY defaults to nomoav bootstrap --yes
User '<u>' already existsState persisted from a prior runRevoke-then-add: `moav user revoke <u> 2>/dev/null
moav test --json output truncated (no overall_status)((count++)) returns 1 at 0→1 under set -e, killing the scriptset-e-safe arithmetic (x=$((x+1))) — general bash-under-set -e gotcha
moav export → Permission denied on state/keys/*.keyRoot containers stage root-owned files; host tar (non-root) can't read themexport chowns the staged copy via a root container before tarring
tar: stdout: write error late in exporttar -tzf … | head SIGPIPE under pipefail (>30 files)tolerate the broken pipe (… | head -30 || true)
No such file or directory: …/config.json.template after a wipeOver-eager cleanup deleted repo-tracked templates in configs/Wipe only the docker volumes (down -v), never configs/ — it holds tracked *.template
Show full SKILL.md (155 more words)Show less
Cross-run state coupling (important)

Preserving volumes for cert reuse couples runs: moav_state keeps .bootstrapped + keys, so a re-bootstrap can skip regenerating host configs and leave user add with nothing — intermittently. Rule of thumb: only DOMAIN runs keep state (they need the cert); domainless/full runs start from a clean slate (docker compose --profile all down -v — volumes only). Known open follow-up: re-bootstrap on existing state doesn't reliably regenerate host configs — a real bootstrap.sh bug worth fixing so 2nd+ domain runs are repeatable.

Client round-trip (moav-client — Epic 5, planned)

Server-side e2e is done. The client analogue is not built yet: provision a user on the server, import the bundle into MotherofallVPNs/moav-client, connect per protocol, verify the exit IP, and diff against the server's expected matrix. moav-client already has Go unit tests + CI (go test -race, tsc+vite build, shellcheck); the gap is the live round-trip. Wire it here when Epic 5 starts, sharing this file's result-interpretation + failure-mode tables.

© MotherofallVPNs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/moav-e2e of MotherofallVPNs/MoaV.

Open the folder on GitHubat commit 47e213e

Compare with similar skills

Moav E2E next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Moav E2E compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Moav E2E this skillMotherofallVPNs/MoaV448—~1.9kAutomated safety check: NotesMIT
Validate Stylebotankit/stylebot1.6k—~780Automated safety check: PassMIT
Whole-App Health Sweepreticlehq/reticle1.2k—~1.1kAutomated safety check: PassApache-2.0
Stark Smoke TestScaffold-Stark/scaffold-stark-2109—~3kAutomated safety check: NotesNone
Vss E2E Smokeopen-edge-platform/edge-ai-libraries169—~1.5kAutomated safety check: PassApache-2.0
Testing QAaiskillstore/marketplace4303 repos~1.2kAutomated safety check: PassNone

Similar skills

  • Validate Stylebot

    ankit/stylebot

    Launch Stylebot in a real, headed Chrome window (via yarn dev:chrome) so the user can manually eyeball a change — in whatever checkout the current session is in, worktree or main.

    1.6k GitHub stars~780 tokensUpdated today
    Testing & QAAuto-check passed
  • Whole-App Health Sweep

    reticlehq/reticle

    Sweeps a running web app by clicking every reachable control, then reports dead buttons, console errors, failed requests and mismatches between API data and the screen.

    1.2k GitHub stars~1.1k tokensUpdated today
    Testing & QAAuto-check passed
  • Stark Smoke Test

    Scaffold-Stark/scaffold-stark-2

    Use after Phase 1 dependency updates are merged, before any Phase 2 propagation to sibling forks - runs the end-to-end devnet gate (up brings devnet/deploy/dev-server up, verify drives Chrome over…

    109 GitHub stars~3k tokensUpdated 2 mo ago
    Testing & QAAuto-check: notes
  • Vss E2E Smoke

    open-edge-platform/edge-ai-libraries

    Run this skill whenever the user asks to verify my VSS install works, smoke test VSS, check whether the deployment succeeded, or run an end-to-end test of summary/search for the…

    169 GitHub stars~1.5k tokensUpdated today
    Testing & QAAuto-check passed
  • Testing QA

    aiskillstore/marketplace

    Comprehensive testing and QA workflow covering unit testing, integration testing, E2E testing, browser automation, and quality assurance.

    430 GitHub starsUsed in 3 repos~1.2k tokens
    Testing & QAAuto-check passed
  • QA Engineer

    nagisanzenin/production-grade

    [production-grade internal] Writes and runs tests when you want to verify code works — unit, integration, e2e, performance, contract testing.

    181 GitHub stars~7.7k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed

Categories

Questions about Moav E2E

What does Moav E2E do?

Run and debug MoaV's end-to-end tests — real protocol connectivity (client-test.sh) and the moav CLI smoke test — against a LIVE server, via the self-hosted e2e workflow or a local test VPS. Moav E2E is an agent skill from MotherofallVPNs/MoaV.sh) and the moav CLI smoke test — against a LIVE server, via the self-hosted e2e workflow or a local test VPS.

When should I use Moav E2E?

Moav E2E fits situations like: validating a branch before release; diagnosing a protocol that wont connect; checking that moav CLI commands still work after a change.

How do I install Moav E2E in Claude Code?

Run `npx skills add MotherofallVPNs/MoaV --skill moav-e2e -a claude-code`. Or copy the skill folder (.claude/skills/moav-e2e in MotherofallVPNs/MoaV) into .claude/skills/moav-e2e in your project. Claude Code loads it when a task matches its description.

How do I install Moav E2E in Codex?

Run `npx skills add MotherofallVPNs/MoaV --skill moav-e2e -a codex`. Or copy the skill folder (.claude/skills/moav-e2e in MotherofallVPNs/MoaV) into .agents/skills/moav-e2e in your project. Codex loads it when a task matches its description.

Can I use Moav E2E in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MotherofallVPNs/MoaV --skill moav-e2e -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/moav-e2e, .gemini/skills/moav-e2e, .github/skills/moav-e2e and .opencode/skills/moav-e2e in your project.

What does Moav E2E need to run?

Going by SKILL.md and its folder, Moav E2E needs the command-line tools its instructions call (gh, docker and go) and credentials named ADMIN_PASSWORD. Our summary lists: Docker.

Does Moav E2E access the network?

SKILL.md contains no URLs. Its commands use gh and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Moav E2E safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Moav E2E use?

Moav E2E is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Moav E2E use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Moav E2E?

Skills that share tags, products or a category with Moav E2E: Validate Stylebot (ankit/stylebot, 1.6k stars), Whole-App Health Sweep (reticlehq/reticle, 1.2k stars), Stark Smoke Test (Scaffold-Stark/scaffold-stark-2, 109 stars) and Vss E2E Smoke (open-edge-platform/edge-ai-libraries, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Moav E2E?

MotherofallVPNs (a GitHub organization) maintains it in MotherofallVPNs/MoaV, which has 448 GitHub stars. The repository was last updated on October 7, 2026.

Source: MotherofallVPNs/MoaV on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.