Agent skill

Web App Verification

by Porabuild in Porabuild/Poracode

Prove a web change actually works by exercising the flow in Poracode's browser and collecting visual, console, and network evidence.

Apache-2.0Auto-check passed

Install Web App Verification

skills CLI
$ npx skills add Porabuild/Poracode --skill web-app-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Porabuild/Poracode web-app-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Porabuild/Poracode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/resources/plugins/browser-tools/skills/web-app-verification .claude/skills/web-app-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
web-app-verification
GitHub stars
114
Token cost
~465 tokens
SKILL.md length
267 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

Prove a web change actually works by exercising the flow in Poracode's browser and collecting visual, console, and network evidence.

  • SKILL.md covers Set the baseline, Exercise the flow, Collect the evidence and Verdict
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Web App Verification is an agent skill from Porabuild/Poracode. Prove a web change actually works by exercising the flow in Poracode's browser and collecting visual, console, and network evidence.

Its SKILL.md is about 470 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: One window for all your AI coding agents. Run Claude, Codex, OpenCode, Gemini, Antigravity, Cursor, and Copilot side-by-side. Terminal and chat, any layout. The licence is Apache-2.0.

Example prompts

  • “/web-app-verification”

What it can do on your machine

Read from SKILL.md and the folder at commit bffd89d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Web App Verification loads about 465 tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 267 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~465

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Porabuild/Poracode at commit bffd89d, republished under its Apache-2.0 licence (© Porabuild). 267 words, ~465 tokens.

Download SKILL.mdSave it as .claude/skills/web-app-verification/SKILL.md (or your agent's skills folder).
name
web-app-verification
description
Prove a web change actually works by exercising the flow in Poracode's browser and collecting visual, console, and network evidence.

Web App Verification

A change is not verified because the code looks right or the build passed. Drive the real flow and report what the app did.

Set the baseline

Call browser.enable once, then open the exact target the user named — their local dev URL, their preview deployment. Do not substitute a different URL or a web search when the page is unreachable; say it is unreachable.

Capture the starting state with browser.snapshot plus the current URL, and clear the console with a reload so pre-existing noise is not mistaken for your change. Note any errors that survive the reload — those are the baseline, not your regression.

Exercise the flow

Walk the path a user would take, one action at a time, using the refs from the snapshot rather than coordinates. After each navigation or state-changing action, wait for the expected URL, text, or element before continuing.

Test the boundaries the change actually touched: the empty state, the error path, the second submit. A single happy path proves very little.

Collect the evidence

For every claim you intend to make, hold one artifact:

  • Visual — a screenshot when layout, spacing, or appearance is part of the requirement.
  • Console — browser.console after the flow, separating new errors from the baseline.
  • Network — failed or unexpected requests from browser.requests, with status codes.

Verdict

State plainly what you verified, what you observed, and what you could not check — a flow behind a login you do not have, a path that needs data you cannot create. "Works" without evidence is not a verdict.

Call browser.disable before you stop or hand back to the user.

© Porabuild, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in resources/plugins/browser-tools/skills/web-app-verification of Porabuild/Poracode.

Open the folder on GitHubat commit bffd89d

Compare with similar skills

Web App Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Web App Verification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Web App Verification this skillPorabuild/Poracode114—~465Automated safety check: PassApache-2.0
Scaffold Exercisesvinvcn/mattpocock-skills-zh-CN4.7k—~767Automated safety check: PassMIT
Performing Soc Tabletop Exercisemukul975/Anthropic-Cybersecurity-Skills34k—~4.2kAutomated safety check: PassApache-2.0
Performing Ransomware Tabletop Exercisemukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Performing Purple Team Exercisemukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.0
ActualizeNeoLabHQ/context-engineering-kit1.7k—~932Automated safety check: PassGPL-3.0

Similar skills

  • Scaffold Exercises

    vinvcn/mattpocock-skills-zh-CN

    创建包含章节、题目、答案和讲解的练习目录结构,并确保通过 linting。适用于用户想 scaffold exercises、创建 exercise stubs,或设置新的课程章节时。

    4.7k GitHub stars~767 tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • Performing Soc Tabletop Exercise

    mukul975/Anthropic-Cybersecurity-Skills

    Performs tabletop exercises for SOC teams simulating security incidents through discussion-based scenarios to test incident response procedures, communication workflows, and decision-making under…

    34k GitHub stars~4.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Ransomware Tabletop Exercise

    mukul975/Anthropic-Cybersecurity-Skills

    Plans and facilitates tabletop exercises simulating ransomware incidents, using realistic scenarios based on threat actors like LockBit and ALPHV/BlackCat with injects covering double extortion and…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Purple Team Exercise

    mukul975/Anthropic-Cybersecurity-Skills

    Performs purple team exercises by coordinating red team adversary emulation with blue team detection validation using MITRE ATT&CK-mapped attack scenarios, real-time detection testing, and…

    34k GitHub stars~3.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Actualize

    NeoLabHQ/context-engineering-kit

    Reconcile the project's FPF state with recent repository changes

    1.7k GitHub stars~932 tokensUpdated 1 mo ago
    Knowledge ManagementAuto-check passed
  • Scaffold Exercises

    fossasia/eventyay-interpretation

    Create exercise directory structures with sections, problems, solutions, and explainers that pass linting.

    1.6k GitHub starsUsed in 11 repos~898 tokens
    DevelopmentAuto-check passed

More from Porabuild/Poracode

All 21 skills in this repo
  • Interactive Testing

    Porabuild/Poracode

    Run repeatable integration and smoke testing against the real Poracode Electron app through Chrome DevTools Protocol.

    114 GitHub stars~4.5k tokensUpdated today
    Auto-check: notes
  • Release Notes

    Porabuild/Poracode

    Write consistent, hand-written-looking changelog entries for a Poracode release.

    114 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Skill Creator Poracode

    Porabuild/Poracode

    Create a new reusable agent skill managed by Poracode. An agent skill from Porabuild/Poracode.

    114 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • App Controls

    Porabuild/Poracode

    Inspect and drive Poracode itself — the Terminal panel, other threads, projects, workspaces, git, pull requests, and schedules — through the poracode MCP.

    114 GitHub stars~745 tokensUpdated today
    Auto-check passed
  • Chrome Control

    Porabuild/Poracode

    Use the user's real Chrome tabs and signed-in sessions for visible browser workflows.

    114 GitHub stars~691 tokensUpdated today
    Auto-check passed
  • Computer Use

    Porabuild/Poracode

    Inspect and operate native Windows, macOS, or Linux applications through Poracode's desktop-control tools.

    114 GitHub stars~718 tokensUpdated today
    Auto-check passed

Questions about Web App Verification

What does Web App Verification do?

Prove a web change actually works by exercising the flow in Poracode's browser and collecting visual, console, and network evidence. Web App Verification is an agent skill from Porabuild/Poracode. Prove a web change actually works by exercising the flow in Poracode's browser and collecting visual, console, and network evidence.

How do I install Web App Verification in Claude Code?

Run `npx skills add Porabuild/Poracode --skill web-app-verification -a claude-code`. Or copy the skill folder (resources/plugins/browser-tools/skills/web-app-verification in Porabuild/Poracode) into .claude/skills/web-app-verification in your project. Claude Code loads it when a task matches its description.

How do I install Web App Verification in Codex?

Run `npx skills add Porabuild/Poracode --skill web-app-verification -a codex`. Or copy the skill folder (resources/plugins/browser-tools/skills/web-app-verification in Porabuild/Poracode) into .agents/skills/web-app-verification in your project. Codex loads it when a task matches its description.

Can I use Web App Verification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Porabuild/Poracode --skill web-app-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web-app-verification, .gemini/skills/web-app-verification, .github/skills/web-app-verification and .opencode/skills/web-app-verification in your project.

What does Web App Verification need to run?

SKILL.md names no scripts, command-line tools or credentials: Web App Verification is instructions for the agent only.

Does Web App Verification access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Web App Verification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Web App Verification use?

Web App Verification is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Web App Verification use?

About 465 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Web App Verification?

Skills that share tags, products or a category with Web App Verification: Scaffold Exercises (vinvcn/mattpocock-skills-zh-CN, 4.7k stars), Performing Soc Tabletop Exercise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Ransomware Tabletop Exercise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Performing Purple Team Exercise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Web App Verification?

Porabuild (a GitHub organization) maintains it in Porabuild/Poracode, which has 114 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 8, 2026.

Source: Porabuild/Poracode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.