Agent skill

Whole-App Health Sweep

by reticlehq in reticlehq/reticle

Sweeps a running web app by clicking every reachable control, then reports dead buttons, console errors, failed requests and mismatches between API data and the screen.

Apache-2.0Auto-check passedTesting & QA

Install Whole-App Health Sweep

skills CLI
$ npx skills add reticlehq/reticle --skill audit-my-app -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install reticlehq/reticle audit-my-app --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/reticlehq/reticle.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-my-app .claude/skills/audit-my-app && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-my-app
GitHub stars
1.2k
Token cost
~1.1k tokens
SKILL.md length
423 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Sweeps a running web app by clicking every reachable control, then reports dead buttons, console errors, failed requests and mismatches between API data and the screen.

  • Works in 5 steps: Ask the app what it can do → Click everything → Compare what the API said against what… → …
  • Smoke testing an unfamiliar codebase without writing a script
  • SKILL.md covers 1. Ask the app what it can do, 2. Click everything, 3. Compare what the API said… and 4. Find the parts nobody…, plus 1 more section
  • Calls curl and npx; reaches docs.reticle.sh

What it does

The skill uses Reticle to check an app without needing to understand its code. It first asks the app to describe its own testable surface (test ids, domain signals, stores and saved flows), then runs a crawl that clicks everything reachable, bounded by a step limit that defaults to 25. Two counts signal real problems: dead controls, meaning buttons wired to nothing, and contradictions, where a channel disagrees with what the screen showed. Console errors and failed requests are worth reading but a busy app produces them innocently.

Because the crawl clicks everything, it should point at a development environment, and a separate explore call gives a non-destructive pass over what is reachable. A reconcile step compares what the API returned with what rendered, such as ten rows from the API but nine in the table, which neither the network log nor the DOM shows alone. Coverage and domain calls list the parts nobody exercised and whether saved flows actually assert anything. The skill warns against hand-rolling the sweep, since a dead button throws no error.

When your agent uses it

  • Smoke testing an unfamiliar codebase without writing a script
  • Checking an app after a large merge or dependency bump
  • Running a pre-release health check on a web app
  • Finding screens whose displayed data does not match the API response

Example prompts

  • “Smoke test the app running on localhost:3000 and tell me what is broken.”
  • “We just bumped dependencies, so sweep every screen for dead buttons and console errors.”
  • “Compare what the orders API returned with what the table shows.”
  • “Which parts of the app has no saved flow ever exercised?”

Requirements

  • A running web app in a development environment
  • Reticle installed in the project through npx

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Ask the app what it can do
  2. Click everything
  3. Compare what the API said against what rendered
  4. Find the parts nobody exercised
  5. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 178e5c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • docs.reticle.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Whole-App Health Sweep loads about 1.1k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 423 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from reticlehq/reticle at commit 178e5c0, republished under its Apache-2.0 licence (© reticlehq). 423 words, ~1,072 tokens.

Download SKILL.mdSave it as .claude/skills/audit-my-app/SKILL.md (or your agent's skills folder).
name
audit-my-app
description
Sweep a whole running web app for what is broken, without writing a script or knowing the codebase. Clicks every reachable control and reports dead buttons, console errors, failed requests, and places where the API and the screen disagree. Use on an unfamiliar codebase, before a release, after a big merge or dependency bump, when the user asks for a smoke test or a health check, or when someone says "just check everything still works".
license
Apache-2.0
metadata.version
3.7.0
metadata.homepage
https://www.reticle.sh
metadata.repository
https://github.com/reticlehq/reticle

Sweep the whole app and report what is broken

You do not need to understand the codebase to check it. Reticle drives every reachable control in the running app and reports the anomalies. Not installed? RETICLE_INSTALL_SOURCE=npx_skill npx @reticlehq/server@latest init, then the install-and-verify skill.

1. Ask the app what it can do

reticle_run({ tool: "reticle_capabilities", args: { sessionId } })

About 1 KB, and it is the app describing its own testable surface: every registered testid, every domain signal, the stores, and the saved flows with their steps. That beats snapshotting the DOM and inferring intent from element names, and it is the cheapest orientation available.

2. Click everything

reticle_run({ tool: "reticle_verify", sessionId, args: { action: "crawl", maxSteps: 25 } })
json
{
  "interactiveFound": 3,
  "stepsRun": 3,
  "anomalies": [],
  "counts": { "consoleErrors": 0, "failedRequests": 0, "deadControls": 0, "contradictions": 0 },
  "visited": ["- textbox \"Email\"", "- button \"Sign in\""],
  "truncated": false
}

deadControls and contradictions are the two counts that mean a real problem. Console errors and failed requests are worth reading but a busy app produces both innocently. A dead control is a button wired to nothing; a contradiction is a channel disagreeing with what the screen showed.

It clicks everything, so point it at a dev environment. maxSteps bounds it and defaults to 25. Want a non-destructive pass first: what is reachable, without touching it? reticle_run({ tool: "reticle_explore", sessionId }).

Do not hand-roll this sweep. The obvious version (click each control, assert no console error) passes on exactly the bug you are sweeping for, because a dead button throws nothing.

3. Compare what the API said against what rendered

reticle_run({ tool: "reticle_reconcile", sessionId })

The API returned ten rows, the table shows nine, nothing errored. Neither the network log nor the DOM is wrong on its own. Only the comparison catches it, and nothing else you can run makes that comparison.

Show full SKILL.md (168 more words)Show less

4. Find the parts nobody exercised

reticle_run({ tool: "reticle_verify", sessionId, args: { action: "coverage" } })   // { total, exercised, untouched }

And if the project already has saved flows, ask whether they prove anything:

reticle_run({ tool: "reticle_domain", sessionId })
// → { flowCount, coverage: { asserted, presenceOnly, assertionFree }, gaps: { declaredUntestedSignals, … } }

A suite of forty flows where thirty-one assert nothing is a suite that will stay green through any regression. That number is usually the most alarming thing in the whole audit, and nothing else reports it.

5. Report

Lead with the counts, then one line per real finding with its file:line from reticle_look { action: "element" }. Separate:

  • Broken: dead controls, contradictions, failed requests, errors thrown during the sweep.
  • Unverified: untouched controls and assertionFree flows. Not known to be broken; known to be unchecked.
  • Pre-existing: console errors that were already there before the sweep started. Say so, so nobody attributes them to today's change.

Do not report a clean audit over a partial one. If truncated is true or maxSteps cut the sweep short, say what was not reached. A silent cap reads as "everything is fine" when it means "I stopped".


Full capability reference: curl https://docs.reticle.sh/capabilities.md. Everything else: curl https://docs.reticle.sh/llms.txt.

© reticlehq, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/audit-my-app of reticlehq/reticle.

Open the folder on GitHubat commit 178e5c0

Compare with similar skills

Whole-App Health Sweep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Whole-App Health Sweep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Whole-App Health Sweep this skillreticlehq/reticle1.2k—~1.1kAutomated safety check: PassApache-2.0
Diff-Driven Smoke TestsSkyvern-AI/skyvern23k—~5.2kAutomated safety check: PassAGPL-3.0
LangBot Testinglangbot-app/LangBot18k—~1kAutomated safety check: NotesApache-2.0
Agentic Browser Testingpetrkindlmann/qa-skills170—~4.5kAutomated safety check: PassMIT
Testing QAaiskillstore/marketplace4333 repos~1.2kAutomated safety check: PassNone
Playwright E2E Testsonyx-dot-app/onyx32k1 repos~2.8kAutomated safety check: NotesCustom licence

Similar skills

  • Diff-Driven Smoke Tests

    Skyvern-AI/skyvern

    Reads your git diff, writes a handful of happy-path browser smoke tests, runs them with Skyvern or Chrome DevTools MCP and posts screenshot evidence to the PR.

    23k GitHub stars~5.2k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • LangBot Testing

    langbot-app/LangBot

    Tests LangBot's WebUI and core flows through an automated browser and backend logs, with a routing table to reference guides per feature area.

    18k GitHub stars~1k tokensUpdated today
    Testing & QAAuto-check: notes
  • Agentic Browser Testing

    petrkindlmann/qa-skills

    Goal-driven E2E testing where a browser agent (Playwright MCP / computer-use) reads a natural-language goal and explores the app via the accessibility tree to assert outcomes — no pre-written script.

    170 GitHub stars~4.5k tokensUpdated 4 mo ago
    Testing & QAAuto-check passed
  • Testing QA

    aiskillstore/marketplace

    Comprehensive testing and QA workflow covering unit testing, integration testing, E2E testing, browser automation, and quality assurance.

    433 GitHub starsUsed in 3 repos~1.2k tokens
    Testing & QAAuto-check passed
  • Playwright E2E Tests

    onyx-dot-app/onyx

    Write and maintain Playwright end-to-end tests for the Onyx application.

    32k GitHub starsUsed in 1 repo~2.8k tokens
    Testing & QAAuto-check: notes
  • Hands On Test

    ktnyt/cclsp

    Performs manual hands-on testing of a web application using playwright-cli.

    675 GitHub stars~1.7k tokensUpdated 7 mo ago
    Testing & QAAuto-check passed

More from reticlehq/reticle

All 19 skills in this repo
  • Agentic TDD

    reticlehq/reticle

    Applies red-green TDD to behavior unit tests cannot reach, by stating the expected outcome against the running app with Reticle before writing the feature.

    1.2k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Broken UI Debugger

    reticlehq/reticle

    Finds why a running web app misbehaves when the console is empty and the code looks fine, by reading the click, request, store and console together.

    1.2k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Drives and verifies Electron or Tauri desktop apps through Reticle, which sees the renderer and the IPC calls that a browser-based testing tool cannot observe.

    1.2k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Finds out why a passing test suite sits on top of a broken app by comparing what the running app does with what the tests claim, using Reticle.

    1.2k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Fix What I Pointed At

    reticlehq/reticle

    Picks up bugs a person flagged by pointing at elements in the running app, each mark carrying the element, their note and the source file and line, then fixes and verifies them.

    1.2k GitHub stars~878 tokensUpdated yesterday
    Auto-check passed
  • Reticle Flow Replay

    reticlehq/reticle

    Saves a user journey driven through the app as a deterministic regression check that replays with no model and no test code, using Reticle.

    1.2k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Whole-App Health Sweep

What does Whole-App Health Sweep do?

Sweeps a running web app by clicking every reachable control, then reports dead buttons, console errors, failed requests and mismatches between API data and the screen. The skill uses Reticle to check an app without needing to understand its code. It first asks the app to describe its own testable surface (test ids, domain signals, stores and saved flows), then runs a crawl that clicks everything reachable, bounded by a step limit that defaults to 25.

When should I use Whole-App Health Sweep?

Whole-App Health Sweep fits situations like: smoke testing an unfamiliar codebase without writing a script; checking an app after a large merge or dependency bump; running a pre-release health check on a web app; finding screens whose displayed data does not match the API response.

How do I install Whole-App Health Sweep in Claude Code?

Run `npx skills add reticlehq/reticle --skill audit-my-app -a claude-code`. Or copy the skill folder (skills/audit-my-app in reticlehq/reticle) into .claude/skills/audit-my-app in your project. Claude Code loads it when a task matches its description.

How do I install Whole-App Health Sweep in Codex?

Run `npx skills add reticlehq/reticle --skill audit-my-app -a codex`. Or copy the skill folder (skills/audit-my-app in reticlehq/reticle) into .agents/skills/audit-my-app in your project. Codex loads it when a task matches its description.

Can I use Whole-App Health Sweep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add reticlehq/reticle --skill audit-my-app -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-my-app, .gemini/skills/audit-my-app, .github/skills/audit-my-app and .opencode/skills/audit-my-app in your project.

What does Whole-App Health Sweep need to run?

Going by SKILL.md and its folder, Whole-App Health Sweep needs the command-line tools its instructions call (curl and npx). Our summary lists: A running web app in a development environment; Reticle installed in the project through npx.

Does Whole-App Health Sweep access the network?

SKILL.md names 1 domain. In commands or code: docs.reticle.sh; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Whole-App Health Sweep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Whole-App Health Sweep use?

Whole-App Health Sweep is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Whole-App Health Sweep use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Whole-App Health Sweep?

Skills that share tags, products or a category with Whole-App Health Sweep: Diff-Driven Smoke Tests (Skyvern-AI/skyvern, 23k stars), LangBot Testing (langbot-app/LangBot, 18k stars), Agentic Browser Testing (petrkindlmann/qa-skills, 170 stars) and Testing QA (aiskillstore/marketplace, 433 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Whole-App Health Sweep?

reticlehq (a GitHub organization) maintains it in reticlehq/reticle, which has 1,199 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: reticlehq/reticle on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.