Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Qa

CSecurity

Use after code changes, before releases, or when testing features - runs the right level of QA based on what changed

13 stars
0 votes
0 copies
0 views
Added 10/4/2026
testinggobashdockertestingdatabase

Works with

cli

Security Analysis

C67/100
criticalPipes output to a shell interpreter
mediumUses curl or wget to download content
criticalDownloads and executes remote scripts — classic supply chain attack
mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned 10/4/2026

$npx -y skills add karloscodes/fusionaly-oss --skill qa --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Qa?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Qa
[![Security: C — Skills Directory](https://www.skillsdirectory.com/api/skills/karloscodes-fusionaly-oss/badge)](https://www.skillsdirectory.com/skills/karloscodes-fusionaly-oss)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: qa
description: Use after code changes, before releases, or when testing features - runs the right level of QA based on what changed
---

# QA Testing

## What did you change? Start here.

| Change | Test level | Command |
|--------|-----------|---------|
| Bug fix, refactor, small feature | **Unit** | `make test` |
| Feature, UI, big change | **Unit + E2E** | `make test` then `make test-e2e` |
| Visual / UI verification | **Agent-browser** | `make dev` + agent-browser |
| Install script, matcha, infra | **VM install** | multipass VM |
| Release | **All of the above** | See release checklist |

---

## Level 1: Unit Tests (~3 seconds)

```bash
make test
```

Run after every change. No excuses.

---

## Level 2: E2E Tests (~5 minutes)

```bash
# CRITICAL: Kill any running dev server first — E2E uses its own database
lsof -ti :3000 | xargs kill -9 2>/dev/null
make test-e2e
```

Playwright tests that run onboarding, create websites, check dashboards, ingest events. Run after features or big changes.

---

## Level 3: Visual QA with agent-browser

For verifying UI rendering, checking that data displays correctly, or testing flows that E2E doesn't cover.

### Setup (one-time)
```bash
npm i -g agent-browser
agent-browser install
```

### Start dev server
```bash
make dev    # MUST use make dev (Go + Vite together)
```

### Dev credentials
- Email: `admin@example.com`
- Password: `password`
- Created by `make db-seed`

### Login
```bash
agent-browser open "http://localhost:3000/login"
agent-browser snapshot -i
agent-browser fill @e1 "admin@example.com"
agent-browser fill @e3 "password"
agent-browser click @e4
```

### Navigate and verify
```bash
agent-browser snapshot -i           # list interactive elements with refs
agent-browser click @e11            # click element by ref
agent-browser scroll down 1000      # scroll to find sections
agent-browser screenshot            # capture page as PNG
agent-browser get url               # check current URL
```

### Generate real browser events
```bash
# The /_demo page includes the tracking script — fires real pageviews
agent-browser open "http://localhost:3000/_demo"

# Wait for event processing (~10s), then check dashboard
```

### Key pages to verify

| Page | How to reach | What to check |
|------|-------------|---------------|
| Admin home | `/admin` | Website list loads |
| Dashboard | Click arrow (→) on a website | Charts, stats, time range |
| Browsers tab | Scroll to Device Analytics, click "Browsers" | Browser names (Brave, Edge, etc.) |
| Settings | Click "Settings" in nav | Forms save, flash messages |
| Events | Click "Events" tab on dashboard | Event list, sessions view |

### Important
- **Always `make dev`** — `make watch-go` alone won't render Inertia pages
- **Click through the UI** — don't force navigation with `open` after login (breaks Inertia state)
- **`/_demo` for real events** — sends actual `Sec-CH-UA` headers from the browser
- Dev database: `storage/fusionaly-development.db`

---

## Level 4: VM Install Test

Only needed when changing: install script, matcha, Docker setup, or release infrastructure.

### Create fresh VM
```bash
multipass delete fusionaly-test --purge 2>/dev/null || true
multipass launch 24.04 --name fusionaly-test --cpus 2 --memory 2G --disk 10G
```

### Run install
```bash
multipass exec fusionaly-test -- bash -c '
sudo apt-get update -qq && sudo apt-get install -y -qq expect

cat > /tmp/run_install.exp << '\''EXPECTSCRIPT'\''
#!/usr/bin/expect -f
set timeout 300
spawn sudo bash -c "curl -fsSL https://fusionaly.com/install | bash"
expect "Enter your domain name"
send "test.local\r"
expect "Proceed with this configuration"
send "Y\r"
expect eof
EXPECTSCRIPT

expect /tmp/run_install.exp
'
```

### Verify
```bash
multipass exec fusionaly-test -- bash -c '
echo "=== Containers ===" && sudo docker ps
echo "=== Version ===" && fusionaly version
echo "=== Health ===" && curl -s http://172.18.0.2:8080/_health
'
```

### Browser test via tunnel
```bash
VM_IP=$(multipass info fusionaly-test | grep IPv4 | awk '{print $2}')
ssh -L 8080:172.18.0.2:8080 ubuntu@$VM_IP
# Open http://localhost:8080/setup
```

### Cleanup
```bash
multipass delete fusionaly-test --purge
```

---

## Release Checklist

Before tagging a release:

- [ ] `make test` passes
- [ ] `make test-e2e` passes (kill dev server first!)
- [ ] Visual QA: dashboard loads, browser stats correct, events ingesting
- [ ] VM install test (if install/infra changed)
- [ ] Pro: update OSS submodule, build, test

---

## Common Issues

| Issue | Cause | Fix |
|-------|-------|-----|
| E2E fails "Setup already complete" | Dev server running (wrong DB) | `lsof -ti :3000 \| xargs kill -9` |
| agent-browser login doesn't work | Vite not running | Use `make dev`, not `make watch-go` |
| Dashboard shows JSON error | Navigated directly after forced POST | Start fresh browser, click through UI |
| `/_demo` events not appearing | Processing job hasn't run yet | Wait ~10 seconds, check `ingested_events` table |
| VM can't reach app | Docker internal network | Use SSH tunnel to 172.18.0.2:8080 |

Attribution

karloscodeskarloscodes
View sourceSee grades on GitHubMore from karloscodes →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Screen Reader Testing

Practical guide to testing web applications with screen readers for comprehensive accessibility validation.

401991 votes

Tdd Workflow

在编写新功能、修复错误或重构代码时使用此技能。强制执行测试驱动开发,包含单元测试、集成测试和端到端测试,覆盖率超过80%。

2456590 votes

Eval Harness

克劳德代码会话的正式评估框架,实施评估驱动开发(EDD)原则

2456590 votes

Python Testing

使用pytest、TDD方法、夹具、模拟、参数化和覆盖率要求的Python测试策略。

2456590 votes

Django Tdd

Django测试策略,包括pytest-django、TDD方法论、factory_boy、模拟、覆盖率以及测试Django REST Framework API。

2456590 votes
View all in testing →