- Updated
- Version
- v1.1
- Sources
- 1 source
- Status
- Published
webapp-testing
Web app testing
Anthropic
Verifies a local browser journey and produces reproducible evidence without deploying the application.
- License
- Apache-2.0
- Risk
- Risk level: high
Risk profile
This is a risk profile, not a certification or a safety guarantee.
What can it read?
Present
- It can read what the local app shows in the browser, including the page structure.
What can it create or change?
Present
- It can create test scripts, save screenshots, and change the local test app while it runs.
Can it use the internet or send data?
Not evaluated
- The published fields do not say whether this skill can use the internet or send data.
Can it use saved logins or a paid quota?
Not evaluated
- The published fields do not say whether this skill can use saved logins or a paid quota.
Which action needs your approval?
Not evaluated
- The published fields do not say which actions need your approval first.
When was the source verified, and has the snapshot changed since?
Present
- The source was last verified on 2026-07-19. The published snapshot still matches that verification. This is not a live check of the upstream source.
- Canonical source
- https://github.com/anthropics/skills/blob/fa0fa64bdc967915dc8399e803be67759e1e62b8/skills/webapp-testing/SKILL.md(opens in a new tab)
- Source revision
- fa0fa64bdc967915dc8399e803be67759e1e62b8
- License
- Apache-2.0
- Verification date
- 2026-07-19
- Source status
- Verified
- Change status
- Snapshot consistent
- The published snapshot still matches the last verification. This is not a live check of the upstream source.
Understand
Covered goals
- test a local web application
- verify UI behavior
- capture reproducible browser evidence
Inputs → outputs
- local application URL or static HTML file
- user journey and expected behavior
- server command and port when the application is not already running
- native Python Playwright automation script
- observed UI behavior, screenshots, rendered DOM evidence, or browser console logs
Recognize
Verbatim from the English source
Triggers
- test this web app
- validate a UI flow
- reproduce a browser issue
Non-triggers
- deploy an application
- test a remote production mutation without authorization
- replace unit tests with screenshots
Choose
Verbatim from the English source
Permissions
- write and execute scoped Python Playwright scripts
- launch a local browser and read rendered application state
- start and stop explicitly scoped local application servers
- interact with and potentially mutate local test application state
External effects
- local browser and optional application-server processes are started and stopped
- Python scripts, screenshots, DOM captures, and logs can be written to disk
- browser actions can mutate the local application's test state
Compatibility
- local web applications in a Python environment with Playwright and Chromium
Required tools
- Python
- Playwright synchronous API and Chromium
- optional scripts/with_server.py helper for local server lifecycle
Check permissions and confirm every external effect before using this skill.
Compare
Understand → Recognize → Choose → Compare
Pack for your agent
Pre-written instruction by SkillCodex — your request is neither sent nor used to adapt this text; no content is generated, and copying executes nothing.
Use in your agent
Complete the task with Web app testing
# Use Web app testing in your agent ## Objective Use the existing webapp-testing skill only when it directly covers the requested task. ## Prerequisites - local application URL or static HTML file - user journey and expected behavior - server command and port when the application is not already running - Python - Playwright synchronous API and Chromium - optional scripts/with_server.py helper for local server lifecycle ## Permissions - write and execute scoped Python Playwright scripts - launch a local browser and read rendered application state - start and stop explicitly scoped local application servers - interact with and potentially mutate local test application state ## External effects - local browser and optional application-server processes are started and stopped - Python scripts, screenshots, DOM captures, and logs can be written to disk - browser actions can mutate the local application's test state ## Procedure - Open the canonical source pinned to revision fa0fa64bdc967915dc8399e803be67759e1e62b8. - Read the skill instructions before calling its tools. - Ask for confirmation before any paid, destructive, or remote effect not already authorized. - Run the procedure within the requested scope and retain useful evidence. ## When not to use - deploy an application - test a remote production mutation without authorization - replace unit tests with screenshots ## Expected result - native Python Playwright automation script - observed UI behavior, screenshots, rendered DOM evidence, or browser console logs ## Guardrails - Show the proposed changes before any external action. - Do not publish, send, delete, pay for, or change remote state without explicit authorization. - Preserve unrelated changes and stop if the scope becomes ambiguous. ## Output format - Outcome or verdict. - Files or actions involved. - Checks run and observable evidence. - Remaining blockers or limitations.
- Requires · Python
- Requires · Playwright synchronous API and Chromium
- Requires · optional scripts/with_server.py helper for local server lifecycle
Why it works
- Activation is limited to tasks the skill actually covers.
- Permissions, tools, and external effects are visible before execution.
- Confirmation and the output format keep actions controllable.
Try next
Check the Web app testing result
# Verify the Web app testing outcome ## Objective Check that the webapp-testing skill was used within scope and that its effects match the authorized request. ## Checks - Compare the source and revision with the manifest. - Separate local, browser, and external evidence. - Report any permission or effect that was not disclosed. ## Guardrails - Show the proposed changes before any external action. - Do not publish, send, delete, pay for, or change remote state without explicit authorization. - Preserve unrelated changes and stop if the scope becomes ambiguous. ## Output format - Outcome or verdict. - Files or actions involved. - Checks run and observable evidence. - Remaining blockers or limitations.
sha256:f701ccd98bf70fde21cd1638e5feb07fa563e85bef3479eb9a2f83fe518ff2c9
Verify in your agent
Confirm that Web app testing produced the right outcome
# Verify Web app testing in your agent ## Result to check Verify the use of webapp-testing for the current bounded task. ## Failure signals - The source or revision does not match the manifest. - A permission or external effect was not disclosed. - The output does not match the expected artifacts. - The skill activated for a declared non-trigger. ## Checks - Compare the SHA-256 of SKILL.md with sha256:51b7349e77ec63b7744a6f63647e7566a0b4d2e301121cc10e8c2113af6556a2. - Confirm the permissions actually used and the observed effects. - Verify artifacts with the narrowest available test. - Separate local, browser, and external evidence in the report. ## Expected result - native Python Playwright automation script - observed UI behavior, screenshots, rendered DOM evidence, or browser console logs ## Guardrails - Show the proposed changes before any external action. - Do not publish, send, delete, pay for, or change remote state without explicit authorization. - Preserve unrelated changes and stop if the scope becomes ambiguous. ## Output format - Outcome or verdict. - Files or actions involved. - Checks run and observable evidence. - Remaining blockers or limitations.
- Requires · Python
- Requires · Playwright synchronous API and Chromium
- Requires · optional scripts/with_server.py helper for local server lifecycle
Why it works
- The check starts from the manifest and expected artifacts, not a general impression.
- Observed permissions and effects are compared with what was disclosed.
- Local, browser, and external evidence stay separate in the verdict.
Try next
Prepare the next Web app testing check
# Make the Web app testing check reusable ## Objective Turn the successful checks into a bounded checklist for the next use of webapp-testing. ## Checks - Keep only observable signals. - Tie each permission to its expected effect. - Add an explicit stop if the source or revision changes. ## Guardrails - Show the proposed changes before any external action. - Do not publish, send, delete, pay for, or change remote state without explicit authorization. - Preserve unrelated changes and stop if the scope becomes ambiguous. ## Output format - Outcome or verdict. - Files or actions involved. - Checks run and observable evidence. - Remaining blockers or limitations.
sha256:95ff794874deb1f7a4190401e975ae8a5d83903b3332000f72138593890f0567
Pack digest: sha256:01522b4d0fe743448d5cb39f34f2aa3ac42b20ea88074df012ba71c09b56ce2b
Source provenance
Open the canonical source (opens in a new tab)- Source revision
- fa0fa64bdc967915dc8399e803be67759e1e62b8
- Digest
- sha256:51b7349e77ec63b7744a6f63647e7566a0b4d2e301121cc10e8c2113af6556a2