跳到主要内容
知仓学习社ZHICANG

vc-web-testing

Web testing with Playwright, Vitest, k6. E2E/unit/integration/load/security/visual/a11y testing. Use for test automation, flakiness, Core Web Vitals…

读凭据读文件写文件执行命令联网严重 1 · 高危 6withkynam/vibecode-pro-max-kit

它会碰到什么

扫了多少27 个文本文件,75 KB
它会碰到什么读凭据读文件写文件执行命令联网
命中总数23 处
命中统计严重 1 · 高 6 · 中 12 · 低 0
逐条看命中(7 条严重或高危)
  • 严重 scripts/init-playwright.js:206cred-paths
    writeFile('.env.test.example', envExample);
  • scripts/init-playwright.js:28cred-envread
    workers: process.env.CI ? 1 : undefined,
  • scripts/init-playwright.js:34cred-envread
    baseURL: process.env.BASE_URL || 'http://localhost:3000',
  • scripts/init-playwright.js:49cred-envread
    reuseExistingServer: !process.env.CI,
  • scripts/init-playwright.js:66cred-envread
    email: process.env.TEST_USER_EMAIL || 'test@example.com',
  • scripts/init-playwright.js:67cred-envread
    password: process.env.TEST_USER_PASSWORD || 'password',
  • scripts/init-playwright.js:160cred-envread
    workers: process.env.CI ? 1 : undefined,

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Web Testing Skill

> Output style: Follow process/development-protocols/communication-standards.md — answer-first, plain language, no unexplained jargon, TL;DR on long responses.

Comprehensive web testing: unit, integration, E2E, load, security, visual regression, accessibility.

Quick Start

npx vitest run                    # Unit tests
npx playwright test               # E2E tests
npx playwright test --ui          # E2E with UI
k6 run load-test.js               # Load tests
npx @axe-core/cli https://example.com  # Accessibility
npx lighthouse https://example.com     # Performance

Testing Strategy (Choose Your Model)

| Model | Structure | Best For |

|-------|-----------|----------|

| Pyramid | Unit 70% > Integration 20% > E2E 10% | Monoliths |

| Trophy | Integration-heavy | Modern SPAs |

| Honeycomb | Contract-centric | Microservices |

./references/testing-pyramid-strategy.md

Reference Documentation

Core Testing

  • ./references/unit-integration-testing.md - Vitest, browser mode, AAA
  • ./references/e2e-testing-playwright.md - Fixtures, sharding, selectors
  • ./references/playwright-component-testing.md - CT patterns (production-ready)
  • ./references/component-testing.md - React/Vue/Angular patterns

Test Infrastructure

  • ./references/test-data-management.md - Factories, fixtures, seeding
  • ./references/database-testing.md - Testcontainers, transactions
  • ./references/ci-cd-testing-workflows.md - GitHub Actions, sharding
  • ./references/contract-testing.md - Pact, MSW patterns

Cross-Browser & Mobile

  • ./references/cross-browser-checklist.md - Browser/device matrix
  • ./references/mobile-gesture-testing.md - Touch, swipe, orientation

Performance & Quality

  • ./references/performance-core-web-vitals.md - LCP/CLS/INP, Lighthouse CI
  • ./references/visual-regression.md - Screenshot comparison
  • ./references/test-flakiness-mitigation.md - Stability strategies

Accessibility & Security

  • ./references/accessibility-testing.md - WCAG, axe-core
  • ./references/security-testing-overview.md - OWASP Top 10
  • ./references/security-checklists.md - Auth, API, headers

API & Load

  • ./references/api-testing.md - Supertest, GraphQL
  • ./references/load-testing-k6.md - k6 patterns

Checklists

  • ./references/pre-release-checklist.md - Complete release checklist
  • ./references/functional-testing-checklist.md - Feature testing

Scripts

Initialize Playwright Project

node ./scripts/init-playwright.js [--ct] [--dir <path>]

Creates best-practice Playwright setup: config, fixtures, example tests.

Analyze Test Results

node ./scripts/analyze-test-results.js \
  --playwright test-results/results.json \
  --vitest coverage/vitest.json \
  --output markdown

Parses Playwright/Vitest/JUnit results into unified summary.

CI/CD Integration

jobs:
  test:
    steps:
      - run: pnpm run test:unit      # Gate 1: Fast fail
      - run: pnpm run test:e2e       # Gate 2: After unit pass
      - run: pnpm run test:a11y      # Accessibility
      - run: npx lhci autorun       # Performance

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。