Skip to main content

test-red-team

Stars7
Forks0
UpdatedJuly 29, 2026 at 01:34

Adversarial red-team of a running web, React Native, or Capacitor hybrid app. Drives a visible (headed) browser by hand โ€” playwright-cli (web/PWA), Android WebView attach (Capacitor), or adb tap-walk (native) โ€” never scripted test files. Attacks every feature across 4 dimensions: UI/UX, data pipeline, security (OWASP-mapped), and performance. Cross-references Sentry telemetry, Supabase DB-layer mutation truth and RLS, and current OWASP/MASVS guidance. Produces a severity-ranked defect list with repro steps and evidence. Generic across any repo and stack. Use when asked to "red team this app", "attack my app", "break it", "find all the defects", "adversarial test", "pre-launch hardening", "pentest the app", or "full app QA". Distinct from test-playwright (session PDCA), test-qa (happy-path crawl), and audit-security (static code review).

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
2 files
SKILL.md
readonly