qa-specialized-testing
当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试(负载/压力/稳定性)、安全测试(OWASP Top 10 TOP 漏洞)、兼容性测试(多浏览器/多设备)的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确,再评估性能和安全。专项测试的产出是一组可复用的测试方案(性能指标基线、安全渗透用例、兼容性矩阵)。 触发场景:性能测试、安全测试(专项)、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security testing, and cross-browser compatibility. Skill: qa-specialized-testing Owner: kokxi Summary: 当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试(负载/压力/稳定性)、安全测试(OWASP Top 10 TOP 漏洞)、兼容性测试(多浏览器/多设备)的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确,再评估性能和安全。专项测试的产出是一组可复用的测试方案(性能指标基线、安全渗透用例、兼容性矩阵)。 触发场景:性能测试、安全测试(专项)、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security test
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
1.8.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.8.0release · observed Sep 29, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s170jw3s1atcj5jwhqb4r7v7eh8912kp:qa-specialized-testing- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/snapshot"
Documentation
CLAWHUB
78,362 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: qa-specialized-testing
description: >-
当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试(负载/压力/稳定性)、安全测试(OWASP Top 10 TOP 漏洞)、兼容性测试(多浏览器/多设备)的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确,再评估性能和安全。专项测试的产出是一组可复用的测试方案(性能指标基线、安全渗透用例、兼容性矩阵)。 触发场景:性能测试、安全测试(专项)、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security testing, and cross-browser compatibility.
license: MIT
allowed-tools: Read Grep Glob Bash
metadata:
display-name: "Specialized Testing"
version: "1.8.0"
when-to-use: "用户说\"性能测试\"、\"安全测试(专项)\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入测试\"、\"跨浏览器测试\"、需要进行专项测试、功能测试完成后需要补充专项测试时"
related-skills: "{\"upstream\":[\"qa-risk-intuition\",\"qa-test-strategy-design\"],\"downstream\":[\"qa-release-risk-governance\",\"qa-agent-testing\",\"qa-mobile-testing\"]}"
references: "[\"references/performance-depth.md\"]"
input-format: "{\"required\":[{\"name\":\"测试策略\",\"type\":\"object\",\"description\":\"来自qa-test-strategy-design的测试策略\"},{\"name\":\"专项需求\",\"type\":\"string\",\"description\":\"性能/安全/兼容性等专项测试需求\"}],\"optional\":[{\"name\":\"环境信息\",\"type\":\"string\",\"description\":\"专项测试环境配置\"}]}"
output-format: "{\"traceability\":[\"每个专项测试用例带唯一ID(TC_{模块缩写}_{功能缩写}_{序号},如 TC_API_LOGIN_001)\",\"关联专项类型和需求ID\"],\"structure\":[\"覆盖率:标注口径(基于现有需求/输入文档),禁止\\\"全覆盖/100%\\\"绝对化表述;缺失模块标注\\\"未覆盖+原因\\\"\",{\"specialized_test_plan\":\"专项测试方案\"},{\"performance_cases\":\"性能测试场景\"},{\"security_cases\":\"安全测试用例\"},{\"compatibility_matrix\":\"兼容性矩阵\"}]}"
error-recovery-guidance: "{\"on_failure\":\"专项测试遗漏维度时回退到测试策略补充范围\",\"retry_behavior\":\"补全范围后重新执行专项测试\"}"
categories: "[\"Development\",\"Testing\"]"
depth-requirement: "{\"reference_value\":\"根据专项类型调整测试深度:简单×1/中等×2/复杂×3\",\"minimum\":\"至少完成性能、安全、兼容性3类专项中的2类\"}"
---
> ⚠️ 本技能单独使用效果有限,建议配合完整技能集(12 步工作流)使用。安装:npx skills add Kokxi/qa-test-skills
# 专项测试能力
## 核心原则
专项测试不只是会用工具,而是知道测什么、怎么测、测到什么程度算够。
## 深度要求(参考值)
**关键指标**:根据系统复杂度调整专项测试深度
| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |
|--------|------------|------------|------|
| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |
| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |
| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |
**适用范围**:本技能仅在你明确要求某个专项测试方向(如性能/安全/兼容性)且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用,不得在未获授权的系统上执行。
## 加载时机
| 什么时候读 | 读哪个 |
|-----------|--------|
| 做性能测试专项时 | [`references/performance-depth.md`](references/performance-depth.md) |
> `维度1:性能测试`的完整内容已下沉至 `references/performance-depth.md`,避免每次触发都占用上下文。
## 维度2:安全测试
> ⚠️ **授权与法律声明**:安全测试(尤其是渗透测试)必须获得系统所有者的明确书面授权。
> 执行前必须确认:
> 1. 测试目标属于你或已获得明确授权
> 2. 清楚界定测试范围、目标环境和边界(严禁超出授权范围)
> 3. 了解并遵守当地网络安全相关法律法规
> 4. 测试活动不会对业务系统造成影响(建议使用独立测试环境)
> 5. 使用攻击性工具(Burp Suite/SQLMap 等)仅限于你拥有或明确获授权的系统
### 安全测试类型
```text
├─ OWASP Top 10
│ ├─ 注入攻击(Injection)
│ ├─ 失效的身份认证(Broken Authentication)
│ ├─ 敏感数据暴露(Sensitive Data Exposure)
│ ├─ XML外部实体(XXE)
│ ├─ 失效的访问控制(Broken Access Control)
│ ├─ 安全配置错误(Security Misconfiguration)
│ ├─ 跨站脚本(XSS)
│ ├─ 不安_meta.json
{
"ownerId": "kn71y9b23csfx0ykgm55d5m9x5891zt8",
"slug": "qa-specialized-testing",
"version": "1.8.0",
"publishedAt": 1790656105679
}references/performance-depth.md
# 性能测试维度详解
> 本文是 `qa-specialized-testing` 的**性能测试维度详解**。做性能测试专项时读本文;
其余部分留在 SKILL.md,不必读本文。
---
### 性能测试类型
```text
├─ 负载测试(Load Testing)
│ ├─ 目标:验证系统在预期负载下的表现
│ ├─ 方法:逐步增加并发,观察性能指标
│ └─ 指标:响应时间、吞吐量、错误率
│
├─ 压力测试(Stress Testing)
│ ├─ 目标:验证系统在极限负载下的表现
│ ├─ 方法:持续增加并发直到系统崩溃
│ └─ 指标:系统极限、崩溃点、恢复能力
│
├─ 稳定性测试(Soak Testing)
│ ├─ 目标:验证系统长时间运行的稳定性
│ ├─ 方法:持续运行24-72小时
│ └─ 指标:内存泄漏、资源消耗、性能退化
│
└─ 尖峰测试(Spike Testing)
├─ 目标:验证系统应对突发流量的能力
├─ 方法:突然增加并发
└─ 指标:系统响应、恢复时间、数据一致性
```
### 性能指标
```text
核心指标:
├─ 响应时间(Response Time)
│ ├─ P50:50%请求的响应时间
│ ├─ P95:95%请求的响应时间
│ ├─ P99:99%请求的响应时间
│ └─ 目标:P99 < 1秒
│
├─ 吞吐量(Throughput)
│ ├─ TPS:每秒事务数
│ ├─ QPS:每秒查询数
│ └─ 目标:根据业务定义
│
├─ 错误率(Error Rate)
│ ├─ 计算:错误请求数 / 总请求数
│ └─ 目标:< 0.1%
│
└─ 资源使用率
├─ CPU使用率:< 80%
├─ 内存使用率:< 80%
├─ 磁盘IO:< 80%
└─ 网络IO:< 80%
```
### 性能测试工具
```text
├─ JMeter
│ ├─ 优点:功能全面、插件丰富
│ ├─ 缺点:界面复杂、资源消耗大
│ └─ 适用:复杂场景、协议测试
│
├─ Locust
│ ├─ 优点:代码化、分布式
│ ├─ 缺点:需要编程能力
│ └─ 适用:API测试、分布式测试
│
├─ k6
│ ├─ 优点:现代化、CI友好
│ ├─ 缺点:社区较小
│ └─ 适用:现代应用、DevOps
│
└─ wrk
├─ 优点:轻量、高效
├─ 缺点:功能简单
└─ 适用:简单压测、快速验证
```skill-card.md
## Description: Guides developers through performance, authorized security, and cross-browser compatibility testing after functional testing is complete. This skill is ready for commercial/non-commercial use. ## Publisher: [kokxi](https://clawhub.ai/user/kokxi) ### License/Terms of Use: MIT-0 ## Use Case: Developers and QA engineers use this skill to plan and assess performance, authorized security, and browser/device compatibility tests after functional testing, with traceable cases and coverage boundaries. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Security testing can affect systems outside the intended scope. Mitigation: Require explicit authorization and a defined target, environment, and scope before testing. Risk: The optional installation command retrieves a third-party skill collection. Mitigation: Run it only if you trust the source; it is not required to use this guidance. ## Reference(s): - [ClawHub skill release](https://clawhub.ai/kokxi/skills/qa-specialized-testing) - [Performance testing reference](references/performance-depth.md) ## Skill Output: **Output Type(s):** [Text, Guidance] **Output Format:** [Markdown test plans, cases, and matrices] **Output Parameters:** [1D] **Other Properties Related to Output:** [Traceable test case IDs, performance baselines, security cases, compatibility matrices, and explicit coverage gaps.] ## Skill Version(s): 1.8.0 (source: skill frontmatter and server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/kokxi/skills/qa-specialized-testing",
"sourceUrl": "https://clawhub.ai/kokxi/skills/qa-specialized-testing",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T01:49:04.825Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T01:49:04.825Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/kokxi/qa-specialized-testing",
"sourceUrl": "https://clawhub.ai/kokxi/qa-specialized-testing",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T01:49:04.825Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.8.0",
"href": "https://clawhub.ai/kokxi/qa-specialized-testing",
"sourceUrl": "https://clawhub.ai/kokxi/qa-specialized-testing",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-29T04:28:25.679Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.8.0",
"description": "- Performance testing content is now moved to a separate reference file (`references/performance-depth.md`) for modular loading and reduced context size. - SKILL.md restructured with metadata blocks and improved field organization for clarity and machine-readability. - Removed legacy summary file (`skill-card.md`) and updated documentation to match new loading strategy. - All functional principles, coverage criteria, and checklists remain intact; only performance test methodology is relocated to an external reference for on-demand access.",
"href": "https://clawhub.ai/kokxi/qa-specialized-testing",
"sourceUrl": "https://clawhub.ai/kokxi/qa-specialized-testing",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-29T04:28:25.679Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
