{"id":"6e03b8eb-2aa4-490f-b78d-c8670db85790","entityType":"agent","slug":"clawhub-kokxi-qa-specialized-testing","name":"qa-specialized-testing","canonicalUrl":"https://www.xpersona.co/agent/clawhub-kokxi-qa-specialized-testing","canonicalPath":"/agent/clawhub-kokxi-qa-specialized-testing","generatedAt":"2026-10-11T03:54:30.721Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T01:49:04.825Z","emptyReason":null},"description":"当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。 触发场景：性能测试、安全测试（专项）、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security testing, and cross-browser compatibility. Skill: qa-specialized-testing Owner: kokxi Summary: 当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。 触发场景：性能测试、安全测试（专项）、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security test","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s170jw3s1atcj5jwhqb4r7v7eh8912kp:qa-specialized-testing","sourceUrl":"https://clawhub.ai/kokxi/qa-specialized-testing","homepage":"https://clawhub.ai/kokxi/skills/qa-specialized-testing","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/kokxi/qa-specialized-testing","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/kokxi/skills/qa-specialized-testing","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T01:49:04.825Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T01:49:04.825Z","emptyReason":null},"stars":null,"forks":null,"downloads":1200,"packageName":null,"latestVersion":"1.8.0","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T01:49:04.811Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T01:49:04.825Z","lastCrawledAt":"2026-10-11T01:49:04.811Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T01:49:04.811Z","lastVerifiedAt":null,"highlights":[{"version":"1.8.0","createdAt":"2026-09-29T04:28:25.679Z","changelog":"- Performance testing content is now moved to a separate reference file (`references/performance-depth.md`) for modular loading and reduced context size. - SKILL.md restructured with metadata blocks and improved field organization for clarity and machine-readability. - Removed legacy summary file (`skill-card.md`) and updated documentation to match new loading strategy. - All functional principles, coverage criteria, and checklists remain intact; only performance test methodology is relocated to an external reference for on-demand access.","fileCount":4,"zipByteSize":6467},{"version":"1.7.7","createdAt":"2026-09-27T14:40:50.214Z","changelog":"1.7.7","fileCount":3,"zipByteSize":5791},{"version":"1.7.6","createdAt":"2026-09-01T12:45:40.581Z","changelog":"显示名改中文","fileCount":3,"zipByteSize":6144},{"version":"1.7.5","createdAt":"2026-08-30T15:18:47.010Z","changelog":"1.7.5: 版本号升级","fileCount":3,"zipByteSize":5862},{"version":"1.7.0","createdAt":"2026-08-16T14:32:41.722Z","changelog":"- Removed the deprecated file: skill-card.md. - Updated SKILL.md version to 1.7.0. - No changes to logic, content, or structure of the skill itself. - Documentation now only includes SKILL.md.","fileCount":3,"zipByteSize":5635},{"version":"1.6.3","createdAt":"2026-08-12T15:27:45.195Z","changelog":"- Added `slug` and `displayName` fields to metadata for improved identification and display. - Updated version to 1.6.3. - Removed the file `skill-card.md`. - No changes made to core guidelines, input/output formats, or testing methodologies. - Documentation structure and skill usage guidance remain consistent.","fileCount":3,"zipByteSize":5527},{"version":"1.6.0","createdAt":"2026-07-06T17:17:29.462Z","changelog":"- Expanded downstream related skills to include qa-agent-testing and qa-mobile-testing. - Enhanced input and output formats: added traceability (test case IDs) and more structured output requirements. - Added categories and explicit error recovery guidance for missed coverage. - Updated when_to_use triggers for more precise and wider matching. - Removed skill-card.md as part of file cleanup and documentation update.","fileCount":3,"zipByteSize":5538},{"version":"1.5.0","createdAt":"2026-06-29T12:35:26.430Z","changelog":"- Refined the skill's activation conditions: specialization is now triggered only after functional testing is completed. - Introduced a new structure for input/output formats, including required fields and structured output sections (test plan, test cases, compatibility matrix). - Added a recommendations table guiding minimum testing depth based on system complexity. - Simplified and clarified descriptions on when and how to use the skill. - Removed skill-card.md and updated structural documentation (in SKILL.md).","fileCount":3,"zipByteSize":5326}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s170jw3s1atcj5jwhqb4r7v7eh8912kp:qa-specialized-testing","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T03:54:30.719Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kokxi-qa-specialized-testing/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T01:49:04.825Z","emptyReason":null},"readme":"Skill: qa-specialized-testing\n\nOwner: kokxi\n\nSummary: 当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。 触发场景：性能测试、安全测试（专项）、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security testing, and cross-browser compatibility.\n\nTags: latest:1.8.0\n\nVersion history:\n\nv1.8.0 | 2026-09-29T04:28:25.679Z | auto\n\n- Performance testing content is now moved to a separate reference file (`references/performance-depth.md`) for modular loading and reduced context size.\n- SKILL.md restructured with metadata blocks and improved field organization for clarity and machine-readability.\n- Removed legacy summary file (`skill-card.md`) and updated documentation to match new loading strategy.\n- All functional principles, coverage criteria, and checklists remain intact; only performance test methodology is relocated to an external reference for on-demand access.\n\nv1.7.7 | 2026-09-27T14:40:50.214Z | user\n\n1.7.7\n\nv1.7.6 | 2026-09-01T12:45:40.581Z | user\n\n显示名改中文\n\nv1.7.5 | 2026-08-30T15:18:47.010Z | user\n\n1.7.5: 版本号升级\n\nv1.7.0 | 2026-08-16T14:32:41.722Z | auto\n\n- Removed the deprecated file: skill-card.md.\n- Updated SKILL.md version to 1.7.0.\n- No changes to logic, content, or structure of the skill itself.\n- Documentation now only includes SKILL.md.\n\nv1.6.3 | 2026-08-12T15:27:45.195Z | auto\n\n- Added `slug` and `displayName` fields to metadata for improved identification and display.\n- Updated version to 1.6.3.\n- Removed the file `skill-card.md`.\n- No changes made to core guidelines, input/output formats, or testing methodologies.\n- Documentation structure and skill usage guidance remain consistent.\n\nv1.6.0 | 2026-07-06T17:17:29.462Z | auto\n\n- Expanded downstream related skills to include qa-agent-testing and qa-mobile-testing.\n- Enhanced input and output formats: added traceability (test case IDs) and more structured output requirements.\n- Added categories and explicit error recovery guidance for missed coverage.\n- Updated when_to_use triggers for more precise and wider matching.\n- Removed skill-card.md as part of file cleanup and documentation update.\n\nv1.5.0 | 2026-06-29T12:35:26.430Z | auto\n\n- Refined the skill's activation conditions: specialization is now triggered only after functional testing is completed.\n- Introduced a new structure for input/output formats, including required fields and structured output sections (test plan, test cases, compatibility matrix).\n- Added a recommendations table guiding minimum testing depth based on system complexity.\n- Simplified and clarified descriptions on when and how to use the skill.\n- Removed skill-card.md and updated structural documentation (in SKILL.md).\n\nv1.4.1 | 2026-06-25T16:56:36.070Z | auto\n\n- skill-card.md 文件已移除，文档结构更简洁。\n- SKILL.md 大幅精简描述，聚焦激活条件与覆盖领域。\n- 新增对安全测试的授权与法律声明，明确只能在授权范围内操作。\n- 保留三大专项测试方法、工具和检查清单，但去除了部分辅助性说明。\n- 明确适用场景与限制，提升安全合规性。\n\nv1.4.0 | 2026-06-24T05:12:13.563Z | auto\n\n- Expanded skill description with more detailed triggers and keywords, improving clarity on when to use the skill.\n- Enhanced overview section, emphasizing the core principles of specialized testing.\n- Added clear example scenarios and guidelines to clarify practical use cases.\n- Updated and streamlined content in SKILL.md for better readability; removed redundant explanations.\n- skill-card.md file removed for simplification.\n\nv1.3.0 | 2026-06-23T00:35:16.515Z | auto\n\n- 新增详细的专项测试指南，涵盖性能、安全、兼容性三个维度\n- 增补各类专项测试方法、核心指标、常用工具示例\n- 明确输入输出格式与激活场景\n- 提供专项测试、验收流程及检查清单，提升可操作性\n- 丰富相关技能联动描述，便于上下游衔接\n\nArchive index:\n\nArchive v1.8.0: 4 files, 6467 bytes\n\nFiles: references/performance-depth.md (2395b), skill-card.md (1775b), SKILL.md (8794b), _meta.json (141b)\n\nFile v1.8.0:SKILL.md\n\n---\nname: qa-specialized-testing\ndescription: >-\n  当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。 触发场景：性能测试、安全测试（专项）、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security testing, and cross-browser compatibility.\nlicense: MIT\nallowed-tools: Read Grep Glob Bash\nmetadata:\n  display-name: \"Specialized Testing\"\n  version: \"1.8.0\"\n  when-to-use: \"用户说\\\"性能测试\\\"、\\\"安全测试（专项）\\\"、\\\"兼容性测试\\\"、\\\"专项测试\\\"、\\\"压力测试\\\"、\\\"渗透测试\\\"、\\\"SQL注入测试\\\"、\\\"跨浏览器测试\\\"、需要进行专项测试、功能测试完成后需要补充专项测试时\"\n  related-skills: \"{\\\"upstream\\\":[\\\"qa-risk-intuition\\\",\\\"qa-test-strategy-design\\\"],\\\"downstream\\\":[\\\"qa-release-risk-governance\\\",\\\"qa-agent-testing\\\",\\\"qa-mobile-testing\\\"]}\"\n  references: \"[\\\"references/performance-depth.md\\\"]\"\n  input-format: \"{\\\"required\\\":[{\\\"name\\\":\\\"测试策略\\\",\\\"type\\\":\\\"object\\\",\\\"description\\\":\\\"来自qa-test-strategy-design的测试策略\\\"},{\\\"name\\\":\\\"专项需求\\\",\\\"type\\\":\\\"string\\\",\\\"description\\\":\\\"性能/安全/兼容性等专项测试需求\\\"}],\\\"optional\\\":[{\\\"name\\\":\\\"环境信息\\\",\\\"type\\\":\\\"string\\\",\\\"description\\\":\\\"专项测试环境配置\\\"}]}\"\n  output-format: \"{\\\"traceability\\\":[\\\"每个专项测试用例带唯一ID（TC_{模块缩写}_{功能缩写}_{序号}，如 TC_API_LOGIN_001）\\\",\\\"关联专项类型和需求ID\\\"],\\\"structure\\\":[\\\"覆盖率：标注口径（基于现有需求/输入文档），禁止\\\\\\\"全覆盖/100%\\\\\\\"绝对化表述；缺失模块标注\\\\\\\"未覆盖+原因\\\\\\\"\\\",{\\\"specialized_test_plan\\\":\\\"专项测试方案\\\"},{\\\"performance_cases\\\":\\\"性能测试场景\\\"},{\\\"security_cases\\\":\\\"安全测试用例\\\"},{\\\"compatibility_matrix\\\":\\\"兼容性矩阵\\\"}]}\"\n  error-recovery-guidance: \"{\\\"on_failure\\\":\\\"专项测试遗漏维度时回退到测试策略补充范围\\\",\\\"retry_behavior\\\":\\\"补全范围后重新执行专项测试\\\"}\"\n  categories: \"[\\\"Development\\\",\\\"Testing\\\"]\"\n  depth-requirement: \"{\\\"reference_value\\\":\\\"根据专项类型调整测试深度：简单×1/中等×2/复杂×3\\\",\\\"minimum\\\":\\\"至少完成性能、安全、兼容性3类专项中的2类\\\"}\"\n---\n> ⚠️ 本技能单独使用效果有限，建议配合完整技能集（12 步工作流）使用。安装：npx skills add Kokxi/qa-test-skills\n\n# 专项测试能力\n\n## 核心原则\n\n专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\n\n## 深度要求（参考值）\n\n**关键指标**：根据系统复杂度调整专项测试深度\n\n| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |\n|--------|------------|------------|------|\n| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |\n| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |\n| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |\n\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\n\n## 加载时机\n\n| 什么时候读 | 读哪个 |\n|-----------|--------|\n| 做性能测试专项时 | [`references/performance-depth.md`](references/performance-depth.md) |\n\n> `维度1：性能测试`的完整内容已下沉至 `references/performance-depth.md`，避免每次触发都占用上下文。\n\n## 维度2：安全测试\n\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\n> 执行前必须确认：\n> 1. 测试目标属于你或已获得明确授权\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\n> 3. 了解并遵守当地网络安全相关法律法规\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\n\n### 安全测试类型\n\n```text\n├─ OWASP Top 10\n│   ├─ 注入攻击（Injection）\n│   ├─ 失效的身份认证（Broken Authentication）\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\n│   ├─ XML外部实体（XXE）\n│   ├─ 失效的访问控制（Broken Access Control）\n│   ├─ 安全配置错误（Security Misconfiguration）\n│   ├─ 跨站脚本（XSS）\n│   ├─ 不安全的反序列化（Insecure Deserialization）\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\n│   └─ 不足的日志和监控（Insufficient Logging）\n│\n├─ 渗透测试\n│   ├─ 信息收集：域名、IP、端口\n│   ├─ 漏洞扫描：自动化扫描\n│   ├─ 漏洞利用：手动验证\n│   └─ 报告输出：漏洞报告\n│\n└─ 代码审计\n    ├─ 静态分析：代码扫描\n    ├─ 动态分析：运行时检测\n    └─ 人工审计：代码Review\n```\n\n### 安全测试工具\n\n```text\n├─ Burp Suite\n│   ├─ 用途：Web应用渗透测试\n│   ├─ 功能：代理、扫描、爬虫、爆破\n│   └─ 适用：Web安全测试\n│\n├─ OWASP ZAP\n│   ├─ 用途：Web应用安全扫描\n│   ├─ 功能：自动扫描、手动测试\n│   └─ 适用：自动化安全测试\n│\n├─ SQLMap\n│   ├─ 用途：SQL注入测试\n│   ├─ 功能：自动检测、利用SQL注入\n│   └─ 适用：SQL注入测试\n│\n└─ Nmap\n    ├─ 用途：网络扫描\n    ├─ 功能：端口扫描、服务识别\n    └─ 适用：信息收集\n```\n\n## 维度3：兼容性测试\n\n### 兼容性测试维度\n\n```text\n├─ 浏览器兼容\n│   ├─ Chrome\n│   ├─ Firefox\n│   ├─ Safari\n│   ├─ Edge\n│   └─ IE（如需要）\n│\n├─ 设备兼容\n│   ├─ PC\n│   ├─ 手机（iOS/Android）\n│   ├─ 平板\n│   └─ 不同分辨率\n│\n├─ 系统兼容\n│   ├─ Windows\n│   ├─ macOS\n│   ├─ Linux\n│   └─ 不同版本\n│\n└─ 网络兼容\n    ├─ WiFi\n    ├─ 4G/5G\n    ├─ 弱网\n    └─ 离线\n```\n\n### 兼容性测试工具\n\n```text\n├─ 浏览器测试\n│   ├─ BrowserStack：云端真机测试\n│   ├─ Sauce Labs：云端测试平台\n│   ├─ LambdaTest：跨浏览器测试\n│   └─ Can I Use：兼容性查询\n│\n├─ 移动端测试\n│   ├─ Appium：移动端自动化\n│   ├─ XCTest/Espresso：原生测试\n│   └─ 真机测试：实际设备测试\n│\n└─ 响应式测试\n    ├─ Chrome DevTools：设备模拟\n    ├─ Responsinator：响应式检查\n    └─ Am I Responsive：响应式检查\n```\n\n## 专项测试检查清单\n\n### 性能测试检查\n- [ ] 测试场景设计？\n- [ ] 性能指标定义？\n- [ ] 测试工具选择？\n- [ ] 测试环境准备？\n- [ ] 监控工具配置？\n- [ ] 结果分析报告？\n\n### 安全测试检查\n- [ ] 测试范围确定？\n- [ ] 测试工具准备？\n- [ ] OWASP Top 10覆盖？\n- [ ] 渗透测试执行？\n- [ ] 漏洞报告输出？\n- [ ] 修复验证完成？\n\n### 兼容性测试检查\n- [ ] 浏览器范围确定？\n- [ ] 设备范围确定？\n- [ ] 测试矩阵设计？\n- [ ] 测试工具选择？\n- [ ] 测试执行完成？\n- [ ] 问题报告输出？\n\n## 输出示例\n\n**用户说\"测一下这个接口的性能\"**\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\n\n**用户说\"做个安全测试\"**\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\n\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\n\n## 检查清单\n\n专项测试完成后检查：\n- [ ] 测试类型是否明确？\n- [ ] 测试工具是否选择？\n- [ ] 测试环境是否准备？\n- [ ] 测试执行是否完成？\n- [ ] 结果分析是否深入？\n- [ ] 报告输出是否规范？\n\nFile v1.8.0:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.8.0\",\n  \"publishedAt\": 1790656105679\n}\n\nFile v1.8.0:references/performance-depth.md\n\n# 性能测试维度详解\n\n> 本文是 `qa-specialized-testing` 的**性能测试维度详解**。做性能测试专项时读本文；\n其余部分留在 SKILL.md，不必读本文。\n\n---\n\n\n### 性能测试类型\n\n```text\n├─ 负载测试（Load Testing）\n│   ├─ 目标：验证系统在预期负载下的表现\n│   ├─ 方法：逐步增加并发，观察性能指标\n│   └─ 指标：响应时间、吞吐量、错误率\n│\n├─ 压力测试（Stress Testing）\n│   ├─ 目标：验证系统在极限负载下的表现\n│   ├─ 方法：持续增加并发直到系统崩溃\n│   └─ 指标：系统极限、崩溃点、恢复能力\n│\n├─ 稳定性测试（Soak Testing）\n│   ├─ 目标：验证系统长时间运行的稳定性\n│   ├─ 方法：持续运行24-72小时\n│   └─ 指标：内存泄漏、资源消耗、性能退化\n│\n└─ 尖峰测试（Spike Testing）\n    ├─ 目标：验证系统应对突发流量的能力\n    ├─ 方法：突然增加并发\n    └─ 指标：系统响应、恢复时间、数据一致性\n```\n\n### 性能指标\n\n```text\n核心指标：\n├─ 响应时间（Response Time）\n│   ├─ P50：50%请求的响应时间\n│   ├─ P95：95%请求的响应时间\n│   ├─ P99：99%请求的响应时间\n│   └─ 目标：P99 < 1秒\n│\n├─ 吞吐量（Throughput）\n│   ├─ TPS：每秒事务数\n│   ├─ QPS：每秒查询数\n│   └─ 目标：根据业务定义\n│\n├─ 错误率（Error Rate）\n│   ├─ 计算：错误请求数 / 总请求数\n│   └─ 目标：< 0.1%\n│\n└─ 资源使用率\n    ├─ CPU使用率：< 80%\n    ├─ 内存使用率：< 80%\n    ├─ 磁盘IO：< 80%\n    └─ 网络IO：< 80%\n```\n\n### 性能测试工具\n\n```text\n├─ JMeter\n│   ├─ 优点：功能全面、插件丰富\n│   ├─ 缺点：界面复杂、资源消耗大\n│   └─ 适用：复杂场景、协议测试\n│\n├─ Locust\n│   ├─ 优点：代码化、分布式\n│   ├─ 缺点：需要编程能力\n│   └─ 适用：API测试、分布式测试\n│\n├─ k6\n│   ├─ 优点：现代化、CI友好\n│   ├─ 缺点：社区较小\n│   └─ 适用：现代应用、DevOps\n│\n└─ wrk\n    ├─ 优点：轻量、高效\n    ├─ 缺点：功能简单\n    └─ 适用：简单压测、快速验证\n```\n\nFile v1.8.0:skill-card.md\n\n## Description:\n\nGuides developers through performance, authorized security, and cross-browser compatibility testing after functional testing is complete.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[kokxi](https://clawhub.ai/user/kokxi)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and QA engineers use this skill to plan and assess performance, authorized security, and browser/device compatibility tests after functional testing, with traceable cases and coverage boundaries.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Security testing can affect systems outside the intended scope.\n\nMitigation: Require explicit authorization and a defined target, environment, and scope before testing.\n\nRisk: The optional installation command retrieves a third-party skill collection.\n\nMitigation: Run it only if you trust the source; it is not required to use this guidance.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/kokxi/skills/qa-specialized-testing)\n- [Performance testing reference](references/performance-depth.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Guidance]\n\n**Output Format:** [Markdown test plans, cases, and matrices]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Traceable test case IDs, performance baselines, security cases, compatibility matrices, and explicit coverage gaps.]\n\n## Skill Version(s):\n\n1.8.0 (source: skill frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.7.7: 3 files, 5791 bytes\n\nFiles: skill-card.md (1767b), SKILL.md (10493b), _meta.json (141b)\n\nFile v1.7.7:SKILL.md\n\n---\nname: qa-specialized-testing\nslug: qa-specialized-testing\ndisplayName: Specialized Testing\nversion: 1.7.7\ndescription: >-\n  当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。\n\nwhen_to_use: 用户说\"性能测试\"、\"安全测试（专项）\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入测试\"、\"跨浏览器测试\"、需要进行专项测试、功能测试完成后需要补充专项测试时\nallowed-tools: Read Grep Glob Bash\nrelated_skills:\n  upstream:\n    - qa-risk-intuition          # 输入：风险评估识别专项测试需求\n    - qa-test-strategy-design    # 输入：测试策略确定专项测试范围\n  downstream:\n    - qa-release-risk-governance # 输出：专项测试结果用于发布评估\n    - qa-agent-testing\n    - qa-mobile-testing\ninput_format:\n  required:\n    - name: 测试策略\n      type: object\n      description: 来自qa-test-strategy-design的测试策略\n    - name: 专项需求\n      type: string\n      description: 性能/安全/兼容性等专项测试需求\n  optional:\n    - name: 环境信息\n      type: string\n      description: 专项测试环境配置\noutput_format:\n  traceability:\n    - 每个专项测试用例带唯一ID（TC_{模块缩写}_{功能缩写}_{序号}，如 TC_API_LOGIN_001）\n    - 关联专项类型和需求ID\n  structure:\n    - 测试用例表格：固定 9 列（用例编号|测试类型|功能模块|测试标题|用例级别|预置条件|测试步骤|预期结果|风险等级）\n    - 用例级别：P0≤20%（核心流程）/ P1≤40%（主要功能）/ P2≤30%（次要功能）/ P3≤10%（边缘场景）\n    - 覆盖率：标注口径（基于现有需求/输入文档），禁止\"全覆盖/100%\"绝对化表述；缺失模块标注\"未覆盖+原因\"\n    - specialized_test_plan: 专项测试方案\n    - performance_cases: 性能测试场景\n    - security_cases: 安全测试用例\n    - compatibility_matrix: 兼容性矩阵\ncategories: ['Development','Testing']\ndepth_requirement_quantification:\n  reference_value: \"根据专项类型调整测试深度：简单×1/中等×2/复杂×3\"\n  minimum: \"至少完成性能、安全、兼容性3类专项中的2类\"\nerror_recovery_guidance:\n  on_failure: \"专项测试遗漏维度时回退到测试策略补充范围\"\n  retry_behavior: \"补全范围后重新执行专项测试\"\n---\n# 专项测试能力\n\n## 核心原则\n\n专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\n\n## 深度要求（参考值）\n\n**关键指标**：根据系统复杂度调整专项测试深度\n\n| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |\n|--------|------------|------------|------|\n| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |\n| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |\n| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |\n\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\n\n## 维度1：性能测试\n\n### 性能测试类型\n\n```text\n├─ 负载测试（Load Testing）\n│   ├─ 目标：验证系统在预期负载下的表现\n│   ├─ 方法：逐步增加并发，观察性能指标\n│   └─ 指标：响应时间、吞吐量、错误率\n│\n├─ 压力测试（Stress Testing）\n│   ├─ 目标：验证系统在极限负载下的表现\n│   ├─ 方法：持续增加并发直到系统崩溃\n│   └─ 指标：系统极限、崩溃点、恢复能力\n│\n├─ 稳定性测试（Soak Testing）\n│   ├─ 目标：验证系统长时间运行的稳定性\n│   ├─ 方法：持续运行24-72小时\n│   └─ 指标：内存泄漏、资源消耗、性能退化\n│\n└─ 尖峰测试（Spike Testing）\n    ├─ 目标：验证系统应对突发流量的能力\n    ├─ 方法：突然增加并发\n    └─ 指标：系统响应、恢复时间、数据一致性\n```\n\n### 性能指标\n\n```text\n核心指标：\n├─ 响应时间（Response Time）\n│   ├─ P50：50%请求的响应时间\n│   ├─ P95：95%请求的响应时间\n│   ├─ P99：99%请求的响应时间\n│   └─ 目标：P99 < 1秒\n│\n├─ 吞吐量（Throughput）\n│   ├─ TPS：每秒事务数\n│   ├─ QPS：每秒查询数\n│   └─ 目标：根据业务定义\n│\n├─ 错误率（Error Rate）\n│   ├─ 计算：错误请求数 / 总请求数\n│   └─ 目标：< 0.1%\n│\n└─ 资源使用率\n    ├─ CPU使用率：< 80%\n    ├─ 内存使用率：< 80%\n    ├─ 磁盘IO：< 80%\n    └─ 网络IO：< 80%\n```\n\n### 性能测试工具\n\n```text\n├─ JMeter\n│   ├─ 优点：功能全面、插件丰富\n│   ├─ 缺点：界面复杂、资源消耗大\n│   └─ 适用：复杂场景、协议测试\n│\n├─ Locust\n│   ├─ 优点：代码化、分布式\n│   ├─ 缺点：需要编程能力\n│   └─ 适用：API测试、分布式测试\n│\n├─ k6\n│   ├─ 优点：现代化、CI友好\n│   ├─ 缺点：社区较小\n│   └─ 适用：现代应用、DevOps\n│\n└─ wrk\n    ├─ 优点：轻量、高效\n    ├─ 缺点：功能简单\n    └─ 适用：简单压测、快速验证\n```\n\n## 维度2：安全测试\n\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\n> 执行前必须确认：\n> 1. 测试目标属于你或已获得明确授权\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\n> 3. 了解并遵守当地网络安全相关法律法规\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\n\n### 安全测试类型\n\n```text\n├─ OWASP Top 10\n│   ├─ 注入攻击（Injection）\n│   ├─ 失效的身份认证（Broken Authentication）\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\n│   ├─ XML外部实体（XXE）\n│   ├─ 失效的访问控制（Broken Access Control）\n│   ├─ 安全配置错误（Security Misconfiguration）\n│   ├─ 跨站脚本（XSS）\n│   ├─ 不安全的反序列化（Insecure Deserialization）\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\n│   └─ 不足的日志和监控（Insufficient Logging）\n│\n├─ 渗透测试\n│   ├─ 信息收集：域名、IP、端口\n│   ├─ 漏洞扫描：自动化扫描\n│   ├─ 漏洞利用：手动验证\n│   └─ 报告输出：漏洞报告\n│\n└─ 代码审计\n    ├─ 静态分析：代码扫描\n    ├─ 动态分析：运行时检测\n    └─ 人工审计：代码Review\n```\n\n### 安全测试工具\n\n```text\n├─ Burp Suite\n│   ├─ 用途：Web应用渗透测试\n│   ├─ 功能：代理、扫描、爬虫、爆破\n│   └─ 适用：Web安全测试\n│\n├─ OWASP ZAP\n│   ├─ 用途：Web应用安全扫描\n│   ├─ 功能：自动扫描、手动测试\n│   └─ 适用：自动化安全测试\n│\n├─ SQLMap\n│   ├─ 用途：SQL注入测试\n│   ├─ 功能：自动检测、利用SQL注入\n│   └─ 适用：SQL注入测试\n│\n└─ Nmap\n    ├─ 用途：网络扫描\n    ├─ 功能：端口扫描、服务识别\n    └─ 适用：信息收集\n```\n\n## 维度3：兼容性测试\n\n### 兼容性测试维度\n\n```text\n├─ 浏览器兼容\n│   ├─ Chrome\n│   ├─ Firefox\n│   ├─ Safari\n│   ├─ Edge\n│   └─ IE（如需要）\n│\n├─ 设备兼容\n│   ├─ PC\n│   ├─ 手机（iOS/Android）\n│   ├─ 平板\n│   └─ 不同分辨率\n│\n├─ 系统兼容\n│   ├─ Windows\n│   ├─ macOS\n│   ├─ Linux\n│   └─ 不同版本\n│\n└─ 网络兼容\n    ├─ WiFi\n    ├─ 4G/5G\n    ├─ 弱网\n    └─ 离线\n```\n\n### 兼容性测试工具\n\n```text\n├─ 浏览器测试\n│   ├─ BrowserStack：云端真机测试\n│   ├─ Sauce Labs：云端测试平台\n│   ├─ LambdaTest：跨浏览器测试\n│   └─ Can I Use：兼容性查询\n│\n├─ 移动端测试\n│   ├─ Appium：移动端自动化\n│   ├─ XCTest/Espresso：原生测试\n│   └─ 真机测试：实际设备测试\n│\n└─ 响应式测试\n    ├─ Chrome DevTools：设备模拟\n    ├─ Responsinator：响应式检查\n    └─ Am I Responsive：响应式检查\n```\n\n## 专项测试检查清单\n\n### 性能测试检查\n- [ ] 测试场景设计？\n- [ ] 性能指标定义？\n- [ ] 测试工具选择？\n- [ ] 测试环境准备？\n- [ ] 监控工具配置？\n- [ ] 结果分析报告？\n\n### 安全测试检查\n- [ ] 测试范围确定？\n- [ ] 测试工具准备？\n- [ ] OWASP Top 10覆盖？\n- [ ] 渗透测试执行？\n- [ ] 漏洞报告输出？\n- [ ] 修复验证完成？\n\n### 兼容性测试检查\n- [ ] 浏览器范围确定？\n- [ ] 设备范围确定？\n- [ ] 测试矩阵设计？\n- [ ] 测试工具选择？\n- [ ] 测试执行完成？\n- [ ] 问题报告输出？\n\n## 输出示例\n\n**用户说\"测一下这个接口的性能\"**\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\n\n**用户说\"做个安全测试\"**\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\n\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\n\n## 检查清单\n\n专项测试完成后检查：\n- [ ] 测试类型是否明确？\n- [ ] 测试工具是否选择？\n- [ ] 测试环境是否准备？\n- [ ] 测试执行是否完成？\n- [ ] 结果分析是否深入？\n- [ ] 报告输出是否规范？\n\nFile v1.7.7:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.7.7\",\n  \"publishedAt\": 1790520050214\n}\n\nFile v1.7.7:skill-card.md\n\n## Description:\n\nProvides reusable plans and test cases for performance, security, and cross-browser or device compatibility testing after functional testing is complete.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[kokxi](https://clawhub.ai/user/kokxi)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nQA engineers and developers use this skill to plan targeted performance, authorized security, and compatibility testing after functional testing, producing test cases, performance baselines, and compatibility matrices.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Security testing guidance could be applied to systems without authorization.\n\nMitigation: Confirm written authorization and the target scope before any security testing; do not scan systems without explicit permission.\n\nRisk: Stress or load testing could disrupt live services.\n\nMitigation: Use a dedicated test environment and confirm permission before running load or stress tests.\n\n## Reference(s):\n\n- [QA Specialized Testing on ClawHub](https://clawhub.ai/kokxi/skills/qa-specialized-testing)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, Guidance]\n\n**Output Format:** [Markdown test plans, test-case tables, and compatibility matrices]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Test cases include IDs, priorities, expected outcomes, and risk levels.]\n\n## Skill Version(s):\n\n1.7.7 (source: release metadata and skill frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.7.6: 3 files, 6144 bytes\n\nFiles: skill-card.md (2059b), SKILL.md (11083b), _meta.json (141b)\n\nFile v1.7.6:SKILL.md\n\n---\r\nname: qa-specialized-testing\r\nslug: qa-specialized-testing\r\ndisplayName: 专项测试\r\nversion: 1.7.5\r\ndescription: >-\r\n  当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。\r\n  本技能属于 QA Test Skills 技能集（49 个技能之一），完整工作流体验需安装全套：npx skills add Kokxi/qa-test-skills\r\n\r\nwhen_to_use: 用户说\"性能测试\"、\"安全测试（专项）\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入测试\"、\"跨浏览器测试\"、需要进行专项测试、功能测试完成后需要补充专项测试时\r\nallowed-tools: Read Grep Glob Bash\r\nrelated_skills:\r\n  upstream:\r\n    - qa-risk-intuition          # 输入：风险评估识别专项测试需求\r\n    - qa-test-strategy-design    # 输入：测试策略确定专项测试范围\r\n  downstream:\r\n    - qa-release-risk-governance # 输出：专项测试结果用于发布评估\r\n    - qa-agent-testing\r\n    - qa-mobile-testing\r\ninput_format:\r\n  required:\r\n    - name: 测试策略\r\n      type: object\r\n      description: 来自qa-test-strategy-design的测试策略\r\n    - name: 专项需求\r\n      type: string\r\n      description: 性能/安全/兼容性等专项测试需求\r\n  optional:\r\n    - name: 环境信息\r\n      type: string\r\n      description: 专项测试环境配置\r\noutput_format:\r\n  traceability:\r\n    - 每个专项测试用例带唯一ID（TC_{模块缩写}_{功能缩写}_{序号}，如 TC_API_LOGIN_001）\r\n    - 关联专项类型和需求ID\r\n  structure:\r\n    - 测试用例表格：固定 9 列（用例编号|测试类型|功能模块|测试标题|用例级别|预置条件|测试步骤|预期结果|风险等级）\r\n    - 用例级别：P0≤20%（核心流程）/ P1≤40%（主要功能）/ P2≤30%（次要功能）/ P3≤10%（边缘场景）\r\n    - 覆盖率：标注口径（基于现有需求/输入文档），禁止\"全覆盖/100%\"绝对化表述；缺失模块标注\"未覆盖+原因\"\r\n    - specialized_test_plan: 专项测试方案\r\n    - performance_cases: 性能测试场景\r\n    - security_cases: 安全测试用例\r\n    - compatibility_matrix: 兼容性矩阵\r\ncategories: ['Development','Testing']\r\ndepth_requirement_quantification:\r\n  reference_value: \"根据专项类型调整测试深度：简单×1/中等×2/复杂×3\"\r\n  minimum: \"至少完成性能、安全、兼容性3类专项中的2类\"\r\nerror_recovery_guidance:\r\n  on_failure: \"专项测试遗漏维度时回退到测试策略补充范围\"\r\n  retry_behavior: \"补全范围后重新执行专项测试\"\r\n---\r\n> ⚠️ 本技能单独使用效果有限，建议配合完整技能集（12 步工作流）使用。安装：npx skills add Kokxi/qa-test-skills\r\n\r\n# 专项测试能力\r\n\r\n## 核心原则\r\n\r\n专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\r\n\r\n## 深度要求（参考值）\r\n\r\n**关键指标**：根据系统复杂度调整专项测试深度\r\n\r\n| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |\r\n|--------|------------|------------|------|\r\n| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |\r\n| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |\r\n| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |\r\n\r\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\r\n\r\n## 维度1：性能测试\r\n\r\n### 性能测试类型\r\n\r\n```text\r\n├─ 负载测试（Load Testing）\r\n│   ├─ 目标：验证系统在预期负载下的表现\r\n│   ├─ 方法：逐步增加并发，观察性能指标\r\n│   └─ 指标：响应时间、吞吐量、错误率\r\n│\r\n├─ 压力测试（Stress Testing）\r\n│   ├─ 目标：验证系统在极限负载下的表现\r\n│   ├─ 方法：持续增加并发直到系统崩溃\r\n│   └─ 指标：系统极限、崩溃点、恢复能力\r\n│\r\n├─ 稳定性测试（Soak Testing）\r\n│   ├─ 目标：验证系统长时间运行的稳定性\r\n│   ├─ 方法：持续运行24-72小时\r\n│   └─ 指标：内存泄漏、资源消耗、性能退化\r\n│\r\n└─ 尖峰测试（Spike Testing）\r\n    ├─ 目标：验证系统应对突发流量的能力\r\n    ├─ 方法：突然增加并发\r\n    └─ 指标：系统响应、恢复时间、数据一致性\r\n```\r\n\r\n### 性能指标\r\n\r\n```text\r\n核心指标：\r\n├─ 响应时间（Response Time）\r\n│   ├─ P50：50%请求的响应时间\r\n│   ├─ P95：95%请求的响应时间\r\n│   ├─ P99：99%请求的响应时间\r\n│   └─ 目标：P99 < 1秒\r\n│\r\n├─ 吞吐量（Throughput）\r\n│   ├─ TPS：每秒事务数\r\n│   ├─ QPS：每秒查询数\r\n│   └─ 目标：根据业务定义\r\n│\r\n├─ 错误率（Error Rate）\r\n│   ├─ 计算：错误请求数 / 总请求数\r\n│   └─ 目标：< 0.1%\r\n│\r\n└─ 资源使用率\r\n    ├─ CPU使用率：< 80%\r\n    ├─ 内存使用率：< 80%\r\n    ├─ 磁盘IO：< 80%\r\n    └─ 网络IO：< 80%\r\n```\r\n\r\n### 性能测试工具\r\n\r\n```text\r\n├─ JMeter\r\n│   ├─ 优点：功能全面、插件丰富\r\n│   ├─ 缺点：界面复杂、资源消耗大\r\n│   └─ 适用：复杂场景、协议测试\r\n│\r\n├─ Locust\r\n│   ├─ 优点：代码化、分布式\r\n│   ├─ 缺点：需要编程能力\r\n│   └─ 适用：API测试、分布式测试\r\n│\r\n├─ k6\r\n│   ├─ 优点：现代化、CI友好\r\n│   ├─ 缺点：社区较小\r\n│   └─ 适用：现代应用、DevOps\r\n│\r\n└─ wrk\r\n    ├─ 优点：轻量、高效\r\n    ├─ 缺点：功能简单\r\n    └─ 适用：简单压测、快速验证\r\n```\r\n\r\n## 维度2：安全测试\r\n\r\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\r\n> 执行前必须确认：\r\n> 1. 测试目标属于你或已获得明确授权\r\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\r\n> 3. 了解并遵守当地网络安全相关法律法规\r\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\r\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\r\n\r\n### 安全测试类型\r\n\r\n```text\r\n├─ OWASP Top 10\r\n│   ├─ 注入攻击（Injection）\r\n│   ├─ 失效的身份认证（Broken Authentication）\r\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\r\n│   ├─ XML外部实体（XXE）\r\n│   ├─ 失效的访问控制（Broken Access Control）\r\n│   ├─ 安全配置错误（Security Misconfiguration）\r\n│   ├─ 跨站脚本（XSS）\r\n│   ├─ 不安全的反序列化（Insecure Deserialization）\r\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\r\n│   └─ 不足的日志和监控（Insufficient Logging）\r\n│\r\n├─ 渗透测试\r\n│   ├─ 信息收集：域名、IP、端口\r\n│   ├─ 漏洞扫描：自动化扫描\r\n│   ├─ 漏洞利用：手动验证\r\n│   └─ 报告输出：漏洞报告\r\n│\r\n└─ 代码审计\r\n    ├─ 静态分析：代码扫描\r\n    ├─ 动态分析：运行时检测\r\n    └─ 人工审计：代码Review\r\n```\r\n\r\n### 安全测试工具\r\n\r\n```text\r\n├─ Burp Suite\r\n│   ├─ 用途：Web应用渗透测试\r\n│   ├─ 功能：代理、扫描、爬虫、爆破\r\n│   └─ 适用：Web安全测试\r\n│\r\n├─ OWASP ZAP\r\n│   ├─ 用途：Web应用安全扫描\r\n│   ├─ 功能：自动扫描、手动测试\r\n│   └─ 适用：自动化安全测试\r\n│\r\n├─ SQLMap\r\n│   ├─ 用途：SQL注入测试\r\n│   ├─ 功能：自动检测、利用SQL注入\r\n│   └─ 适用：SQL注入测试\r\n│\r\n└─ Nmap\r\n    ├─ 用途：网络扫描\r\n    ├─ 功能：端口扫描、服务识别\r\n    └─ 适用：信息收集\r\n```\r\n\r\n## 维度3：兼容性测试\r\n\r\n### 兼容性测试维度\r\n\r\n```text\r\n├─ 浏览器兼容\r\n│   ├─ Chrome\r\n│   ├─ Firefox\r\n│   ├─ Safari\r\n│   ├─ Edge\r\n│   └─ IE（如需要）\r\n│\r\n├─ 设备兼容\r\n│   ├─ PC\r\n│   ├─ 手机（iOS/Android）\r\n│   ├─ 平板\r\n│   └─ 不同分辨率\r\n│\r\n├─ 系统兼容\r\n│   ├─ Windows\r\n│   ├─ macOS\r\n│   ├─ Linux\r\n│   └─ 不同版本\r\n│\r\n└─ 网络兼容\r\n    ├─ WiFi\r\n    ├─ 4G/5G\r\n    ├─ 弱网\r\n    └─ 离线\r\n```\r\n\r\n### 兼容性测试工具\r\n\r\n```text\r\n├─ 浏览器测试\r\n│   ├─ BrowserStack：云端真机测试\r\n│   ├─ Sauce Labs：云端测试平台\r\n│   ├─ LambdaTest：跨浏览器测试\r\n│   └─ Can I Use：兼容性查询\r\n│\r\n├─ 移动端测试\r\n│   ├─ Appium：移动端自动化\r\n│   ├─ XCTest/Espresso：原生测试\r\n│   └─ 真机测试：实际设备测试\r\n│\r\n└─ 响应式测试\r\n    ├─ Chrome DevTools：设备模拟\r\n    ├─ Responsinator：响应式检查\r\n    └─ Am I Responsive：响应式检查\r\n```\r\n\r\n## 专项测试检查清单\r\n\r\n### 性能测试检查\r\n- [ ] 测试场景设计？\r\n- [ ] 性能指标定义？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试环境准备？\r\n- [ ] 监控工具配置？\r\n- [ ] 结果分析报告？\r\n\r\n### 安全测试检查\r\n- [ ] 测试范围确定？\r\n- [ ] 测试工具准备？\r\n- [ ] OWASP Top 10覆盖？\r\n- [ ] 渗透测试执行？\r\n- [ ] 漏洞报告输出？\r\n- [ ] 修复验证完成？\r\n\r\n### 兼容性测试检查\r\n- [ ] 浏览器范围确定？\r\n- [ ] 设备范围确定？\r\n- [ ] 测试矩阵设计？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试执行完成？\r\n- [ ] 问题报告输出？\r\n\r\n## 输出示例\r\n\r\n**用户说\"测一下这个接口的性能\"**\r\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\r\n\r\n**用户说\"做个安全测试\"**\r\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\r\n\r\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\r\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\r\n\r\n## 检查清单\r\n\r\n专项测试完成后检查：\r\n- [ ] 测试类型是否明确？\r\n- [ ] 测试工具是否选择？\r\n- [ ] 测试环境是否准备？\r\n- [ ] 测试执行是否完成？\r\n- [ ] 结果分析是否深入？\r\n- [ ] 报告输出是否规范？\n\nFile v1.7.6:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.7.6\",\n  \"publishedAt\": 1788266740581\n}\n\nFile v1.7.6:skill-card.md\n\n## Description:\n\n专项测试帮助 QA and engineering teams design focused performance, security, and compatibility validation after functional testing is complete.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[kokxi](https://clawhub.ai/user/kokxi)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nQA testers, developers, and release engineers use this skill to create specialized test plans, performance scenarios, security test cases, and compatibility matrices once core functionality has already been validated.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Security and penetration-testing guidance can be misused if applied outside authorized systems.\n\nMitigation: Use security testing only on systems you own or have explicit written permission to test, with scope, target environment, and boundaries confirmed before execution.\n\nRisk: The release evidence flags an unpinned npx command that can install a broad external skill bundle and change future agent behavior.\n\nMitigation: Do not run the full-bundle install unless you trust the publisher and have pinned or verified the CLI package and repository commit.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/kokxi/skills/qa-specialized-testing)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, configuration, guidance]\n\n**Output Format:** [Markdown test plans, traceable test case tables, performance scenarios, security cases, and compatibility matrices]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes specialized_test_plan, performance_cases, security_cases, compatibility_matrix, and test cases with unique IDs.]\n\n## Skill Version(s):\n\n1.7.6 (source: server release evidence; artifact frontmatter lists 1.7.5)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.7.5: 3 files, 5862 bytes\n\nFiles: skill-card.md (1926b), SKILL.md (10493b), _meta.json (141b)\n\nFile v1.7.5:SKILL.md\n\n---\nname: qa-specialized-testing\nslug: qa-specialized-testing\ndisplayName: Specialized Testing\nversion: 1.7.5\ndescription: >-\n  当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。\n\nwhen_to_use: 用户说\"性能测试\"、\"安全测试（专项）\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入测试\"、\"跨浏览器测试\"、需要进行专项测试、功能测试完成后需要补充专项测试时\nallowed-tools: Read Grep Glob Bash\nrelated_skills:\n  upstream:\n    - qa-risk-intuition          # 输入：风险评估识别专项测试需求\n    - qa-test-strategy-design    # 输入：测试策略确定专项测试范围\n  downstream:\n    - qa-release-risk-governance # 输出：专项测试结果用于发布评估\n    - qa-agent-testing\n    - qa-mobile-testing\ninput_format:\n  required:\n    - name: 测试策略\n      type: object\n      description: 来自qa-test-strategy-design的测试策略\n    - name: 专项需求\n      type: string\n      description: 性能/安全/兼容性等专项测试需求\n  optional:\n    - name: 环境信息\n      type: string\n      description: 专项测试环境配置\noutput_format:\n  traceability:\n    - 每个专项测试用例带唯一ID（TC_{模块缩写}_{功能缩写}_{序号}，如 TC_API_LOGIN_001）\n    - 关联专项类型和需求ID\n  structure:\n    - 测试用例表格：固定 9 列（用例编号|测试类型|功能模块|测试标题|用例级别|预置条件|测试步骤|预期结果|风险等级）\n    - 用例级别：P0≤20%（核心流程）/ P1≤40%（主要功能）/ P2≤30%（次要功能）/ P3≤10%（边缘场景）\n    - 覆盖率：标注口径（基于现有需求/输入文档），禁止\"全覆盖/100%\"绝对化表述；缺失模块标注\"未覆盖+原因\"\n    - specialized_test_plan: 专项测试方案\n    - performance_cases: 性能测试场景\n    - security_cases: 安全测试用例\n    - compatibility_matrix: 兼容性矩阵\ncategories: ['Development','Testing']\ndepth_requirement_quantification:\n  reference_value: \"根据专项类型调整测试深度：简单×1/中等×2/复杂×3\"\n  minimum: \"至少完成性能、安全、兼容性3类专项中的2类\"\nerror_recovery_guidance:\n  on_failure: \"专项测试遗漏维度时回退到测试策略补充范围\"\n  retry_behavior: \"补全范围后重新执行专项测试\"\n---\n# 专项测试能力\n\n## 核心原则\n\n专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\n\n## 深度要求（参考值）\n\n**关键指标**：根据系统复杂度调整专项测试深度\n\n| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |\n|--------|------------|------------|------|\n| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |\n| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |\n| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |\n\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\n\n## 维度1：性能测试\n\n### 性能测试类型\n\n```text\n├─ 负载测试（Load Testing）\n│   ├─ 目标：验证系统在预期负载下的表现\n│   ├─ 方法：逐步增加并发，观察性能指标\n│   └─ 指标：响应时间、吞吐量、错误率\n│\n├─ 压力测试（Stress Testing）\n│   ├─ 目标：验证系统在极限负载下的表现\n│   ├─ 方法：持续增加并发直到系统崩溃\n│   └─ 指标：系统极限、崩溃点、恢复能力\n│\n├─ 稳定性测试（Soak Testing）\n│   ├─ 目标：验证系统长时间运行的稳定性\n│   ├─ 方法：持续运行24-72小时\n│   └─ 指标：内存泄漏、资源消耗、性能退化\n│\n└─ 尖峰测试（Spike Testing）\n    ├─ 目标：验证系统应对突发流量的能力\n    ├─ 方法：突然增加并发\n    └─ 指标：系统响应、恢复时间、数据一致性\n```\n\n### 性能指标\n\n```text\n核心指标：\n├─ 响应时间（Response Time）\n│   ├─ P50：50%请求的响应时间\n│   ├─ P95：95%请求的响应时间\n│   ├─ P99：99%请求的响应时间\n│   └─ 目标：P99 < 1秒\n│\n├─ 吞吐量（Throughput）\n│   ├─ TPS：每秒事务数\n│   ├─ QPS：每秒查询数\n│   └─ 目标：根据业务定义\n│\n├─ 错误率（Error Rate）\n│   ├─ 计算：错误请求数 / 总请求数\n│   └─ 目标：< 0.1%\n│\n└─ 资源使用率\n    ├─ CPU使用率：< 80%\n    ├─ 内存使用率：< 80%\n    ├─ 磁盘IO：< 80%\n    └─ 网络IO：< 80%\n```\n\n### 性能测试工具\n\n```text\n├─ JMeter\n│   ├─ 优点：功能全面、插件丰富\n│   ├─ 缺点：界面复杂、资源消耗大\n│   └─ 适用：复杂场景、协议测试\n│\n├─ Locust\n│   ├─ 优点：代码化、分布式\n│   ├─ 缺点：需要编程能力\n│   └─ 适用：API测试、分布式测试\n│\n├─ k6\n│   ├─ 优点：现代化、CI友好\n│   ├─ 缺点：社区较小\n│   └─ 适用：现代应用、DevOps\n│\n└─ wrk\n    ├─ 优点：轻量、高效\n    ├─ 缺点：功能简单\n    └─ 适用：简单压测、快速验证\n```\n\n## 维度2：安全测试\n\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\n> 执行前必须确认：\n> 1. 测试目标属于你或已获得明确授权\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\n> 3. 了解并遵守当地网络安全相关法律法规\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\n\n### 安全测试类型\n\n```text\n├─ OWASP Top 10\n│   ├─ 注入攻击（Injection）\n│   ├─ 失效的身份认证（Broken Authentication）\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\n│   ├─ XML外部实体（XXE）\n│   ├─ 失效的访问控制（Broken Access Control）\n│   ├─ 安全配置错误（Security Misconfiguration）\n│   ├─ 跨站脚本（XSS）\n│   ├─ 不安全的反序列化（Insecure Deserialization）\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\n│   └─ 不足的日志和监控（Insufficient Logging）\n│\n├─ 渗透测试\n│   ├─ 信息收集：域名、IP、端口\n│   ├─ 漏洞扫描：自动化扫描\n│   ├─ 漏洞利用：手动验证\n│   └─ 报告输出：漏洞报告\n│\n└─ 代码审计\n    ├─ 静态分析：代码扫描\n    ├─ 动态分析：运行时检测\n    └─ 人工审计：代码Review\n```\n\n### 安全测试工具\n\n```text\n├─ Burp Suite\n│   ├─ 用途：Web应用渗透测试\n│   ├─ 功能：代理、扫描、爬虫、爆破\n│   └─ 适用：Web安全测试\n│\n├─ OWASP ZAP\n│   ├─ 用途：Web应用安全扫描\n│   ├─ 功能：自动扫描、手动测试\n│   └─ 适用：自动化安全测试\n│\n├─ SQLMap\n│   ├─ 用途：SQL注入测试\n│   ├─ 功能：自动检测、利用SQL注入\n│   └─ 适用：SQL注入测试\n│\n└─ Nmap\n    ├─ 用途：网络扫描\n    ├─ 功能：端口扫描、服务识别\n    └─ 适用：信息收集\n```\n\n## 维度3：兼容性测试\n\n### 兼容性测试维度\n\n```text\n├─ 浏览器兼容\n│   ├─ Chrome\n│   ├─ Firefox\n│   ├─ Safari\n│   ├─ Edge\n│   └─ IE（如需要）\n│\n├─ 设备兼容\n│   ├─ PC\n│   ├─ 手机（iOS/Android）\n│   ├─ 平板\n│   └─ 不同分辨率\n│\n├─ 系统兼容\n│   ├─ Windows\n│   ├─ macOS\n│   ├─ Linux\n│   └─ 不同版本\n│\n└─ 网络兼容\n    ├─ WiFi\n    ├─ 4G/5G\n    ├─ 弱网\n    └─ 离线\n```\n\n### 兼容性测试工具\n\n```text\n├─ 浏览器测试\n│   ├─ BrowserStack：云端真机测试\n│   ├─ Sauce Labs：云端测试平台\n│   ├─ LambdaTest：跨浏览器测试\n│   └─ Can I Use：兼容性查询\n│\n├─ 移动端测试\n│   ├─ Appium：移动端自动化\n│   ├─ XCTest/Espresso：原生测试\n│   └─ 真机测试：实际设备测试\n│\n└─ 响应式测试\n    ├─ Chrome DevTools：设备模拟\n    ├─ Responsinator：响应式检查\n    └─ Am I Responsive：响应式检查\n```\n\n## 专项测试检查清单\n\n### 性能测试检查\n- [ ] 测试场景设计？\n- [ ] 性能指标定义？\n- [ ] 测试工具选择？\n- [ ] 测试环境准备？\n- [ ] 监控工具配置？\n- [ ] 结果分析报告？\n\n### 安全测试检查\n- [ ] 测试范围确定？\n- [ ] 测试工具准备？\n- [ ] OWASP Top 10覆盖？\n- [ ] 渗透测试执行？\n- [ ] 漏洞报告输出？\n- [ ] 修复验证完成？\n\n### 兼容性测试检查\n- [ ] 浏览器范围确定？\n- [ ] 设备范围确定？\n- [ ] 测试矩阵设计？\n- [ ] 测试工具选择？\n- [ ] 测试执行完成？\n- [ ] 问题报告输出？\n\n## 输出示例\n\n**用户说\"测一下这个接口的性能\"**\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\n\n**用户说\"做个安全测试\"**\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\n\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\n\n## 检查清单\n\n专项测试完成后检查：\n- [ ] 测试类型是否明确？\n- [ ] 测试工具是否选择？\n- [ ] 测试环境是否准备？\n- [ ] 测试执行是否完成？\n- [ ] 结果分析是否深入？\n- [ ] 报告输出是否规范？\n\nFile v1.7.5:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.7.5\",\n  \"publishedAt\": 1788103127010\n}\n\nFile v1.7.5:skill-card.md\n\n## Description:\n\nHelps agents design specialized QA test plans for performance, security, and compatibility after functional testing is complete.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[kokxi](https://clawhub.ai/user/kokxi)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, QA engineers, and test automation agents use this skill to plan deeper quality validation after functional testing, including performance scenarios, authorized security checks, and compatibility matrices.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Security testing guidance could be applied to systems without authorization or outside the approved scope.\n\nMitigation: Confirm written authorization, define targets and boundaries, and use only approved test environments before applying security test cases.\n\nRisk: Performance, stress, or security testing could affect service availability if run against production systems.\n\nMitigation: Prefer a dedicated test environment, agree on test limits, and monitor system health during execution.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/kokxi/skills/qa-specialized-testing)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, guidance, configuration]\n\n**Output Format:** [Markdown test plans, test case tables, performance scenarios, security cases, and compatibility matrices]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Outputs are advisory QA artifacts and require review against the authorized test scope and environment.]\n\n## Skill Version(s):\n\n1.7.5 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.7.0: 3 files, 5635 bytes\n\nFiles: skill-card.md (2085b), SKILL.md (9997b), _meta.json (141b)\n\nFile v1.7.0:SKILL.md\n\n---\nname: qa-specialized-testing\nslug: qa-specialized-testing\ndisplayName: Specialized Testing\nversion: 1.7.0\ndescription: >-\n  当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。\n\nwhen_to_use: 用户说\"性能测试\"、\"安全测试（专项）\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入测试\"、\"跨浏览器测试\"、需要进行专项测试、功能测试完成后需要补充专项测试时\nallowed-tools: Read Grep Glob Bash\nrelated_skills:\n  upstream:\n    - qa-risk-intuition          # 输入：风险评估识别专项测试需求\n    - qa-test-strategy-design    # 输入：测试策略确定专项测试范围\n  downstream:\n    - qa-release-risk-governance # 输出：专项测试结果用于发布评估\n    - qa-agent-testing\n    - qa-mobile-testing\ninput_format:\n  required:\n    - name: 测试策略\n      type: object\n      description: 来自qa-test-strategy-design的测试策略\n    - name: 专项需求\n      type: string\n      description: 性能/安全/兼容性等专项测试需求\n  optional:\n    - name: 环境信息\n      type: string\n      description: 专项测试环境配置\noutput_format:\n  traceability:\n    - 每个专项测试用例带唯一ID（TC-XXXX）\n    - - 关联专项类型和需求ID\n  structure:\n    - specialized_test_plan: 专项测试方案\n    - performance_cases: 性能测试场景\n    - security_cases: 安全测试用例\n    - compatibility_matrix: 兼容性矩阵\ncategories: ['Development','Testing']\ndepth_requirement_quantification:\n  reference_value: \"根据专项类型调整测试深度：简单×1/中等×2/复杂×3\"\n  minimum: \"至少完成性能、安全、兼容性3类专项中的2类\"\nerror_recovery_guidance:\n  on_failure: \"专项测试遗漏维度时回退到测试策略补充范围\"\n  retry_behavior: \"补全范围后重新执行专项测试\"\n---\n# 专项测试能力\n\n## 核心原则\n\n专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\n\n## 深度要求（参考值）\n\n**关键指标**：根据系统复杂度调整专项测试深度\n\n| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |\n|--------|------------|------------|------|\n| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |\n| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |\n| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |\n\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\n\n## 维度1：性能测试\n\n### 性能测试类型\n\n```text\n├─ 负载测试（Load Testing）\n│   ├─ 目标：验证系统在预期负载下的表现\n│   ├─ 方法：逐步增加并发，观察性能指标\n│   └─ 指标：响应时间、吞吐量、错误率\n│\n├─ 压力测试（Stress Testing）\n│   ├─ 目标：验证系统在极限负载下的表现\n│   ├─ 方法：持续增加并发直到系统崩溃\n│   └─ 指标：系统极限、崩溃点、恢复能力\n│\n├─ 稳定性测试（Soak Testing）\n│   ├─ 目标：验证系统长时间运行的稳定性\n│   ├─ 方法：持续运行24-72小时\n│   └─ 指标：内存泄漏、资源消耗、性能退化\n│\n└─ 尖峰测试（Spike Testing）\n    ├─ 目标：验证系统应对突发流量的能力\n    ├─ 方法：突然增加并发\n    └─ 指标：系统响应、恢复时间、数据一致性\n```\n\n### 性能指标\n\n```text\n核心指标：\n├─ 响应时间（Response Time）\n│   ├─ P50：50%请求的响应时间\n│   ├─ P95：95%请求的响应时间\n│   ├─ P99：99%请求的响应时间\n│   └─ 目标：P99 < 1秒\n│\n├─ 吞吐量（Throughput）\n│   ├─ TPS：每秒事务数\n│   ├─ QPS：每秒查询数\n│   └─ 目标：根据业务定义\n│\n├─ 错误率（Error Rate）\n│   ├─ 计算：错误请求数 / 总请求数\n│   └─ 目标：< 0.1%\n│\n└─ 资源使用率\n    ├─ CPU使用率：< 80%\n    ├─ 内存使用率：< 80%\n    ├─ 磁盘IO：< 80%\n    └─ 网络IO：< 80%\n```\n\n### 性能测试工具\n\n```text\n├─ JMeter\n│   ├─ 优点：功能全面、插件丰富\n│   ├─ 缺点：界面复杂、资源消耗大\n│   └─ 适用：复杂场景、协议测试\n│\n├─ Locust\n│   ├─ 优点：代码化、分布式\n│   ├─ 缺点：需要编程能力\n│   └─ 适用：API测试、分布式测试\n│\n├─ k6\n│   ├─ 优点：现代化、CI友好\n│   ├─ 缺点：社区较小\n│   └─ 适用：现代应用、DevOps\n│\n└─ wrk\n    ├─ 优点：轻量、高效\n    ├─ 缺点：功能简单\n    └─ 适用：简单压测、快速验证\n```\n\n## 维度2：安全测试\n\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\n> 执行前必须确认：\n> 1. 测试目标属于你或已获得明确授权\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\n> 3. 了解并遵守当地网络安全相关法律法规\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\n\n### 安全测试类型\n\n```text\n├─ OWASP Top 10\n│   ├─ 注入攻击（Injection）\n│   ├─ 失效的身份认证（Broken Authentication）\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\n│   ├─ XML外部实体（XXE）\n│   ├─ 失效的访问控制（Broken Access Control）\n│   ├─ 安全配置错误（Security Misconfiguration）\n│   ├─ 跨站脚本（XSS）\n│   ├─ 不安全的反序列化（Insecure Deserialization）\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\n│   └─ 不足的日志和监控（Insufficient Logging）\n│\n├─ 渗透测试\n│   ├─ 信息收集：域名、IP、端口\n│   ├─ 漏洞扫描：自动化扫描\n│   ├─ 漏洞利用：手动验证\n│   └─ 报告输出：漏洞报告\n│\n└─ 代码审计\n    ├─ 静态分析：代码扫描\n    ├─ 动态分析：运行时检测\n    └─ 人工审计：代码Review\n```\n\n### 安全测试工具\n\n```text\n├─ Burp Suite\n│   ├─ 用途：Web应用渗透测试\n│   ├─ 功能：代理、扫描、爬虫、爆破\n│   └─ 适用：Web安全测试\n│\n├─ OWASP ZAP\n│   ├─ 用途：Web应用安全扫描\n│   ├─ 功能：自动扫描、手动测试\n│   └─ 适用：自动化安全测试\n│\n├─ SQLMap\n│   ├─ 用途：SQL注入测试\n│   ├─ 功能：自动检测、利用SQL注入\n│   └─ 适用：SQL注入测试\n│\n└─ Nmap\n    ├─ 用途：网络扫描\n    ├─ 功能：端口扫描、服务识别\n    └─ 适用：信息收集\n```\n\n## 维度3：兼容性测试\n\n### 兼容性测试维度\n\n```text\n├─ 浏览器兼容\n│   ├─ Chrome\n│   ├─ Firefox\n│   ├─ Safari\n│   ├─ Edge\n│   └─ IE（如需要）\n│\n├─ 设备兼容\n│   ├─ PC\n│   ├─ 手机（iOS/Android）\n│   ├─ 平板\n│   └─ 不同分辨率\n│\n├─ 系统兼容\n│   ├─ Windows\n│   ├─ macOS\n│   ├─ Linux\n│   └─ 不同版本\n│\n└─ 网络兼容\n    ├─ WiFi\n    ├─ 4G/5G\n    ├─ 弱网\n    └─ 离线\n```\n\n### 兼容性测试工具\n\n```text\n├─ 浏览器测试\n│   ├─ BrowserStack：云端真机测试\n│   ├─ Sauce Labs：云端测试平台\n│   ├─ LambdaTest：跨浏览器测试\n│   └─ Can I Use：兼容性查询\n│\n├─ 移动端测试\n│   ├─ Appium：移动端自动化\n│   ├─ XCTest/Espresso：原生测试\n│   └─ 真机测试：实际设备测试\n│\n└─ 响应式测试\n    ├─ Chrome DevTools：设备模拟\n    ├─ Responsinator：响应式检查\n    └─ Am I Responsive：响应式检查\n```\n\n## 专项测试检查清单\n\n### 性能测试检查\n- [ ] 测试场景设计？\n- [ ] 性能指标定义？\n- [ ] 测试工具选择？\n- [ ] 测试环境准备？\n- [ ] 监控工具配置？\n- [ ] 结果分析报告？\n\n### 安全测试检查\n- [ ] 测试范围确定？\n- [ ] 测试工具准备？\n- [ ] OWASP Top 10覆盖？\n- [ ] 渗透测试执行？\n- [ ] 漏洞报告输出？\n- [ ] 修复验证完成？\n\n### 兼容性测试检查\n- [ ] 浏览器范围确定？\n- [ ] 设备范围确定？\n- [ ] 测试矩阵设计？\n- [ ] 测试工具选择？\n- [ ] 测试执行完成？\n- [ ] 问题报告输出？\n\n## 输出示例\n\n**用户说\"测一下这个接口的性能\"**\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\n\n**用户说\"做个安全测试\"**\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\n\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\n\n## 检查清单\n\n专项测试完成后检查：\n- [ ] 测试类型是否明确？\n- [ ] 测试工具是否选择？\n- [ ] 测试环境是否准备？\n- [ ] 测试执行是否完成？\n- [ ] 结果分析是否深入？\n- [ ] 报告输出是否规范？\n\nFile v1.7.0:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.7.0\",\n  \"publishedAt\": 1786890761722\n}\n\nFile v1.7.0:skill-card.md\n\n## Description:\n\nGuides agents through specialized QA validation after functional testing, covering performance, security, and compatibility testing methods and reusable test plan outputs.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[kokxi](https://clawhub.ai/user/kokxi)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nQA engineers, developers, and release reviewers use this skill after functional validation to design focused performance, security, and compatibility test plans. It helps produce performance scenarios, security test cases, compatibility matrices, and traceable specialized QA outputs.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Security or penetration-testing guidance could be used against systems without authorization.\n\nMitigation: Use security testing content only for systems you own or have explicit written authorization to test, with clearly documented scope and environment boundaries.\n\nRisk: Performance, stress, or security tests may disrupt live services if run in production or outside the approved environment.\n\nMitigation: Define the target environment and test boundaries before execution, and prefer isolated test environments for disruptive checks.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/kokxi/skills/qa-specialized-testing)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, guidance, configuration]\n\n**Output Format:** [Markdown with structured test plans, test cases, and compatibility matrices]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Outputs may include traceable test case identifiers, performance baselines, security test cases, and compatibility coverage matrices.]\n\n## Skill Version(s):\n\n1.7.0 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.6.3: 3 files, 5527 bytes\n\nFiles: skill-card.md (1833b), SKILL.md (9997b), _meta.json (141b)\n\nFile v1.6.3:SKILL.md\n\n---\nname: qa-specialized-testing\nslug: qa-specialized-testing\ndisplayName: Specialized Testing\nversion: 1.6.3\ndescription: >-\n  当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。\n\nwhen_to_use: 用户说\"性能测试\"、\"安全测试（专项）\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入测试\"、\"跨浏览器测试\"、需要进行专项测试、功能测试完成后需要补充专项测试时\nallowed-tools: Read Grep Glob Bash\nrelated_skills:\n  upstream:\n    - qa-risk-intuition          # 输入：风险评估识别专项测试需求\n    - qa-test-strategy-design    # 输入：测试策略确定专项测试范围\n  downstream:\n    - qa-release-risk-governance # 输出：专项测试结果用于发布评估\n    - qa-agent-testing\n    - qa-mobile-testing\ninput_format:\n  required:\n    - name: 测试策略\n      type: object\n      description: 来自qa-test-strategy-design的测试策略\n    - name: 专项需求\n      type: string\n      description: 性能/安全/兼容性等专项测试需求\n  optional:\n    - name: 环境信息\n      type: string\n      description: 专项测试环境配置\noutput_format:\n  traceability:\n    - 每个专项测试用例带唯一ID（TC-XXXX）\n    - - 关联专项类型和需求ID\n  structure:\n    - specialized_test_plan: 专项测试方案\n    - performance_cases: 性能测试场景\n    - security_cases: 安全测试用例\n    - compatibility_matrix: 兼容性矩阵\ncategories: ['Development','Testing']\ndepth_requirement_quantification:\n  reference_value: \"根据专项类型调整测试深度：简单×1/中等×2/复杂×3\"\n  minimum: \"至少完成性能、安全、兼容性3类专项中的2类\"\nerror_recovery_guidance:\n  on_failure: \"专项测试遗漏维度时回退到测试策略补充范围\"\n  retry_behavior: \"补全范围后重新执行专项测试\"\n---\n# 专项测试能力\n\n## 核心原则\n\n专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\n\n## 深度要求（参考值）\n\n**关键指标**：根据系统复杂度调整专项测试深度\n\n| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |\n|--------|------------|------------|------|\n| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |\n| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |\n| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |\n\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\n\n## 维度1：性能测试\n\n### 性能测试类型\n\n```text\n├─ 负载测试（Load Testing）\n│   ├─ 目标：验证系统在预期负载下的表现\n│   ├─ 方法：逐步增加并发，观察性能指标\n│   └─ 指标：响应时间、吞吐量、错误率\n│\n├─ 压力测试（Stress Testing）\n│   ├─ 目标：验证系统在极限负载下的表现\n│   ├─ 方法：持续增加并发直到系统崩溃\n│   └─ 指标：系统极限、崩溃点、恢复能力\n│\n├─ 稳定性测试（Soak Testing）\n│   ├─ 目标：验证系统长时间运行的稳定性\n│   ├─ 方法：持续运行24-72小时\n│   └─ 指标：内存泄漏、资源消耗、性能退化\n│\n└─ 尖峰测试（Spike Testing）\n    ├─ 目标：验证系统应对突发流量的能力\n    ├─ 方法：突然增加并发\n    └─ 指标：系统响应、恢复时间、数据一致性\n```\n\n### 性能指标\n\n```text\n核心指标：\n├─ 响应时间（Response Time）\n│   ├─ P50：50%请求的响应时间\n│   ├─ P95：95%请求的响应时间\n│   ├─ P99：99%请求的响应时间\n│   └─ 目标：P99 < 1秒\n│\n├─ 吞吐量（Throughput）\n│   ├─ TPS：每秒事务数\n│   ├─ QPS：每秒查询数\n│   └─ 目标：根据业务定义\n│\n├─ 错误率（Error Rate）\n│   ├─ 计算：错误请求数 / 总请求数\n│   └─ 目标：< 0.1%\n│\n└─ 资源使用率\n    ├─ CPU使用率：< 80%\n    ├─ 内存使用率：< 80%\n    ├─ 磁盘IO：< 80%\n    └─ 网络IO：< 80%\n```\n\n### 性能测试工具\n\n```text\n├─ JMeter\n│   ├─ 优点：功能全面、插件丰富\n│   ├─ 缺点：界面复杂、资源消耗大\n│   └─ 适用：复杂场景、协议测试\n│\n├─ Locust\n│   ├─ 优点：代码化、分布式\n│   ├─ 缺点：需要编程能力\n│   └─ 适用：API测试、分布式测试\n│\n├─ k6\n│   ├─ 优点：现代化、CI友好\n│   ├─ 缺点：社区较小\n│   └─ 适用：现代应用、DevOps\n│\n└─ wrk\n    ├─ 优点：轻量、高效\n    ├─ 缺点：功能简单\n    └─ 适用：简单压测、快速验证\n```\n\n## 维度2：安全测试\n\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\n> 执行前必须确认：\n> 1. 测试目标属于你或已获得明确授权\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\n> 3. 了解并遵守当地网络安全相关法律法规\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\n\n### 安全测试类型\n\n```text\n├─ OWASP Top 10\n│   ├─ 注入攻击（Injection）\n│   ├─ 失效的身份认证（Broken Authentication）\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\n│   ├─ XML外部实体（XXE）\n│   ├─ 失效的访问控制（Broken Access Control）\n│   ├─ 安全配置错误（Security Misconfiguration）\n│   ├─ 跨站脚本（XSS）\n│   ├─ 不安全的反序列化（Insecure Deserialization）\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\n│   └─ 不足的日志和监控（Insufficient Logging）\n│\n├─ 渗透测试\n│   ├─ 信息收集：域名、IP、端口\n│   ├─ 漏洞扫描：自动化扫描\n│   ├─ 漏洞利用：手动验证\n│   └─ 报告输出：漏洞报告\n│\n└─ 代码审计\n    ├─ 静态分析：代码扫描\n    ├─ 动态分析：运行时检测\n    └─ 人工审计：代码Review\n```\n\n### 安全测试工具\n\n```text\n├─ Burp Suite\n│   ├─ 用途：Web应用渗透测试\n│   ├─ 功能：代理、扫描、爬虫、爆破\n│   └─ 适用：Web安全测试\n│\n├─ OWASP ZAP\n│   ├─ 用途：Web应用安全扫描\n│   ├─ 功能：自动扫描、手动测试\n│   └─ 适用：自动化安全测试\n│\n├─ SQLMap\n│   ├─ 用途：SQL注入测试\n│   ├─ 功能：自动检测、利用SQL注入\n│   └─ 适用：SQL注入测试\n│\n└─ Nmap\n    ├─ 用途：网络扫描\n    ├─ 功能：端口扫描、服务识别\n    └─ 适用：信息收集\n```\n\n## 维度3：兼容性测试\n\n### 兼容性测试维度\n\n```text\n├─ 浏览器兼容\n│   ├─ Chrome\n│   ├─ Firefox\n│   ├─ Safari\n│   ├─ Edge\n│   └─ IE（如需要）\n│\n├─ 设备兼容\n│   ├─ PC\n│   ├─ 手机（iOS/Android）\n│   ├─ 平板\n│   └─ 不同分辨率\n│\n├─ 系统兼容\n│   ├─ Windows\n│   ├─ macOS\n│   ├─ Linux\n│   └─ 不同版本\n│\n└─ 网络兼容\n    ├─ WiFi\n    ├─ 4G/5G\n    ├─ 弱网\n    └─ 离线\n```\n\n### 兼容性测试工具\n\n```text\n├─ 浏览器测试\n│   ├─ BrowserStack：云端真机测试\n│   ├─ Sauce Labs：云端测试平台\n│   ├─ LambdaTest：跨浏览器测试\n│   └─ Can I Use：兼容性查询\n│\n├─ 移动端测试\n│   ├─ Appium：移动端自动化\n│   ├─ XCTest/Espresso：原生测试\n│   └─ 真机测试：实际设备测试\n│\n└─ 响应式测试\n    ├─ Chrome DevTools：设备模拟\n    ├─ Responsinator：响应式检查\n    └─ Am I Responsive：响应式检查\n```\n\n## 专项测试检查清单\n\n### 性能测试检查\n- [ ] 测试场景设计？\n- [ ] 性能指标定义？\n- [ ] 测试工具选择？\n- [ ] 测试环境准备？\n- [ ] 监控工具配置？\n- [ ] 结果分析报告？\n\n### 安全测试检查\n- [ ] 测试范围确定？\n- [ ] 测试工具准备？\n- [ ] OWASP Top 10覆盖？\n- [ ] 渗透测试执行？\n- [ ] 漏洞报告输出？\n- [ ] 修复验证完成？\n\n### 兼容性测试检查\n- [ ] 浏览器范围确定？\n- [ ] 设备范围确定？\n- [ ] 测试矩阵设计？\n- [ ] 测试工具选择？\n- [ ] 测试执行完成？\n- [ ] 问题报告输出？\n\n## 输出示例\n\n**用户说\"测一下这个接口的性能\"**\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\n\n**用户说\"做个安全测试\"**\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\n\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\n\n## 检查清单\n\n专项测试完成后检查：\n- [ ] 测试类型是否明确？\n- [ ] 测试工具是否选择？\n- [ ] 测试环境是否准备？\n- [ ] 测试执行是否完成？\n- [ ] 结果分析是否深入？\n- [ ] 报告输出是否规范？\n\nFile v1.6.3:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.6.3\",\n  \"publishedAt\": 1786548465195\n}\n\nFile v1.6.3:skill-card.md\n\n## Description:\n\nThis skill helps agents design specialized QA validation after functional testing, covering performance, authorized security, and compatibility testing with reusable plans, baselines, test cases, and compatibility matrices.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[kokxi](https://clawhub.ai/user/kokxi)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nQA engineers, developers, and agents use this skill after functional testing to plan performance, authorized security, and compatibility validation. It helps define metrics, select tools, and produce reusable test plans, security cases, and compatibility matrices.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Security and load-testing guidance can be misapplied to unauthorized targets or disruptive production environments.\n\nMitigation: Confirm ownership or written authorization, define the test scope and boundaries, and avoid disruptive tests against production systems without controls.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/kokxi/skills/qa-specialized-testing)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown test plans, checklists, matrices, and optional shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include TC-XXXX traceability IDs, performance baselines, security test cases, and compatibility matrices.]\n\n## Skill Version(s):\n\n1.6.3 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.6.0: 3 files, 5538 bytes\n\nFiles: skill-card.md (1865b), SKILL.md (10232b), _meta.json (141b)\n\nFile v1.6.0:SKILL.md\n\n---\r\nname: qa-specialized-testing\r\nversion: 1.6.0\r\ndescription: >-\r\n  当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。\r\n\r\nwhen_to_use: 用户说\"性能测试\"、\"安全测试（专项）\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入测试\"、\"跨浏览器测试\"、需要进行专项测试、功能测试完成后需要补充专项测试时\r\nallowed-tools: Read Grep Glob Bash\r\nrelated_skills:\r\n  upstream:\r\n    - qa-risk-intuition          # 输入：风险评估识别专项测试需求\r\n    - qa-test-strategy-design    # 输入：测试策略确定专项测试范围\r\n  downstream:\r\n    - qa-release-risk-governance # 输出：专项测试结果用于发布评估\r\n    - qa-agent-testing\r\n    - qa-mobile-testing\r\ninput_format:\r\n  required:\r\n    - name: 测试策略\r\n      type: object\r\n      description: 来自qa-test-strategy-design的测试策略\r\n    - name: 专项需求\r\n      type: string\r\n      description: 性能/安全/兼容性等专项测试需求\r\n  optional:\r\n    - name: 环境信息\r\n      type: string\r\n      description: 专项测试环境配置\r\noutput_format:\r\n  traceability:\r\n    - 每个专项测试用例带唯一ID（TC-XXXX）\r\n    - - 关联专项类型和需求ID\r\n  structure:\r\n    - specialized_test_plan: 专项测试方案\r\n    - performance_cases: 性能测试场景\r\n    - security_cases: 安全测试用例\r\n    - compatibility_matrix: 兼容性矩阵\r\ncategories: ['Development','Testing']\r\ndepth_requirement_quantification:\r\n  reference_value: \"根据专项类型调整测试深度：简单×1/中等×2/复杂×3\"\r\n  minimum: \"至少完成性能、安全、兼容性3类专项中的2类\"\r\nerror_recovery_guidance:\r\n  on_failure: \"专项测试遗漏维度时回退到测试策略补充范围\"\r\n  retry_behavior: \"补全范围后重新执行专项测试\"\r\n---\r\n# 专项测试能力\r\n\r\n## 核心原则\r\n\r\n专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\r\n\r\n## 深度要求（参考值）\r\n\r\n**关键指标**：根据系统复杂度调整专项测试深度\r\n\r\n| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |\r\n|--------|------------|------------|------|\r\n| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |\r\n| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |\r\n| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |\r\n\r\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\r\n\r\n## 维度1：性能测试\r\n\r\n### 性能测试类型\r\n\r\n```text\r\n├─ 负载测试（Load Testing）\r\n│   ├─ 目标：验证系统在预期负载下的表现\r\n│   ├─ 方法：逐步增加并发，观察性能指标\r\n│   └─ 指标：响应时间、吞吐量、错误率\r\n│\r\n├─ 压力测试（Stress Testing）\r\n│   ├─ 目标：验证系统在极限负载下的表现\r\n│   ├─ 方法：持续增加并发直到系统崩溃\r\n│   └─ 指标：系统极限、崩溃点、恢复能力\r\n│\r\n├─ 稳定性测试（Soak Testing）\r\n│   ├─ 目标：验证系统长时间运行的稳定性\r\n│   ├─ 方法：持续运行24-72小时\r\n│   └─ 指标：内存泄漏、资源消耗、性能退化\r\n│\r\n└─ 尖峰测试（Spike Testing）\r\n    ├─ 目标：验证系统应对突发流量的能力\r\n    ├─ 方法：突然增加并发\r\n    └─ 指标：系统响应、恢复时间、数据一致性\r\n```\r\n\r\n### 性能指标\r\n\r\n```text\r\n核心指标：\r\n├─ 响应时间（Response Time）\r\n│   ├─ P50：50%请求的响应时间\r\n│   ├─ P95：95%请求的响应时间\r\n│   ├─ P99：99%请求的响应时间\r\n│   └─ 目标：P99 < 1秒\r\n│\r\n├─ 吞吐量（Throughput）\r\n│   ├─ TPS：每秒事务数\r\n│   ├─ QPS：每秒查询数\r\n│   └─ 目标：根据业务定义\r\n│\r\n├─ 错误率（Error Rate）\r\n│   ├─ 计算：错误请求数 / 总请求数\r\n│   └─ 目标：< 0.1%\r\n│\r\n└─ 资源使用率\r\n    ├─ CPU使用率：< 80%\r\n    ├─ 内存使用率：< 80%\r\n    ├─ 磁盘IO：< 80%\r\n    └─ 网络IO：< 80%\r\n```\r\n\r\n### 性能测试工具\r\n\r\n```text\r\n├─ JMeter\r\n│   ├─ 优点：功能全面、插件丰富\r\n│   ├─ 缺点：界面复杂、资源消耗大\r\n│   └─ 适用：复杂场景、协议测试\r\n│\r\n├─ Locust\r\n│   ├─ 优点：代码化、分布式\r\n│   ├─ 缺点：需要编程能力\r\n│   └─ 适用：API测试、分布式测试\r\n│\r\n├─ k6\r\n│   ├─ 优点：现代化、CI友好\r\n│   ├─ 缺点：社区较小\r\n│   └─ 适用：现代应用、DevOps\r\n│\r\n└─ wrk\r\n    ├─ 优点：轻量、高效\r\n    ├─ 缺点：功能简单\r\n    └─ 适用：简单压测、快速验证\r\n```\r\n\r\n## 维度2：安全测试\r\n\r\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\r\n> 执行前必须确认：\r\n> 1. 测试目标属于你或已获得明确授权\r\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\r\n> 3. 了解并遵守当地网络安全相关法律法规\r\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\r\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\r\n\r\n### 安全测试类型\r\n\r\n```text\r\n├─ OWASP Top 10\r\n│   ├─ 注入攻击（Injection）\r\n│   ├─ 失效的身份认证（Broken Authentication）\r\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\r\n│   ├─ XML外部实体（XXE）\r\n│   ├─ 失效的访问控制（Broken Access Control）\r\n│   ├─ 安全配置错误（Security Misconfiguration）\r\n│   ├─ 跨站脚本（XSS）\r\n│   ├─ 不安全的反序列化（Insecure Deserialization）\r\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\r\n│   └─ 不足的日志和监控（Insufficient Logging）\r\n│\r\n├─ 渗透测试\r\n│   ├─ 信息收集：域名、IP、端口\r\n│   ├─ 漏洞扫描：自动化扫描\r\n│   ├─ 漏洞利用：手动验证\r\n│   └─ 报告输出：漏洞报告\r\n│\r\n└─ 代码审计\r\n    ├─ 静态分析：代码扫描\r\n    ├─ 动态分析：运行时检测\r\n    └─ 人工审计：代码Review\r\n```\r\n\r\n### 安全测试工具\r\n\r\n```text\r\n├─ Burp Suite\r\n│   ├─ 用途：Web应用渗透测试\r\n│   ├─ 功能：代理、扫描、爬虫、爆破\r\n│   └─ 适用：Web安全测试\r\n│\r\n├─ OWASP ZAP\r\n│   ├─ 用途：Web应用安全扫描\r\n│   ├─ 功能：自动扫描、手动测试\r\n│   └─ 适用：自动化安全测试\r\n│\r\n├─ SQLMap\r\n│   ├─ 用途：SQL注入测试\r\n│   ├─ 功能：自动检测、利用SQL注入\r\n│   └─ 适用：SQL注入测试\r\n│\r\n└─ Nmap\r\n    ├─ 用途：网络扫描\r\n    ├─ 功能：端口扫描、服务识别\r\n    └─ 适用：信息收集\r\n```\r\n\r\n## 维度3：兼容性测试\r\n\r\n### 兼容性测试维度\r\n\r\n```text\r\n├─ 浏览器兼容\r\n│   ├─ Chrome\r\n│   ├─ Firefox\r\n│   ├─ Safari\r\n│   ├─ Edge\r\n│   └─ IE（如需要）\r\n│\r\n├─ 设备兼容\r\n│   ├─ PC\r\n│   ├─ 手机（iOS/Android）\r\n│   ├─ 平板\r\n│   └─ 不同分辨率\r\n│\r\n├─ 系统兼容\r\n│   ├─ Windows\r\n│   ├─ macOS\r\n│   ├─ Linux\r\n│   └─ 不同版本\r\n│\r\n└─ 网络兼容\r\n    ├─ WiFi\r\n    ├─ 4G/5G\r\n    ├─ 弱网\r\n    └─ 离线\r\n```\r\n\r\n### 兼容性测试工具\r\n\r\n```text\r\n├─ 浏览器测试\r\n│   ├─ BrowserStack：云端真机测试\r\n│   ├─ Sauce Labs：云端测试平台\r\n│   ├─ LambdaTest：跨浏览器测试\r\n│   └─ Can I Use：兼容性查询\r\n│\r\n├─ 移动端测试\r\n│   ├─ Appium：移动端自动化\r\n│   ├─ XCTest/Espresso：原生测试\r\n│   └─ 真机测试：实际设备测试\r\n│\r\n└─ 响应式测试\r\n    ├─ Chrome DevTools：设备模拟\r\n    ├─ Responsinator：响应式检查\r\n    └─ Am I Responsive：响应式检查\r\n```\r\n\r\n## 专项测试检查清单\r\n\r\n### 性能测试检查\r\n- [ ] 测试场景设计？\r\n- [ ] 性能指标定义？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试环境准备？\r\n- [ ] 监控工具配置？\r\n- [ ] 结果分析报告？\r\n\r\n### 安全测试检查\r\n- [ ] 测试范围确定？\r\n- [ ] 测试工具准备？\r\n- [ ] OWASP Top 10覆盖？\r\n- [ ] 渗透测试执行？\r\n- [ ] 漏洞报告输出？\r\n- [ ] 修复验证完成？\r\n\r\n### 兼容性测试检查\r\n- [ ] 浏览器范围确定？\r\n- [ ] 设备范围确定？\r\n- [ ] 测试矩阵设计？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试执行完成？\r\n- [ ] 问题报告输出？\r\n\r\n## 输出示例\r\n\r\n**用户说\"测一下这个接口的性能\"**\r\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\r\n\r\n**用户说\"做个安全测试\"**\r\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\r\n\r\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\r\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\r\n\r\n## 检查清单\r\n\r\n专项测试完成后检查：\r\n- [ ] 测试类型是否明确？\r\n- [ ] 测试工具是否选择？\r\n- [ ] 测试环境是否准备？\r\n- [ ] 测试执行是否完成？\r\n- [ ] 结果分析是否深入？\r\n- [ ] 报告输出是否规范？\n\nFile v1.6.0:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.6.0\",\n  \"publishedAt\": 1783358249462\n}\n\nFile v1.6.0:skill-card.md\n\n## Description: <br>\nGuides agents through specialized QA after functional testing, covering performance, security, and compatibility test planning. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[kokxi](https://clawhub.ai/user/kokxi) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nQA engineers, developers, and test agents use this skill after functional testing is complete to plan performance, security, and compatibility testing. It helps produce reusable specialized test plans, performance scenarios, security cases, and compatibility matrices with traceable test case IDs. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Security and load-testing guidance could be misused or applied to systems without authorization. <br>\nMitigation: Use only on systems the user owns or has explicit written authorization to test, with targets, scope, and test environment clearly defined before testing. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/kokxi/skills/qa-specialized-testing) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, guidance] <br>\n**Output Format:** [Markdown guidance with structured QA plan sections and checklists] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Produces specialized_test_plan, performance_cases, security_cases, and compatibility_matrix outputs with traceable test case IDs.] <br>\n\n## Skill Version(s): <br>\n1.6.0 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.5.0: 3 files, 5326 bytes\n\nFiles: skill-card.md (1865b), SKILL.md (9852b), _meta.json (141b)\n\nFile v1.5.0:SKILL.md\n\n---\r\nname: qa-specialized-testing\r\nversion: 1.5.0\r\ndescription: >-\r\n  当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。\r\n\r\nwhen_to_use: 用户说\"性能测试\"、\"安全测试\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入\"、\"跨浏览器\"、需要进行专项测试、功能测试完成后需要补充专项测试时\r\nallowed-tools: Read Grep Glob Bash\r\nrelated_skills:\r\n  upstream:\r\n    - qa-risk-intuition          # 输入：风险评估识别专项测试需求\r\n    - qa-test-strategy-design    # 输入：测试策略确定专项测试范围\r\n  downstream:\r\n    - qa-release-risk-governance # 输出：专项测试结果用于发布评估\r\ninput_format:\r\n  required:\r\n    - name: 测试策略\r\n      type: object\r\n      description: 来自qa-test-strategy-design的测试策略\r\n    - name: 专项需求\r\n      type: string\r\n      description: 性能/安全/兼容性等专项测试需求\r\n  optional:\r\n    - name: 环境信息\r\n      type: string\r\n      description: 专项测试环境配置\r\noutput_format:\r\n  structure:\r\n    - specialized_test_plan: 专项测试方案\r\n    - performance_cases: 性能测试场景\r\n    - security_cases: 安全测试用例\r\n    - compatibility_matrix: 兼容性矩阵\r\n---\r\n\r\n# 专项测试能力\r\n\r\n## 核心原则\r\n\r\n你是一位专项测试专家，擅长性能、安全、兼容性等专项测试。\r\n**核心原则**：专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\r\n本技能覆盖性能、安全、兼容性三类专项测试的方法、工具和检查清单。\r\n\r\n## 深度要求（参考值）\r\n\r\n**关键指标**：根据系统复杂度调整专项测试深度\r\n\r\n| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |\r\n|--------|------------|------------|------|\r\n| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |\r\n| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |\r\n| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |\r\n\r\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\r\n\r\n## 维度1：性能测试\r\n\r\n### 性能测试类型\r\n\r\n```text\r\n├─ 负载测试（Load Testing）\r\n│   ├─ 目标：验证系统在预期负载下的表现\r\n│   ├─ 方法：逐步增加并发，观察性能指标\r\n│   └─ 指标：响应时间、吞吐量、错误率\r\n│\r\n├─ 压力测试（Stress Testing）\r\n│   ├─ 目标：验证系统在极限负载下的表现\r\n│   ├─ 方法：持续增加并发直到系统崩溃\r\n│   └─ 指标：系统极限、崩溃点、恢复能力\r\n│\r\n├─ 稳定性测试（Soak Testing）\r\n│   ├─ 目标：验证系统长时间运行的稳定性\r\n│   ├─ 方法：持续运行24-72小时\r\n│   └─ 指标：内存泄漏、资源消耗、性能退化\r\n│\r\n└─ 尖峰测试（Spike Testing）\r\n    ├─ 目标：验证系统应对突发流量的能力\r\n    ├─ 方法：突然增加并发\r\n    └─ 指标：系统响应、恢复时间、数据一致性\r\n```\r\n\r\n### 性能指标\r\n\r\n```text\r\n核心指标：\r\n├─ 响应时间（Response Time）\r\n│   ├─ P50：50%请求的响应时间\r\n│   ├─ P95：95%请求的响应时间\r\n│   ├─ P99：99%请求的响应时间\r\n│   └─ 目标：P99 < 1秒\r\n│\r\n├─ 吞吐量（Throughput）\r\n│   ├─ TPS：每秒事务数\r\n│   ├─ QPS：每秒查询数\r\n│   └─ 目标：根据业务定义\r\n│\r\n├─ 错误率（Error Rate）\r\n│   ├─ 计算：错误请求数 / 总请求数\r\n│   └─ 目标：< 0.1%\r\n│\r\n└─ 资源使用率\r\n    ├─ CPU使用率：< 80%\r\n    ├─ 内存使用率：< 80%\r\n    ├─ 磁盘IO：< 80%\r\n    └─ 网络IO：< 80%\r\n```\r\n\r\n### 性能测试工具\r\n\r\n```text\r\n├─ JMeter\r\n│   ├─ 优点：功能全面、插件丰富\r\n│   ├─ 缺点：界面复杂、资源消耗大\r\n│   └─ 适用：复杂场景、协议测试\r\n│\r\n├─ Locust\r\n│   ├─ 优点：代码化、分布式\r\n│   ├─ 缺点：需要编程能力\r\n│   └─ 适用：API测试、分布式测试\r\n│\r\n├─ k6\r\n│   ├─ 优点：现代化、CI友好\r\n│   ├─ 缺点：社区较小\r\n│   └─ 适用：现代应用、DevOps\r\n│\r\n└─ wrk\r\n    ├─ 优点：轻量、高效\r\n    ├─ 缺点：功能简单\r\n    └─ 适用：简单压测、快速验证\r\n```\r\n\r\n## 维度2：安全测试\r\n\r\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\r\n> 执行前必须确认：\r\n> 1. 测试目标属于你或已获得明确授权\r\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\r\n> 3. 了解并遵守当地网络安全相关法律法规\r\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\r\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\r\n\r\n### 安全测试类型\r\n\r\n```text\r\n├─ OWASP Top 10\r\n│   ├─ 注入攻击（Injection）\r\n│   ├─ 失效的身份认证（Broken Authentication）\r\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\r\n│   ├─ XML外部实体（XXE）\r\n│   ├─ 失效的访问控制（Broken Access Control）\r\n│   ├─ 安全配置错误（Security Misconfiguration）\r\n│   ├─ 跨站脚本（XSS）\r\n│   ├─ 不安全的反序列化（Insecure Deserialization）\r\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\r\n│   └─ 不足的日志和监控（Insufficient Logging）\r\n│\r\n├─ 渗透测试\r\n│   ├─ 信息收集：域名、IP、端口\r\n│   ├─ 漏洞扫描：自动化扫描\r\n│   ├─ 漏洞利用：手动验证\r\n│   └─ 报告输出：漏洞报告\r\n│\r\n└─ 代码审计\r\n    ├─ 静态分析：代码扫描\r\n    ├─ 动态分析：运行时检测\r\n    └─ 人工审计：代码Review\r\n```\r\n\r\n### 安全测试工具\r\n\r\n```text\r\n├─ Burp Suite\r\n│   ├─ 用途：Web应用渗透测试\r\n│   ├─ 功能：代理、扫描、爬虫、爆破\r\n│   └─ 适用：Web安全测试\r\n│\r\n├─ OWASP ZAP\r\n│   ├─ 用途：Web应用安全扫描\r\n│   ├─ 功能：自动扫描、手动测试\r\n│   └─ 适用：自动化安全测试\r\n│\r\n├─ SQLMap\r\n│   ├─ 用途：SQL注入测试\r\n│   ├─ 功能：自动检测、利用SQL注入\r\n│   └─ 适用：SQL注入测试\r\n│\r\n└─ Nmap\r\n    ├─ 用途：网络扫描\r\n    ├─ 功能：端口扫描、服务识别\r\n    └─ 适用：信息收集\r\n```\r\n\r\n## 维度3：兼容性测试\r\n\r\n### 兼容性测试维度\r\n\r\n```text\r\n├─ 浏览器兼容\r\n│   ├─ Chrome\r\n│   ├─ Firefox\r\n│   ├─ Safari\r\n│   ├─ Edge\r\n│   └─ IE（如需要）\r\n│\r\n├─ 设备兼容\r\n│   ├─ PC\r\n│   ├─ 手机（iOS/Android）\r\n│   ├─ 平板\r\n│   └─ 不同分辨率\r\n│\r\n├─ 系统兼容\r\n│   ├─ Windows\r\n│   ├─ macOS\r\n│   ├─ Linux\r\n│   └─ 不同版本\r\n│\r\n└─ 网络兼容\r\n    ├─ WiFi\r\n    ├─ 4G/5G\r\n    ├─ 弱网\r\n    └─ 离线\r\n```\r\n\r\n### 兼容性测试工具\r\n\r\n```text\r\n├─ 浏览器测试\r\n│   ├─ BrowserStack：云端真机测试\r\n│   ├─ Sauce Labs：云端测试平台\r\n│   ├─ LambdaTest：跨浏览器测试\r\n│   └─ Can I Use：兼容性查询\r\n│\r\n├─ 移动端测试\r\n│   ├─ Appium：移动端自动化\r\n│   ├─ XCTest/Espresso：原生测试\r\n│   └─ 真机测试：实际设备测试\r\n│\r\n└─ 响应式测试\r\n    ├─ Chrome DevTools：设备模拟\r\n    ├─ Responsinator：响应式检查\r\n    └─ Am I Responsive：响应式检查\r\n```\r\n\r\n## 专项测试检查清单\r\n\r\n### 性能测试检查\r\n- [ ] 测试场景设计？\r\n- [ ] 性能指标定义？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试环境准备？\r\n- [ ] 监控工具配置？\r\n- [ ] 结果分析报告？\r\n\r\n### 安全测试检查\r\n- [ ] 测试范围确定？\r\n- [ ] 测试工具准备？\r\n- [ ] OWASP Top 10覆盖？\r\n- [ ] 渗透测试执行？\r\n- [ ] 漏洞报告输出？\r\n- [ ] 修复验证完成？\r\n\r\n### 兼容性测试检查\r\n- [ ] 浏览器范围确定？\r\n- [ ] 设备范围确定？\r\n- [ ] 测试矩阵设计？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试执行完成？\r\n- [ ] 问题报告输出？\r\n\r\n## 输出示例\r\n\r\n**用户说\"测一下这个接口的性能\"**\r\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\r\n\r\n**用户说\"做个安全测试\"**\r\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\r\n\r\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\r\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\r\n\r\n## 检查清单\r\n\r\n专项测试完成后检查：\r\n- [ ] 测试类型是否明确？\r\n- [ ] 测试工具是否选择？\r\n- [ ] 测试环境是否准备？\r\n- [ ] 测试执行是否完成？\r\n- [ ] 结果分析是否深入？\r\n- [ ] 报告输出是否规范？\n\nFile v1.5.0:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.5.0\",\n  \"publishedAt\": 1782736526430\n}\n\nFile v1.5.0:skill-card.md\n\n## Description: <br>\nGuides agents through specialized QA planning after functional testing, covering performance, security, and compatibility test methods, tools, and reusable test artifacts. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[kokxi](https://clawhub.ai/user/kokxi) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nQA engineers, developers, and release reviewers use this skill after functional testing to plan deeper performance, security, and compatibility validation. It helps produce specialized test plans, performance scenarios, security cases, and compatibility matrices. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Security or load-testing guidance could be misapplied to systems without authorization or outside an agreed test scope. <br>\nMitigation: Confirm ownership or written permission, define scope and environment, and prefer a dedicated test environment before using invasive tools. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/kokxi/skills/qa-specialized-testing) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Text] <br>\n**Output Format:** [Markdown-style QA plans, test cases, checklists, and compatibility matrices] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Outputs are intended for human review before executing performance, security, or compatibility tests.] <br>\n\n## Skill Version(s): <br>\n1.5.0 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.4.1: 3 files, 4953 bytes\n\nFiles: skill-card.md (2192b), SKILL.md (8607b), _meta.json (141b)\n\nFile v1.4.1:SKILL.md\n\n---\r\nname: qa-specialized-testing\r\ndescription: >-\r\n  专项测试能力，覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10）、兼容性测试方法。当需要设计专项测试方案时激活。\r\n\r\nwhen_to_use: 用户说\"性能测试\"、\"安全测试\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入\"、\"跨浏览器\"、需要进行专项测试、功能测试完成后需要补充专项测试时\r\nallowed-tools: Read Grep Glob Bash\r\nrelated_skills:\r\n  upstream:\r\n    - qa-risk-intuition          # 输入：风险评估识别专项测试需求\r\n    - qa-test-strategy-design    # 输入：测试策略确定专项测试范围\r\n  downstream:\r\n    - qa-release-risk-governance # 输出：专项测试结果用于发布评估\r\ninput_format: 风险评估 + 测试策略\r\noutput_format: 专项测试方案（性能/安全/兼容性测试设计和结果）\r\n---\r\n\r\n# 专项测试能力\r\n\r\n## Overview\r\n\r\n你是一位专项测试专家，擅长性能、安全、兼容性等专项测试。\r\n**核心原则**：专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\r\n本技能覆盖性能、安全、兼容性三类专项测试的方法、工具和检查清单。\r\n\r\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\r\n\r\n## 维度1：性能测试\r\n\r\n### 性能测试类型\r\n\r\n```\r\n├─ 负载测试（Load Testing）\r\n│   ├─ 目标：验证系统在预期负载下的表现\r\n│   ├─ 方法：逐步增加并发，观察性能指标\r\n│   └─ 指标：响应时间、吞吐量、错误率\r\n│\r\n├─ 压力测试（Stress Testing）\r\n│   ├─ 目标：验证系统在极限负载下的表现\r\n│   ├─ 方法：持续增加并发直到系统崩溃\r\n│   └─ 指标：系统极限、崩溃点、恢复能力\r\n│\r\n├─ 稳定性测试（Soak Testing）\r\n│   ├─ 目标：验证系统长时间运行的稳定性\r\n│   ├─ 方法：持续运行24-72小时\r\n│   └─ 指标：内存泄漏、资源消耗、性能退化\r\n│\r\n└─ 尖峰测试（Spike Testing）\r\n    ├─ 目标：验证系统应对突发流量的能力\r\n    ├─ 方法：突然增加并发\r\n    └─ 指标：系统响应、恢复时间、数据一致性\r\n```\r\n\r\n### 性能指标\r\n\r\n```\r\n核心指标：\r\n├─ 响应时间（Response Time）\r\n│   ├─ P50：50%请求的响应时间\r\n│   ├─ P95：95%请求的响应时间\r\n│   ├─ P99：99%请求的响应时间\r\n│   └─ 目标：P99 < 1秒\r\n│\r\n├─ 吞吐量（Throughput）\r\n│   ├─ TPS：每秒事务数\r\n│   ├─ QPS：每秒查询数\r\n│   └─ 目标：根据业务定义\r\n│\r\n├─ 错误率（Error Rate）\r\n│   ├─ 计算：错误请求数 / 总请求数\r\n│   └─ 目标：< 0.1%\r\n│\r\n└─ 资源使用率\r\n    ├─ CPU使用率：< 80%\r\n    ├─ 内存使用率：< 80%\r\n    ├─ 磁盘IO：< 80%\r\n    └─ 网络IO：< 80%\r\n```\r\n\r\n### 性能测试工具\r\n\r\n```\r\n├─ JMeter\r\n│   ├─ 优点：功能全面、插件丰富\r\n│   ├─ 缺点：界面复杂、资源消耗大\r\n│   └─ 适用：复杂场景、协议测试\r\n│\r\n├─ Locust\r\n│   ├─ 优点：代码化、分布式\r\n│   ├─ 缺点：需要编程能力\r\n│   └─ 适用：API测试、分布式测试\r\n│\r\n├─ k6\r\n│   ├─ 优点：现代化、CI友好\r\n│   ├─ 缺点：社区较小\r\n│   └─ 适用：现代应用、DevOps\r\n│\r\n└─ wrk\r\n    ├─ 优点：轻量、高效\r\n    ├─ 缺点：功能简单\r\n    └─ 适用：简单压测、快速验证\r\n```\r\n\r\n## 维度2：安全测试\r\n\r\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\r\n> 执行前必须确认：\r\n> 1. 测试目标属于你或已获得明确授权\r\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\r\n> 3. 了解并遵守当地网络安全相关法律法规\r\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\r\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\r\n\r\n### 安全测试类型\r\n\r\n```\r\n├─ OWASP Top 10\r\n│   ├─ 注入攻击（Injection）\r\n│   ├─ 失效的身份认证（Broken Authentication）\r\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\r\n│   ├─ XML外部实体（XXE）\r\n│   ├─ 失效的访问控制（Broken Access Control）\r\n│   ├─ 安全配置错误（Security Misconfiguration）\r\n│   ├─ 跨站脚本（XSS）\r\n│   ├─ 不安全的反序列化（Insecure Deserialization）\r\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\r\n│   └─ 不足的日志和监控（Insufficient Logging）\r\n│\r\n├─ 渗透测试\r\n│   ├─ 信息收集：域名、IP、端口\r\n│   ├─ 漏洞扫描：自动化扫描\r\n│   ├─ 漏洞利用：手动验证\r\n│   └─ 报告输出：漏洞报告\r\n│\r\n└─ 代码审计\r\n    ├─ 静态分析：代码扫描\r\n    ├─ 动态分析：运行时检测\r\n    └─ 人工审计：代码Review\r\n```\r\n\r\n### 安全测试工具\r\n\r\n```\r\n├─ Burp Suite\r\n│   ├─ 用途：Web应用渗透测试\r\n│   ├─ 功能：代理、扫描、爬虫、爆破\r\n│   └─ 适用：Web安全测试\r\n│\r\n├─ OWASP ZAP\r\n│   ├─ 用途：Web应用安全扫描\r\n│   ├─ 功能：自动扫描、手动测试\r\n│   └─ 适用：自动化安全测试\r\n│\r\n├─ SQLMap\r\n│   ├─ 用途：SQL注入测试\r\n│   ├─ 功能：自动检测、利用SQL注入\r\n│   └─ 适用：SQL注入测试\r\n│\r\n└─ Nmap\r\n    ├─ 用途：网络扫描\r\n    ├─ 功能：端口扫描、服务识别\r\n    └─ 适用：信息收集\r\n```\r\n\r\n## 维度3：兼容性测试\r\n\r\n### 兼容性测试维度\r\n\r\n```\r\n├─ 浏览器兼容\r\n│   ├─ Chrome\r\n│   ├─ Firefox\r\n│   ├─ Safari\r\n│   ├─ Edge\r\n│   └─ IE（如需要）\r\n│\r\n├─ 设备兼容\r\n│   ├─ PC\r\n│   ├─ 手机（iOS/Android）\r\n│   ├─ 平板\r\n│   └─ 不同分辨率\r\n│\r\n├─ 系统兼容\r\n│   ├─ Windows\r\n│   ├─ macOS\r\n│   ├─ Linux\r\n│   └─ 不同版本\r\n│\r\n└─ 网络兼容\r\n    ├─ WiFi\r\n    ├─ 4G/5G\r\n    ├─ 弱网\r\n    └─ 离线\r\n```\r\n\r\n### 兼容性测试工具\r\n\r\n```\r\n├─ 浏览器测试\r\n│   ├─ BrowserStack：云端真机测试\r\n│   ├─ Sauce Labs：云端测试平台\r\n│   ├─ LambdaTest：跨浏览器测试\r\n│   └─ Can I Use：兼容性查询\r\n│\r\n├─ 移动端测试\r\n│   ├─ Appium：移动端自动化\r\n│   ├─ XCTest/Espresso：原生测试\r\n│   └─ 真机测试：实际设备测试\r\n│\r\n└─ 响应式测试\r\n    ├─ Chrome DevTools：设备模拟\r\n    ├─ Responsinator：响应式检查\r\n    └─ Am I Responsive：响应式检查\r\n```\r\n\r\n## 专项测试检查清单\r\n\r\n### 性能测试检查\r\n- [ ] 测试场景设计？\r\n- [ ] 性能指标定义？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试环境准备？\r\n- [ ] 监控工具配置？\r\n- [ ] 结果分析报告？\r\n\r\n### 安全测试检查\r\n- [ ] 测试范围确定？\r\n- [ ] 测试工具准备？\r\n- [ ] OWASP Top 10覆盖？\r\n- [ ] 渗透测试执行？\r\n- [ ] 漏洞报告输出？\r\n- [ ] 修复验证完成？\r\n\r\n### 兼容性测试检查\r\n- [ ] 浏览器范围确定？\r\n- [ ] 设备范围确定？\r\n- [ ] 测试矩阵设计？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试执行完成？\r\n- [ ] 问题报告输出？\r\n\r\n## Examples\r\n\r\n**用户说\"测一下这个接口的性能\"**\r\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\r\n\r\n**用户说\"做个安全测试\"**\r\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\r\n\r\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\r\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\r\n\r\n## Guidelines\r\n\r\n专项测试完成后检查：\r\n- [ ] 测试类型是否明确？\r\n- [ ] 测试工具是否选择？\r\n- [ ] 测试环境是否准备？\r\n- [ ] 测试执行是否完成？\r\n- [ ] 结果分析是否深入？\r\n- [ ] 报告输出是否规范？\n\nFile v1.4.1:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.4.1\",\n  \"publishedAt\": 1782406596070\n}\n\nFile v1.4.1:skill-card.md\n\n## Description: <br>\nProvides specialized QA testing guidance for performance, security, and compatibility testing, including test design, tool selection, metrics, and checklists. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[kokxi](https://clawhub.ai/user/kokxi) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nQA engineers and developers use this skill to plan targeted performance, security, and compatibility testing after core functional coverage is defined. It helps choose test types, tools, metrics, and checklists while keeping security testing within authorized scope. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Security-testing guidance may be misapplied to systems without authorization or outside the approved target scope. <br>\nMitigation: Confirm written authorization, define the target scope and environment, and keep penetration-testing or SQL-injection activity within approved boundaries. <br>\nRisk: Performance or security tools can affect production availability when run against live systems. <br>\nMitigation: Use an isolated test environment unless production testing is explicitly approved, and set test intensity and timing to avoid business disruption. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/kokxi/skills/qa-specialized-testing) <br>\n- [Publisher profile](https://clawhub.ai/user/kokxi) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Shell commands, Configuration] <br>\n**Output Format:** [Markdown guidance with checklists and command-oriented testing recommendations] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Focuses on performance, security, and compatibility testing plans and result summaries.] <br>\n\n## Skill Version(s): <br>\n1.4.1 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.4.0: 3 files, 4452 bytes\n\nFiles: skill-card.md (1708b), SKILL.md (8142b), _meta.json (141b)\n\nFile v1.4.0:SKILL.md\n\n---\r\nname: qa-specialized-testing\r\ndescription: >-\r\n  专项测试能力，覆盖性能测试、安全测试、兼容性测试等专项领域的方法和要点。当用户需要进行性能测试、安全测试、兼容性测试或其他专项测试时自动触发。\r\n  也适用于：功能测试完成后需要补充专项测试，或满足特定非功能需求时。\r\n   关键词：性能测试、安全测试、兼容性测试、专项测试、压力测试、负载测试、渗透测试、SQL注入、XSS、跨浏览器测试、响应式测试、测试工具选型。\nwhen_to_use: 用户说\"性能测试\"、\"安全测试\"、\"兼容性测试\"、\"专项测试\"、\"压力测试\"、\"渗透测试\"、\"SQL注入\"、\"跨浏览器\"、需要进行专项测试、功能测试完成后需要补充专项测试时\r\nallowed-tools: Read Grep Glob Bash\r\nrelated_skills:\r\n  upstream:\r\n    - qa-risk-intuition          # 输入：风险评估识别专项测试需求\r\n    - qa-test-strategy-design    # 输入：测试策略确定专项测试范围\r\n  downstream:\r\n    - qa-release-risk-governance # 输出：专项测试结果用于发布评估\r\ninput_format: 风险评估 + 测试策略\r\noutput_format: 专项测试方案（性能/安全/兼容性测试设计和结果）\r\n---\r\n\r\n# 专项测试能力\r\n\r\n## Overview\r\n\r\n你是一位专项测试专家，擅长性能、安全、兼容性等专项测试。\r\n**核心原则**：专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\r\n本技能覆盖性能、安全、兼容性三类专项测试的方法、工具和检查清单。\r\n\r\n## 维度1：性能测试\r\n\r\n### 性能测试类型\r\n\r\n```\r\n├─ 负载测试（Load Testing）\r\n│   ├─ 目标：验证系统在预期负载下的表现\r\n│   ├─ 方法：逐步增加并发，观察性能指标\r\n│   └─ 指标：响应时间、吞吐量、错误率\r\n│\r\n├─ 压力测试（Stress Testing）\r\n│   ├─ 目标：验证系统在极限负载下的表现\r\n│   ├─ 方法：持续增加并发直到系统崩溃\r\n│   └─ 指标：系统极限、崩溃点、恢复能力\r\n│\r\n├─ 稳定性测试（Soak Testing）\r\n│   ├─ 目标：验证系统长时间运行的稳定性\r\n│   ├─ 方法：持续运行24-72小时\r\n│   └─ 指标：内存泄漏、资源消耗、性能退化\r\n│\r\n└─ 尖峰测试（Spike Testing）\r\n    ├─ 目标：验证系统应对突发流量的能力\r\n    ├─ 方法：突然增加并发\r\n    └─ 指标：系统响应、恢复时间、数据一致性\r\n```\r\n\r\n### 性能指标\r\n\r\n```\r\n核心指标：\r\n├─ 响应时间（Response Time）\r\n│   ├─ P50：50%请求的响应时间\r\n│   ├─ P95：95%请求的响应时间\r\n│   ├─ P99：99%请求的响应时间\r\n│   └─ 目标：P99 < 1秒\r\n│\r\n├─ 吞吐量（Throughput）\r\n│   ├─ TPS：每秒事务数\r\n│   ├─ QPS：每秒查询数\r\n│   └─ 目标：根据业务定义\r\n│\r\n├─ 错误率（Error Rate）\r\n│   ├─ 计算：错误请求数 / 总请求数\r\n│   └─ 目标：< 0.1%\r\n│\r\n└─ 资源使用率\r\n    ├─ CPU使用率：< 80%\r\n    ├─ 内存使用率：< 80%\r\n    ├─ 磁盘IO：< 80%\r\n    └─ 网络IO：< 80%\r\n```\r\n\r\n### 性能测试工具\r\n\r\n```\r\n├─ JMeter\r\n│   ├─ 优点：功能全面、插件丰富\r\n│   ├─ 缺点：界面复杂、资源消耗大\r\n│   └─ 适用：复杂场景、协议测试\r\n│\r\n├─ Locust\r\n│   ├─ 优点：代码化、分布式\r\n│   ├─ 缺点：需要编程能力\r\n│   └─ 适用：API测试、分布式测试\r\n│\r\n├─ k6\r\n│   ├─ 优点：现代化、CI友好\r\n│   ├─ 缺点：社区较小\r\n│   └─ 适用：现代应用、DevOps\r\n│\r\n└─ wrk\r\n    ├─ 优点：轻量、高效\r\n    ├─ 缺点：功能简单\r\n    └─ 适用：简单压测、快速验证\r\n```\r\n\r\n## 维度2：安全测试\r\n\r\n### 安全测试类型\r\n\r\n```\r\n├─ OWASP Top 10\r\n│   ├─ 注入攻击（Injection）\r\n│   ├─ 失效的身份认证（Broken Authentication）\r\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\r\n│   ├─ XML外部实体（XXE）\r\n│   ├─ 失效的访问控制（Broken Access Control）\r\n│   ├─ 安全配置错误（Security Misconfiguration）\r\n│   ├─ 跨站脚本（XSS）\r\n│   ├─ 不安全的反序列化（Insecure Deserialization）\r\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\r\n│   └─ 不足的日志和监控（Insufficient Logging）\r\n│\r\n├─ 渗透测试\r\n│   ├─ 信息收集：域名、IP、端口\r\n│   ├─ 漏洞扫描：自动化扫描\r\n│   ├─ 漏洞利用：手动验证\r\n│   └─ 报告输出：漏洞报告\r\n│\r\n└─ 代码审计\r\n    ├─ 静态分析：代码扫描\r\n    ├─ 动态分析：运行时检测\r\n    └─ 人工审计：代码Review\r\n```\r\n\r\n### 安全测试工具\r\n\r\n```\r\n├─ Burp Suite\r\n│   ├─ 用途：Web应用渗透测试\r\n│   ├─ 功能：代理、扫描、爬虫、爆破\r\n│   └─ 适用：Web安全测试\r\n│\r\n├─ OWASP ZAP\r\n│   ├─ 用途：Web应用安全扫描\r\n│   ├─ 功能：自动扫描、手动测试\r\n│   └─ 适用：自动化安全测试\r\n│\r\n├─ SQLMap\r\n│   ├─ 用途：SQL注入测试\r\n│   ├─ 功能：自动检测、利用SQL注入\r\n│   └─ 适用：SQL注入测试\r\n│\r\n└─ Nmap\r\n    ├─ 用途：网络扫描\r\n    ├─ 功能：端口扫描、服务识别\r\n    └─ 适用：信息收集\r\n```\r\n\r\n## 维度3：兼容性测试\r\n\r\n### 兼容性测试维度\r\n\r\n```\r\n├─ 浏览器兼容\r\n│   ├─ Chrome\r\n│   ├─ Firefox\r\n│   ├─ Safari\r\n│   ├─ Edge\r\n│   └─ IE（如需要）\r\n│\r\n├─ 设备兼容\r\n│   ├─ PC\r\n│   ├─ 手机（iOS/Android）\r\n│   ├─ 平板\r\n│   └─ 不同分辨率\r\n│\r\n├─ 系统兼容\r\n│   ├─ Windows\r\n│   ├─ macOS\r\n│   ├─ Linux\r\n│   └─ 不同版本\r\n│\r\n└─ 网络兼容\r\n    ├─ WiFi\r\n    ├─ 4G/5G\r\n    ├─ 弱网\r\n    └─ 离线\r\n```\r\n\r\n### 兼容性测试工具\r\n\r\n```\r\n├─ 浏览器测试\r\n│   ├─ BrowserStack：云端真机测试\r\n│   ├─ Sauce Labs：云端测试平台\r\n│   ├─ LambdaTest：跨浏览器测试\r\n│   └─ Can I Use：兼容性查询\r\n│\r\n├─ 移动端测试\r\n│   ├─ Appium：移动端自动化\r\n│   ├─ XCTest/Espresso：原生测试\r\n│   └─ 真机测试：实际设备测试\r\n│\r\n└─ 响应式测试\r\n    ├─ Chrome DevTools：设备模拟\r\n    ├─ Responsinator：响应式检查\r\n    └─ Am I Responsive：响应式检查\r\n```\r\n\r\n## 专项测试检查清单\r\n\r\n### 性能测试检查\r\n- [ ] 测试场景设计？\r\n- [ ] 性能指标定义？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试环境准备？\r\n- [ ] 监控工具配置？\r\n- [ ] 结果分析报告？\r\n\r\n### 安全测试检查\r\n- [ ] 测试范围确定？\r\n- [ ] 测试工具准备？\r\n- [ ] OWASP Top 10覆盖？\r\n- [ ] 渗透测试执行？\r\n- [ ] 漏洞报告输出？\r\n- [ ] 修复验证完成？\r\n\r\n### 兼容性测试检查\r\n- [ ] 浏览器范围确定？\r\n- [ ] 设备范围确定？\r\n- [ ] 测试矩阵设计？\r\n- [ ] 测试工具选择？\r\n- [ ] 测试执行完成？\r\n- [ ] 问题报告输出？\r\n\r\n## Examples\r\n\r\n**用户说\"测一下这个接口的性能\"**\r\n→ 性能测试：确定测试类型（负载/压力/稳定性）→选择工具（JMeter/Locust）→定义指标（TPS/响应时间/错误率）→执行→分析瓶颈\r\n\r\n**用户说\"做个安全测试\"**\r\n→ 安全测试：OWASP Top10逐项扫描→SQL注入/XSS/CSRF→认证绕过测试→授权越权测试\r\n\r\n**兼容性测试需求：用户说\"网站要在Chrome和Safari上都能用\"**\r\n→ 确定浏览器矩阵→功能回归→渲染检查→交互测试\r\n\r\n## Guidelines\r\n\r\n专项测试完成后检查：\r\n- [ ] 测试类型是否明确？\r\n- [ ] 测试工具是否选择？\r\n- [ ] 测试环境是否准备？\r\n- [ ] 测试执行是否完成？\r\n- [ ] 结果分析是否深入？\r\n- [ ] 报告输出是否规范？\n\nFile v1.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.4.0\",\n  \"publishedAt\": 1782277933563\n}\n\nFile v1.4.0:skill-card.md\n\n## Description: <br>\nGuides agents through specialized QA testing for performance, security, and compatibility scenarios, including method selection, tool choice, checklists, and result reporting. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[kokxi](https://clawhub.ai/user/kokxi) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nQA engineers and software teams use this skill to plan specialized performance, security, and compatibility testing after functional coverage or when non-functional requirements need validation. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can steer agents toward intrusive security or performance testing without clear authorization or scope. <br>\nMitigation: Require a defined target, scope, environment, and consent before running Bash commands or performing security or performance tests. <br>\n\n\n## Reference(s): <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Shell commands] <br>\n**Output Format:** [Markdown or structured text testing plans, checklists, and result summaries] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include tool recommendations and scoped test checklists for performance, security, and compatibility testing.] <br>\n\n## Skill Version(s): <br>\n1.4.0 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: qa-specialized-testing Owner: kokxi Summary: 当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。 触发场景：性能测试、安全测试（专项）、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security test","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"├─ OWASP Top 10\n│   ├─ 注入攻击（Injection）\n│   ├─ 失效的身份认证（Broken Authentication）\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\n│   ├─ XML外部实体（XXE）\n│   ├─ 失效的访问控制（Broken Access Control）\n│   ├─ 安全配置错误（Security Misconfiguration）\n│   ├─ 跨站脚本（XSS）\n│   ├─ 不安全的反序列化（Insecure Deserialization）\n│   ├─ 使用含有已知漏洞的组件（Vulnerable Components）\n│   └─ 不足的日志和监控（Insufficient Logging）\n│\n├─ 渗透测试\n│   ├─ 信息收集：域名、IP、端口\n│   ├─ 漏洞扫描：自动化扫描\n│   ├─ 漏洞利用：手动验证\n│   └─ 报告输出：漏洞报告\n│\n└─ 代码审计\n    ├─ 静态分析：代码扫描\n    ├─ 动态分析：运行时检测\n    └─ 人工审计：代码Review"},{"language":"text","snippet":"├─ Burp Suite\n│   ├─ 用途：Web应用渗透测试\n│   ├─ 功能：代理、扫描、爬虫、爆破\n│   └─ 适用：Web安全测试\n│\n├─ OWASP ZAP\n│   ├─ 用途：Web应用安全扫描\n│   ├─ 功能：自动扫描、手动测试\n│   └─ 适用：自动化安全测试\n│\n├─ SQLMap\n│   ├─ 用途：SQL注入测试\n│   ├─ 功能：自动检测、利用SQL注入\n│   └─ 适用：SQL注入测试\n│\n└─ Nmap\n    ├─ 用途：网络扫描\n    ├─ 功能：端口扫描、服务识别\n    └─ 适用：信息收集"},{"language":"text","snippet":"├─ 浏览器兼容\n│   ├─ Chrome\n│   ├─ Firefox\n│   ├─ Safari\n│   ├─ Edge\n│   └─ IE（如需要）\n│\n├─ 设备兼容\n│   ├─ PC\n│   ├─ 手机（iOS/Android）\n│   ├─ 平板\n│   └─ 不同分辨率\n│\n├─ 系统兼容\n│   ├─ Windows\n│   ├─ macOS\n│   ├─ Linux\n│   └─ 不同版本\n│\n└─ 网络兼容\n    ├─ WiFi\n    ├─ 4G/5G\n    ├─ 弱网\n    └─ 离线"},{"language":"text","snippet":"├─ 浏览器测试\n│   ├─ BrowserStack：云端真机测试\n│   ├─ Sauce Labs：云端测试平台\n│   ├─ LambdaTest：跨浏览器测试\n│   └─ Can I Use：兼容性查询\n│\n├─ 移动端测试\n│   ├─ Appium：移动端自动化\n│   ├─ XCTest/Espresso：原生测试\n│   └─ 真机测试：实际设备测试\n│\n└─ 响应式测试\n    ├─ Chrome DevTools：设备模拟\n    ├─ Responsinator：响应式检查\n    └─ Am I Responsive：响应式检查"},{"language":"text","snippet":"├─ 负载测试（Load Testing）\n│   ├─ 目标：验证系统在预期负载下的表现\n│   ├─ 方法：逐步增加并发，观察性能指标\n│   └─ 指标：响应时间、吞吐量、错误率\n│\n├─ 压力测试（Stress Testing）\n│   ├─ 目标：验证系统在极限负载下的表现\n│   ├─ 方法：持续增加并发直到系统崩溃\n│   └─ 指标：系统极限、崩溃点、恢复能力\n│\n├─ 稳定性测试（Soak Testing）\n│   ├─ 目标：验证系统长时间运行的稳定性\n│   ├─ 方法：持续运行24-72小时\n│   └─ 指标：内存泄漏、资源消耗、性能退化\n│\n└─ 尖峰测试（Spike Testing）\n    ├─ 目标：验证系统应对突发流量的能力\n    ├─ 方法：突然增加并发\n    └─ 指标：系统响应、恢复时间、数据一致性"},{"language":"text","snippet":"核心指标：\n├─ 响应时间（Response Time）\n│   ├─ P50：50%请求的响应时间\n│   ├─ P95：95%请求的响应时间\n│   ├─ P99：99%请求的响应时间\n│   └─ 目标：P99 < 1秒\n│\n├─ 吞吐量（Throughput）\n│   ├─ TPS：每秒事务数\n│   ├─ QPS：每秒查询数\n│   └─ 目标：根据业务定义\n│\n├─ 错误率（Error Rate）\n│   ├─ 计算：错误请求数 / 总请求数\n│   └─ 目标：< 0.1%\n│\n└─ 资源使用率\n    ├─ CPU使用率：< 80%\n    ├─ 内存使用率：< 80%\n    ├─ 磁盘IO：< 80%\n    └─ 网络IO：< 80%"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: qa-specialized-testing\ndescription: >-\n  当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。 触发场景：性能测试、安全测试（专项）、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security testing, and cross-browser compatibility.\nlicense: MIT\nallowed-tools: Read Grep Glob Bash\nmetadata:\n  display-name: \"Specialized Testing\"\n  version: \"1.8.0\"\n  when-to-use: \"用户说\\\"性能测试\\\"、\\\"安全测试（专项）\\\"、\\\"兼容性测试\\\"、\\\"专项测试\\\"、\\\"压力测试\\\"、\\\"渗透测试\\\"、\\\"SQL注入测试\\\"、\\\"跨浏览器测试\\\"、需要进行专项测试、功能测试完成后需要补充专项测试时\"\n  related-skills: \"{\\\"upstream\\\":[\\\"qa-risk-intuition\\\",\\\"qa-test-strategy-design\\\"],\\\"downstream\\\":[\\\"qa-release-risk-governance\\\",\\\"qa-agent-testing\\\",\\\"qa-mobile-testing\\\"]}\"\n  references: \"[\\\"references/performance-depth.md\\\"]\"\n  input-format: \"{\\\"required\\\":[{\\\"name\\\":\\\"测试策略\\\",\\\"type\\\":\\\"object\\\",\\\"description\\\":\\\"来自qa-test-strategy-design的测试策略\\\"},{\\\"name\\\":\\\"专项需求\\\",\\\"type\\\":\\\"string\\\",\\\"description\\\":\\\"性能/安全/兼容性等专项测试需求\\\"}],\\\"optional\\\":[{\\\"name\\\":\\\"环境信息\\\",\\\"type\\\":\\\"string\\\",\\\"description\\\":\\\"专项测试环境配置\\\"}]}\"\n  output-format: \"{\\\"traceability\\\":[\\\"每个专项测试用例带唯一ID（TC_{模块缩写}_{功能缩写}_{序号}，如 TC_API_LOGIN_001）\\\",\\\"关联专项类型和需求ID\\\"],\\\"structure\\\":[\\\"覆盖率：标注口径（基于现有需求/输入文档），禁止\\\\\\\"全覆盖/100%\\\\\\\"绝对化表述；缺失模块标注\\\\\\\"未覆盖+原因\\\\\\\"\\\",{\\\"specialized_test_plan\\\":\\\"专项测试方案\\\"},{\\\"performance_cases\\\":\\\"性能测试场景\\\"},{\\\"security_cases\\\":\\\"安全测试用例\\\"},{\\\"compatibility_matrix\\\":\\\"兼容性矩阵\\\"}]}\"\n  error-recovery-guidance: \"{\\\"on_failure\\\":\\\"专项测试遗漏维度时回退到测试策略补充范围\\\",\\\"retry_behavior\\\":\\\"补全范围后重新执行专项测试\\\"}\"\n  categories: \"[\\\"Development\\\",\\\"Testing\\\"]\"\n  depth-requirement: \"{\\\"reference_value\\\":\\\"根据专项类型调整测试深度：简单×1/中等×2/复杂×3\\\",\\\"minimum\\\":\\\"至少完成性能、安全、兼容性3类专项中的2类\\\"}\"\n---\n> ⚠️ 本技能单独使用效果有限，建议配合完整技能集（12 步工作流）使用。安装：npx skills add Kokxi/qa-test-skills\n\n# 专项测试能力\n\n## 核心原则\n\n专项测试不只是会用工具，而是知道测什么、怎么测、测到什么程度算够。\n\n## 深度要求（参考值）\n\n**关键指标**：根据系统复杂度调整专项测试深度\n\n| 复杂度 | 维度覆盖要求 | 每维度测试点 | 说明 |\n|--------|------------|------------|------|\n| 简单系统 | 至少2个维度 | 5-8个/维度 | 内部系统/低风险 |\n| 中等系统 | 全部3个维度 | 10-15个/维度 | 业务系统/中等风险 |\n| 复杂系统 | 全部3个维度+深度测试 | 20-30个/维度 | 核心系统/高风险 |\n\n**适用范围**：本技能仅在你明确要求某个专项测试方向（如性能/安全/兼容性）且已确认测试目标和环境授权时激活。安全测试相关内容必须配合授权声明使用，不得在未获授权的系统上执行。\n\n## 加载时机\n\n| 什么时候读 | 读哪个 |\n|-----------|--------|\n| 做性能测试专项时 | [`references/performance-depth.md`](references/performance-depth.md) |\n\n> `维度1：性能测试`的完整内容已下沉至 `references/performance-depth.md`，避免每次触发都占用上下文。\n\n## 维度2：安全测试\n\n> ⚠️ **授权与法律声明**：安全测试（尤其是渗透测试）必须获得系统所有者的明确书面授权。\n> 执行前必须确认：\n> 1. 测试目标属于你或已获得明确授权\n> 2. 清楚界定测试范围、目标环境和边界（严禁超出授权范围）\n> 3. 了解并遵守当地网络安全相关法律法规\n> 4. 测试活动不会对业务系统造成影响（建议使用独立测试环境）\n> 5. 使用攻击性工具（Burp Suite/SQLMap 等）仅限于你拥有或明确获授权的系统\n\n### 安全测试类型\n\n```text\n├─ OWASP Top 10\n│   ├─ 注入攻击（Injection）\n│   ├─ 失效的身份认证（Broken Authentication）\n│   ├─ 敏感数据暴露（Sensitive Data Exposure）\n│   ├─ XML外部实体（XXE）\n│   ├─ 失效的访问控制（Broken Access Control）\n│   ├─ 安全配置错误（Security Misconfiguration）\n│   ├─ 跨站脚本（XSS）\n│   ├─ 不安"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71y9b23csfx0ykgm55d5m9x5891zt8\",\n  \"slug\": \"qa-specialized-testing\",\n  \"version\": \"1.8.0\",\n  \"publishedAt\": 1790656105679\n}"},{"path":"references/performance-depth.md","content":"# 性能测试维度详解\n\n> 本文是 `qa-specialized-testing` 的**性能测试维度详解**。做性能测试专项时读本文；\n其余部分留在 SKILL.md，不必读本文。\n\n---\n\n\n### 性能测试类型\n\n```text\n├─ 负载测试（Load Testing）\n│   ├─ 目标：验证系统在预期负载下的表现\n│   ├─ 方法：逐步增加并发，观察性能指标\n│   └─ 指标：响应时间、吞吐量、错误率\n│\n├─ 压力测试（Stress Testing）\n│   ├─ 目标：验证系统在极限负载下的表现\n│   ├─ 方法：持续增加并发直到系统崩溃\n│   └─ 指标：系统极限、崩溃点、恢复能力\n│\n├─ 稳定性测试（Soak Testing）\n│   ├─ 目标：验证系统长时间运行的稳定性\n│   ├─ 方法：持续运行24-72小时\n│   └─ 指标：内存泄漏、资源消耗、性能退化\n│\n└─ 尖峰测试（Spike Testing）\n    ├─ 目标：验证系统应对突发流量的能力\n    ├─ 方法：突然增加并发\n    └─ 指标：系统响应、恢复时间、数据一致性\n```\n\n### 性能指标\n\n```text\n核心指标：\n├─ 响应时间（Response Time）\n│   ├─ P50：50%请求的响应时间\n│   ├─ P95：95%请求的响应时间\n│   ├─ P99：99%请求的响应时间\n│   └─ 目标：P99 < 1秒\n│\n├─ 吞吐量（Throughput）\n│   ├─ TPS：每秒事务数\n│   ├─ QPS：每秒查询数\n│   └─ 目标：根据业务定义\n│\n├─ 错误率（Error Rate）\n│   ├─ 计算：错误请求数 / 总请求数\n│   └─ 目标：< 0.1%\n│\n└─ 资源使用率\n    ├─ CPU使用率：< 80%\n    ├─ 内存使用率：< 80%\n    ├─ 磁盘IO：< 80%\n    └─ 网络IO：< 80%\n```\n\n### 性能测试工具\n\n```text\n├─ JMeter\n│   ├─ 优点：功能全面、插件丰富\n│   ├─ 缺点：界面复杂、资源消耗大\n│   └─ 适用：复杂场景、协议测试\n│\n├─ Locust\n│   ├─ 优点：代码化、分布式\n│   ├─ 缺点：需要编程能力\n│   └─ 适用：API测试、分布式测试\n│\n├─ k6\n│   ├─ 优点：现代化、CI友好\n│   ├─ 缺点：社区较小\n│   └─ 适用：现代应用、DevOps\n│\n└─ wrk\n    ├─ 优点：轻量、高效\n    ├─ 缺点：功能简单\n    └─ 适用：简单压测、快速验证\n```"},{"path":"skill-card.md","content":"## Description:\n\nGuides developers through performance, authorized security, and cross-browser compatibility testing after functional testing is complete.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[kokxi](https://clawhub.ai/user/kokxi)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and QA engineers use this skill to plan and assess performance, authorized security, and browser/device compatibility tests after functional testing, with traceable cases and coverage boundaries.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Security testing can affect systems outside the intended scope.\n\nMitigation: Require explicit authorization and a defined target, environment, and scope before testing.\n\nRisk: The optional installation command retrieves a third-party skill collection.\n\nMitigation: Run it only if you trust the source; it is not required to use this guidance.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/kokxi/skills/qa-specialized-testing)\n- [Performance testing reference](references/performance-depth.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Guidance]\n\n**Output Format:** [Markdown test plans, cases, and matrices]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Traceable test case IDs, performance baselines, security cases, compatibility matrices, and explicit coverage gaps.]\n\n## Skill Version(s):\n\n1.8.0 (source: skill frontmatter and server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。 触发场景：性能测试、安全测试（专项）、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security testing, and cross-browser compatibility. Skill: qa-specialized-testing Owner: kokxi Summary: 当功能测试做完之后需要做进一步的质量验证时使用此技能。覆盖性能测试（负载/压力/稳定性）、安全测试（OWASP Top 10 TOP 漏洞）、兼容性测试（多浏览器/多设备）的测试方法。不要在功能测试还没做完时就做专项——先保证功能正确，再评估性能和安全。专项测试的产出是一组可复用的测试方案（性能指标基线、安全渗透用例、兼容性矩阵）。 触发场景：性能测试、安全测试（专项）、兼容性测试、专项测试、压力测试、渗透测试、SQL注入测试、跨浏览器测试、功能测试完成后需要补充专项测试时。 Use when the user asks about: specialized non-functional testing — performance and load and stress testing, OWASP security test","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1060,"uniquenessScore":50,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T01:49:04.825Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T01:49:04.825Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:54:30.721Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}