Skip to content
Back to skills

Verify

ASecurity

Drive Houston's TS host + web UI end-to-end to verify a change against the running system (host HTTP battery + Playwright Files/board flows).

  • 117 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
testinggobashreactnode

Security analysis

A96/100
  • mediumUses curl or wget to download content

Pro shows the line behind each finding and how to fix it

Scanned September 19, 2026

npx -y skills add gethouston/houston --skill verify --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Verify?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Verify
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gethouston-verify/badge)](https://www.skillsdirectory.com/skills/gethouston-verify)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: verify
description: Drive Houston's TS host + web UI end-to-end to verify a change against the running system (host HTTP battery + Playwright Files/board flows).
---

# Verifying Houston changes at runtime

## TS host (the real desktop sidecar), hermetically

```bash
mkdir -p /tmp/hh/workspaces/Personal/"Agent 1"
HOUSTON_HOME=/tmp/hh HOUSTON_HOST_PORT=48123 HOUSTON_HOST_TOKEN=t \
  node --import tsx packages/host/src/local/main.ts
# wait for {"status":"ok"}:
curl -s http://127.0.0.1:48123/health
```

- Auth: `Authorization: Bearer t`. Agent ids are `<Workspace>/<Agent>` —
  URL-encode the slash (`/agents/Personal%2FAgent%201/files`).
- SSE reactivity feed: `curl -N 'http://127.0.0.1:48123/v1/events?token=t'`.
- The runtime is only spawned for chat turns; files/agents routes need no
  provider credentials.

## Web UI (the same React tree the desktop ships)

Playwright + the fake host (`@houston/fake-host`), all boot handled by the
harness:

```bash
pnpm --filter houston-web test:e2e             # whole suite
cd packages/web && npx playwright test e2e/files.spec.ts --reporter=line
```

- Specs live in `packages/web/e2e/`; fixtures reset the fake host per test.
- One-off screenshots: drop a temp spec in `e2e/`, `page.screenshot(...)`,
  delete it after (testDir is pinned to `e2e/`).
- Gotchas: controlled inputs never match `input[value=…]` (use
  `getByRole("textbox")`); headless Chromium names blob downloads with a GUID —
  assert downloaded bytes, not `suggestedFilename()`.

## Gates (CI-equivalent, not a substitute for the above)

`pnpm check` · `pnpm typecheck` (ui+app+web) · `pnpm --filter @houston/host test`
· `cd app && pnpm check-locales` · `pnpm check:boundaries`

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…