Skip to content
Back to skills

Sniff

ASecurity

Use when the user types /sniff, or asks to "scan this project for bugs", "find bugs in my app", "QA my site", or "walk my app and tell me what's broken". For a running web app, finds real, reproducible issues (broken pages/links, console & network errors, broken forms, empty/placeholder data, state-loss, bad loading/error states, responsive and accessibility problems), each with reproduction proof, severity, confidence, and a fix. No API key needed.

  • 211 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 21, 2026
testingapi

Works with

  • api
  • mcp

Security analysis

A100/100

Pro scans all 13 files and shows the line behind each finding

Scanned September 21, 2026

npx -y skills add NeverSight/skills_feed --skill sniff --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sniff?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Sniff
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/neversight-sniff/badge)](https://www.skillsdirectory.com/skills/neversight-sniff)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: sniff
description: Use when the user types /sniff, or asks to "scan this project for bugs", "find bugs in my app", "QA my site", or "walk my app and tell me what's broken". For a running web app, finds real, reproducible issues (broken pages/links, console & network errors, broken forms, empty/placeholder data, state-loss, bad loading/error states, responsive and accessibility problems), each with reproduction proof, severity, confidence, and a fix. No API key needed.
---

# /sniff: find real bugs in this project

## What to do

1. Call the unified `sniff` MCP tool with:
   - `mode`: `"walk"`, the autonomous flow-walk that drives a real browser and finds runtime bugs (this is the one that matters; `"scan"` is source-only)
   - `rootDir`: the current project's absolute path
   - omit `baseUrl` to auto-detect the running dev server, or pass it if the user gives a URL
2. If the response is `{ needsSetup: "playwright-browsers" }`, call the `sniff_install` tool, then retry the walk.
3. If no app is running, sniff returns a note + a source-only scan. Tell the user to start their dev server (or pass a URL) for the full flow-walk that finds the real runtime bugs.
4. Present findings grouped by severity (CRITICAL and HIGH first). For each, show the **route**, the **reproduction steps**, the **confidence** (confirmed / likely / uncertain), and the **suggested fix**. Mention any finding marked `needsOutOfBandVerification` (e.g. "submitted but no success shown, confirm the email/job actually ran"). Offer `/sniff-fix` for the safe, auto-fixable ones.

## Example

```
User: /sniff
You: Walking your running app for real bugs…

[calls sniff with mode="walk", rootDir=/Users/user/projects/my-app]

Found 9 real issues (0 false positives) across 12 pages:

**Critical (1)**
- /checkout: Page returns HTTP 500 (crash screen shown to the user)

**High (3)**
- /: Broken link → /pricing-old (HTTP 404)
- /dashboard: Uncaught exception: cannot read 'map' of undefined
- /signup: Submit button does nothing (no request, no message, no change)

**Medium (5)**
- /orders: Empty table with no empty-state ("Your Orders")
- /profile: Placeholder data shipped (test@test.com)
- …each with reproduction steps + a screenshot + a fix.

Want me to fix the safe ones with /sniff-fix?
```

Files in this skill

  • SKILL.md2.2 KB
  • description_ar.txt956 B
  • description_cn.txt527 B
  • description_de.txt606 B
  • description_en.txt454 B
  • description_es.txt691 B
  • description_fr.txt672 B
  • description_it.txt605 B
  • description_ja.txt802 B
  • description_ko.txt702 B
  • description_ru.txt1.2 KB
  • description_tw.txt600 B
  • stats.json68 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…