Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Quality-Max/free-qa-skills --skill form-validation-scangit clone --depth 1 https://github.com/Quality-Max/free-qa-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/quality-max/free-qa-skills/form-validation-scan)<a href="https://agentmods.dev/skills/quality-max/free-qa-skills/form-validation-scan"><img src="https://agentmods.dev/badge/skills/quality-max/free-qa-skills/form-validation-scan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/quality-max/free-qa-skills/form-validation-scan"><img src="https://agentmods.dev/badge/skills/quality-max/free-qa-skills/form-validation-scan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00047 | $0.00698 |
| Opus 5 | $0.00023 | $0.00349 |
| Sonnet 5 | $0.00009 | $0.00140 |
| Haiku 4.5 | $0.00005 | $0.00070 |
Grade A, and why
form-validation-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 79 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Form Validation Scan
Find out if your forms accept garbage. No signup required.
Prerequisites
- Playwright MCP (comes with Claude Code)
Trigger
- "Scan my forms for validation gaps"
- "Do my forms validate input?"
- "Form validation audit https://..."
Workflow
- Navigate to the URL using
mcp__playwright__browser_navigate. - Inventory the forms and fields with
mcp__playwright__browser_evaluate:
() => [...document.forms].map(f => ({
id: f.id || f.name || '(unnamed)',
action: f.action,
fields: [...f.elements].filter(e => e.name).map(e => ({
name: e.name, type: e.type, required: e.required,
pattern: e.pattern || null, maxLength: e.maxLength,
})),
}))
- For one representative form, probe behavior with
mcp__playwright__browser_fill_form+mcp__playwright__browser_clickon submit. Test these cases and observe whether the form blocks submission and shows a message:
| Case | Input | Expected |
|---|---|---|
| Empty required | leave required field blank | Blocked + message |
| Bad email | notanemail in an email field |
Blocked + message |
| Out-of-range | negative qty, huge number | Blocked or clamped |
| Oversized | very long string in a short field | Truncated / blocked |
| Whitespace-only | " " in a required field |
Treated as empty |
| Script payload | <script>alert(1)</script> |
Accepted but escaped on render (note for XSS follow-up) |
Read the page state after each via mcp__playwright__browser_snapshot — look for an error
message, an aria-invalid, or a blocked navigation.
- Output:
## Form Validation Scan: [URL]
**Form: "signup" — 3 gaps**
| Field | Required enforced | Format checked | Error shown | Verdict |
|----------|-------------------|----------------|-------------|---------|
| email | yes | NO | no | Accepts "abc" as email |
| password | yes | yes (min 8) | yes | ok |
| age | no | NO | no | Accepts -5 and 9999 |
### Findings
1. `email` — no format validation; `notanemail` submits. Add `type=email` + server check.
2. `age` — accepts negative and absurd values; add `min`/`max` + server validation.
3. Submitting empty `email` shows no inline error — fails silently.
### Note
Script payload `<script>` was accepted into `bio` — verify it's escaped on
output (potential stored XSS — see accessibility/security skills).
**Want form validation tested on every deploy?** Try QualityMax — qualitymax.io
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 79 lines · 47 tokens per session scan A ead424498a90
form-validation-scan is a skill published in the GitHub repository Quality-Max/free-qa-skills (10 stars, last pushed 16d ago), licensed Apache-2.0. It adds 47 tokens to every session and 698 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
hatch3r-browser-verify
Opt-in browser verification skill — spec-run-first Playwright verification (assertions execute in the runner, agent reads only failures), axe-core a11y audits, toHaveScreenshot() regression diffs, E2E test scaffolds, and snapshot-mode exploratory driving. Default ON for UI-affecting agent invocations; disable globally…
playwright-cli
Automate browser interactions, test web pages and work with Playwright tests.
playwright-component-testing
Set up component testing with Playwright using a story gallery — scaffold stories and a gallery dev page driven by the built-in mount fixture, no dedicated component-testing runtime. Use when asked to test React or Vue components in isolation with Playwright, or to migrate off @playwright/experimental-ct-react / -vue.
playwright-trace
Inspect Playwright trace files from the command line — list actions, view requests, console, errors, snapshots and screenshots.
testing-e2e
End-to-end testing patterns with Playwright — page objects, AI agent testing, visual regression, accessibility testing with axe-core, and CI integration. Use when writing E2E tests, setting up Playwright, implementing visual regression, or testing accessibility.
Axe-core Accessibility Testing
Accessibility testing skill using axe-core and Playwright for automated WCAG 2.1 compliance auditing, custom rules, and accessibility reporting.