Securely manage passwords and sensitive data in your tests
npx skills add https://github.com/testdriverai/testdriverai --skill testdriver:secrets
<!-- Generated from secrets.mdx. DO NOT EDIT. -->
Protect sensitive information like passwords, API keys, and tokens in your TestDriver tests.
When typing sensitive information like passwords, use the secret: true option to prevent the value from being logged or stored:
import { test } from 'vitest';
import { chrome } from 'testdriverai/presets';
test('login with secure password', async (context) => {
const { testdriver } = await chrome(context, {
url: 'https://myapp.com/login'
});
await testdriver.find('email input').click();
await testdriver.type(process.env.TD_USERNAME);
await testdriver.find('password input').click();
// Password is masked in logs and recordings
await testdriver.type(process.env.TD_PASSWORD, { secret: true });
await testdriver.find('login button').click();
await testdriver.assert('dashboard is visible');
});
<Note>
When secret: true is set, the typed text appears as in all logs, recordings, and dashcam output.
</Note>
Store sensitive credentials as GitHub repository secrets so they're never exposed in your code:
<Steps>
<Step title="Navigate to Repository Settings">
Go to your GitHub repository → Settings → Secrets and variables → Actions
</Step>
<Step title="Add Repository Secrets">
Click New repository secret and add your secrets:
TD_API_KEY - Your TestDriver API keyTD_USERNAME - Test account usernameTD_PASSWORD - Test account password</Step>
<Step title="Use in GitHub Actions">
Reference secrets in your workflow file:
- name: Run TestDriver tests
env:
TD_API_KEY: ${{ secrets.TD_API_KEY }}
TD_USERNAME: ${{ secrets.TD_USERNAME }}
TD_PASSWORD: ${{ secrets.TD_PASSWORD }}
run: vitest run
</Step>
</Steps>
For local development, store secrets in a .env file:
TD_API_KEY=your_api_key_here
[email protected]
TD_PASSWORD=your_secure_password
<Warning>
Never commit .env files to version control. Add .env to your .gitignore file.
</Warning>
Here's a full login test with proper secrets handling:
import { test, expect } from 'vitest';
import { chrome } from 'testdriverai/presets';
test('secure login flow', async (context) => {
const { testdriver } = await chrome(context, {
url: process.env.TD_WEBSITE || 'https://staging.myapp.com'
});
// Enter username (not sensitive)
await testdriver.find('email input').click();
await testdriver.type(process.env.TD_USERNAME);
// Enter password securely
await testdriver.find('password input').click();
await testdriver.type(process.env.TD_PASSWORD, { secret: true });
// Submit login
await testdriver.find('login button').click();
// Verify successful login
const loggedIn = await testdriver.assert('user is logged in');
expect(loggedIn).toBeTruthy();
});
<Card title="Secrets Best Practices" icon="shield-check">
secret: true when typing passwords, tokens, or sensitive data</Card>
Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs.
Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup
Use when implementing any feature or bugfix, before writing implementation code
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes
Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and confirming output before making any success claims; evidence before assertions always
Expert guidance for systematic backtesting of trading strategies. Use when developing, testing, stress-testing, or validating quantitative trading strategies. Covers "beating ideas to death" methodology, parameter robustness testing, slippage modeling, bias prevention, and interpreting backtest results. Applicable when user asks about backtesting, strategy validation, robustness testing, avoiding overfitting, or systematic trading development.
Cloud laboratory platform for automated protein testing and validation. Use when designing proteins and needing experimental validation including binding assays, expression testing, thermostability measurements, enzyme activity assays, or protein sequence optimization. Also use for submitting experiments via API, tracking experiment status, downloading results, optimizing protein sequences for better expression using computational tools (NetSolP, SoluProt, SolubleMPNN, ESM), or managing protein design workflows with wet-lab validation.
This skill should be used for time series machine learning tasks including classification, regression, clustering, forecasting, anomaly detection, segmentation, and similarity search. Use when working with temporal data, sequential patterns, or time-indexed observations requiring specialized algorithms beyond standard ML approaches. Particularly suited for univariate and multivariate time series analysis with scikit-learn compatible APIs.
Take testdriverai/testdriver:secrets from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.