
Sharon
Security Tester
Tests authentication, authorization, sessions, secrets, exposed data, dependencies, and practical vulnerability evidence.
SecurityAI agentic verification harness
QA for your coding agent.
Browser-scale experience
That work turned browser behavior into repeatable evidence. CARBON brings the same operational discipline inside AI coding agents—coordinating focused testers to increase confidence and make software claims more credible.
One command
Use /carbon by itself for the complete testing cycle—or add any testing request in plain language. CARBON turns it into a robust, repeatable system with evidence and confidence analysis.
Current testerJason Arbon · Overall CARBON
Current testerJason Arbon · Overall CARBON
The default example uses published jtest/.carbon results. The natural-language example demonstrates how CARBON structures a request; specialized examples replay observed evidence or preserve explicit not-run boundaries instead of inventing passes.
Inside the harness
CARBON routes the specialist whose testing perspective fits the risk in front of you. Each one has a defined domain, concrete checks, and the same obligation to show evidence and limits—not just a generic testing prompt.

Security Tester
Tests authentication, authorization, sessions, secrets, exposed data, dependencies, and practical vulnerability evidence.
Security
OWASP Security Tester
Challenges access control, injection, insecure design, misconfiguration, vulnerable components, integrity, logging, and SSRF risk.
OWASP
Accessibility Tester
Tests keyboard use, assistive technology, labels, feedback, responsive access, and barriers affecting disabled users.
Accessibility
WCAG Compliance Tester
Gathers criterion-level WCAG evidence without overstating an automated scan as accessibility conformance.
WCAG
Usability Tester
Tests discoverability, task clarity, responsive behavior, interaction friction, visual hierarchy, and inclusive UX.
Usability
Performance Tester
Measures latency, Web Vitals, payload and request cost, caching, API timing, mobile constraints, memory, and leaks.
Performance
Content Quality Tester
Reviews page identity, copy clarity, information architecture, credibility, status communication, readability, and localization.
Content
Forms Tester
Exercises input contracts, validation, boundaries, state, submission, recovery, data quality, conversion, and accessible interaction.
Forms
Error Message Tester
Tests truthful status, clear messages, consistent severity, actionable recovery, safe logs, failure loops, and user trust.
Error UX
Search Box Tester
Tests query handling, suggestions, empty states, input accessibility, relevance feedback, and resilient result navigation.
Search
News Content Tester
Reviews article identity, readability, supporting media, metadata, context, advertising boundaries, and multi-device behavior.
Publishing
Homepage & Landing Page Tester
Tests value clarity, trust, navigation, calls to action, responsive composition, dead ends, conversion, and credibility.
Landing Pages
Checkout Tester
Tests order accuracy, address and payment input, trust, retry safety, pricing truth, completion, and conversion-blocking failures.
Checkout
Shopping Cart Tester
Tests line-item state, quantities, promotions, totals, inventory changes, persistence, accessibility, and checkout transitions.
Shopping Cart
Pricing Page Tester
Tests plan clarity, comparison, currency and locale, hidden conditions, billing cadence, conversion paths, and truthful claims.
Pricing Pages
Privacy Tester
Finds PII exposure, consent and tracking problems, excess collection, unsafe storage or transfer, debug leakage, and AI privacy risk.
Privacy / PII
GDPR Compliance Tester
Tests lawful consent, minimization, retention, international transfer, data-subject rights, transparency, security, and accountability.
GDPR
Cookie Consent Tester
Verifies prior consent, purpose and vendor choices, reject symmetry, preference persistence, withdrawal, tracking, and regional behavior.
Cookie Consent
Legal Policies Tester
Checks policy discoverability, consistency, versioning, contact details, user rights, product alignment, accessibility, and credibility.
Legal Policy
GenAI Code Tester
Challenges AI-generated logic, boundaries, null and empty states, failure handling, API use, security, privacy, tests, and misleading shortcuts.
AI Code Review
AI Chatbot Tester
Tests task success, conversation quality, memory, recovery, privacy, safety, injection, tool use, latency, integration, and nondeterminism.
AI ChatbotOptional Cloud add-on
The CARBON plugin runs inside your coding agent and stays local by default. Connect testers.ai Cloud only for selected work that benefits from parallel capacity, recurring runs, saved account history, API automation, or a shared web results console.
Install CARBON and use /carbon normally. Your project context, local tests, credentials, evidence, and reports stay in your coding-agent environment unless you explicitly choose a Cloud workflow.
Create a testers.ai account, then store the premium API key through CARBON’s protected settings flow. Keys and test credentials never need to appear in chat or reports.
Use explicit testers_plan, testers_run, testers_results, testers_import, or testers_schedule workflows. CARBON never silently switches a local run to paid Cloud execution.
FAQ
CARBON stays inside your AI coding-agent harness, works with the tools you already use, records what it actually observed, and keeps missing evidence visible.
/carbon do?By itself, /carbon runs the full testing cycle: it evaluates the project, target, and change; maps risk; creates the right tests; executes safe checks; collects evidence; and analyzes confidence with explicit limits and next actions. You can also add anything you want in plain language—what to focus on, which kinds of tests or frameworks to use, a particular flow, risk, environment, or constraint—and CARBON turns that request into a robust, repeatable testing system.
Yes. CARBON can work with and control any classic test framework your coding agent can run, including multiple frameworks in the same project. It can help interpret, import, repair, and migrate tests between frameworks and implementation languages while keeping the durable test intent and evidence visible. Nothing is rewritten until you approve the change.
Local runs inside your coding agent and keeps CARBON state in the project. Cloud is optional and lets selected tests fan out in parallel on testers.ai infrastructure, a dedicated private instance, or your own cloud, with live progress and evidence returned to the steered run.
Yes. CARBON can use the model and provider credentials already configured in your AI coding-agent environment. You keep control of those keys; CARBON does not require you to hand them to testers.ai.
Yes. CARBON runs locally inside your AI coding-agent harness and writes its state and evidence to your project. testers.ai does not receive your code, prompts, test data, credentials, screenshots, or reports. We do not need or want your private data. Your chosen coding agent and model provider still handle data according to the configuration and terms you selected.
Yes. CARBON can run with dedicated private cloud instances or inside your own cloud environment, so code, tests, credentials, and evidence stay within the boundaries you control. Contact us to design the isolated deployment that fits your organization.
The current packaging supports Claude Code, Codex, Cursor, Antigravity, and MCP-compatible coding agents. The same evidence boundaries apply regardless of host.
Yes. Top-level testing covers functionality, UI, UX, usability, accessibility, privacy, security, performance, networking, reliability, compatibility, content, data integrity, APIs, and localization—when the required access and evidence are available.
No. Reports separate observed results from blocked, deferred, not assessed, and not measured areas. A completed-looking report is not treated as proof of untested coverage.
You do. CARBON assembles the evidence, severe findings, unresolved evidence gaps, and rollback context, but preserves human authority over ship, canary, hold, or rollback decisions.