
Sharon
Security Tester
Tests authentication, authorization, sessions, secrets, exposed data, dependencies, and practical vulnerability evidence.
SecurityFully automated QA subagents.
CARBON does the QA testing work. You take the credit.
One command
Use /carbon by itself for the complete testing cycle—or add any testing request in plain language. CARBON turns it into a robust, repeatable system with evidence and confidence analysis.
Current testerJason · Overall CARBON
Current testerJason · Overall CARBON
The default example uses published jtest/.carbon results. The natural-language example demonstrates how CARBON structures a request; specialized examples replay observed evidence or preserve explicit not-run boundaries instead of inventing passes.
AI testing sub-agents
CARBON routes the specialist sub-agent whose testing perspective fits the risk in front of you. Each sub-agent has a defined domain, concrete checks, and the same obligation to show evidence and limits—not just a generic testing prompt.

Security Tester
Tests authentication, authorization, sessions, secrets, exposed data, dependencies, and practical vulnerability evidence.
Security
GenAI Code Tester
Challenges AI-generated logic, boundaries, null and empty states, failure handling, API use, security, privacy, tests, and misleading shortcuts.
AI Code Review
Accessibility Tester
Tests keyboard use, assistive technology, labels, feedback, responsive access, and barriers affecting disabled users.
Accessibility
WCAG Compliance Tester
Gathers criterion-level WCAG evidence without overstating an automated scan as accessibility conformance.
WCAG
Usability Tester
Tests discoverability, task clarity, responsive behavior, interaction friction, visual hierarchy, and inclusive UX.
Usability
Performance Tester
Measures latency, Web Vitals, payload and request cost, caching, API timing, mobile constraints, memory, and leaks.
Performance
Content Quality Tester
Reviews page identity, copy clarity, information architecture, credibility, status communication, readability, and localization.
Content
Forms Tester
Exercises input contracts, validation, boundaries, state, submission, recovery, data quality, conversion, and accessible interaction.
Forms
Error Message Tester
Tests truthful status, clear messages, consistent severity, actionable recovery, safe logs, failure loops, and user trust.
Error UX
Search Box Tester
Tests query handling, suggestions, empty states, input accessibility, relevance feedback, and resilient result navigation.
Search
News Content Tester
Reviews article identity, readability, supporting media, metadata, context, advertising boundaries, and multi-device behavior.
Publishing
Homepage & Landing Page Tester
Tests value clarity, trust, navigation, calls to action, responsive composition, dead ends, conversion, and credibility.
Landing Pages
Checkout Tester
Tests order accuracy, address and payment input, trust, retry safety, pricing truth, completion, and conversion-blocking failures.
Checkout
Shopping Cart Tester
Tests line-item state, quantities, promotions, totals, inventory changes, persistence, accessibility, and checkout transitions.
Shopping Cart
Pricing Page Tester
Tests plan clarity, comparison, currency and locale, hidden conditions, billing cadence, conversion paths, and truthful claims.
Pricing Pages
Privacy Tester
Finds PII exposure, consent and tracking problems, excess collection, unsafe storage or transfer, debug leakage, and AI privacy risk.
Privacy / PII
GDPR Compliance Tester
Tests lawful consent, minimization, retention, international transfer, data-subject rights, transparency, security, and accountability.
GDPR
Cookie Consent Tester
Verifies prior consent, purpose and vendor choices, reject symmetry, preference persistence, withdrawal, tracking, and regional behavior.
Cookie Consent
Legal Policies Tester
Checks policy discoverability, consistency, versioning, contact details, user rights, product alignment, accessibility, and credibility.
Legal Policy
OWASP Security Tester
Challenges access control, injection, insecure design, misconfiguration, vulnerable components, integrity, logging, and SSRF risk.
OWASP
AI Chatbot Tester
Tests task success, conversation quality, memory, recovery, privacy, safety, injection, tool use, latency, integration, and nondeterminism.
AI ChatbotEnterprise private cloud
All local CARBON execution is free inside your coding agent. Enterprise can deploy CARBON Cloud inside infrastructure you control when selected work benefits from private parallel capacity, recurring runs, API automation, or a shared results console.
Install CARBON and use every local /carbon workflow for free. Project context, tests, credentials, evidence, and reports stay inside your coding-agent environment.
Enterprise runs parallel workers, the API, and the web console in your cloud, VPC, or dedicated private instance. Your code, credentials, test data, and evidence stay within boundaries you control.
Use explicit planning, execution, results, import, and scheduling workflows. CARBON never silently moves a local run into your cloud environment.
CARBON pricing
The complete CARBON harness is free inside your coding agent. Enterprise adds high-volume parallel execution inside private-cloud infrastructure you control.
Run the complete CARBON harness inside the coding agent you already use—for free.
/carbon workflowRun high volumes of CARBON tests in parallel inside your private cloud.
Local execution is fully unlocked and free. Private-cloud execution is Enterprise-only and explicit: CARBON never silently moves a local run into a cloud environment.
Browser and framework control
By default, CARBON uses the browser and computer controls already built into your AI coding agent. If you want, ask it to use CARBON’s AI-first Clicky Browser, Vibium, Playwright, Selenium, or any other framework. CARBON can run, exercise, coordinate, and manage multiple test frameworks for you.
Run /carbon with no framework instructions. CARBON chooses the available native controls automatically.
/carbon use CARBON’s AI-first Clicky Browser
CARBON handles Vibium behind the scenes, runs or creates the relevant automation, manages execution, and brings the evidence back into the same confidence analysis.
/carbon use Vibium for test automation
CARBON can use the Playwright setup already in your project, create focused coverage when needed, exercise the suite, and manage the available traces, screenshots, assertions, and reports.
/carbon use Playwright for test automation
CARBON can preserve your Selenium language and runner, manage the existing suite, add focused automation where needed, and bring available WebDriver results and artifacts into one evidence-qualified report.
/carbon use Selenium for test automation
FAQ
CARBON stays inside your AI coding-agent harness, works with the tools you already use, records what it actually observed, and keeps missing evidence visible.
/carbon do?By itself, /carbon runs the full testing cycle: it evaluates the project, target, and change; maps risk; creates the right tests; executes safe checks; collects evidence; and analyzes confidence with explicit limits and next actions. You can also add anything you want in plain language—what to focus on, which kinds of tests or frameworks to use, a particular flow, risk, environment, or constraint—and CARBON turns that request into a robust, repeatable testing system.
Yes. CARBON can work with and control any classic test framework your coding agent can run, including multiple frameworks in the same project. It can help interpret, import, repair, and migrate tests between frameworks and implementation languages while keeping the durable test intent and evidence visible. Nothing is rewritten until you approve the change.
All local CARBON execution is free inside your coding agent and keeps CARBON state in the project. Enterprise adds self-hosted private-cloud execution so selected tests can fan out in parallel within infrastructure you control.
Yes. CARBON can use the model and provider credentials already configured in your AI coding-agent environment. You keep control of those keys; CARBON does not require you to hand them to testers.ai.
Yes. CARBON runs locally inside your AI coding-agent harness and writes its state and evidence to your project. testers.ai does not receive your code, prompts, test data, credentials, screenshots, or reports. We do not need or want your private data. Your chosen coding agent and model provider still handle data according to the configuration and terms you selected.
Yes, with Enterprise. CARBON can run with dedicated private-cloud instances or inside your own cloud environment, so code, tests, credentials, and evidence stay within the boundaries you control. Contact us to design the isolated deployment that fits your organization.
The current packaging supports Claude Code, Codex, Cursor, Antigravity, and MCP-compatible coding agents. The same evidence boundaries apply regardless of host.
Yes. Top-level testing covers functionality, UI, UX, usability, accessibility, privacy, security, performance, networking, reliability, compatibility, content, data integrity, APIs, and localization—when the required access and evidence are available.
No. Reports separate observed results from blocked, deferred, not assessed, and not measured areas. A completed-looking report is not treated as proof of untested coverage.
People who have tested Chrome, Google Search, and Windows. These are products where quality has to survive relentless change and enormous scale. We built CARBON from that experience. We know how to make testing systems hold up when the pressure is real, and nobody cares more deeply about quality than we do. You can trust us to scale because we have already done it where scale is unforgiving. Quality is not a checkbox here. It is the whole point.
You do. CARBON assembles the evidence, severe findings, unresolved evidence gaps, and rollback context, but preserves human authority over ship, canary, hold, or rollback decisions.
Questions about CARBON?Ask about the plugin, testing workflows, privacy, frameworks, or anything else.