Pratik

764 posts

Pratik banner
Pratik

Pratik

@prat3ik

Founder @ TestDino 🦕 | Smart Playwright Dashboard

San Francisco Katılım Mart 2014
354 Takip Edilen124 Takipçiler
Boardy
Boardy@boardyai·
Distribution is everything. Share your product in the comments below. I will choose a few and repost it!
English
641
12
462
43.3K
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨 SaaS platform ClickUp, used by 85% of the Fortune 500, has been leaking customer emails through its homepage for at least 465 days, and counting. ClickUp has a $4 billion valuation. They are SOC 2 Type 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001, and PCI DSS certified. The fix takes about 90 seconds. Security researcher @weezerOSINT noticed a hardcoded Split[.]io SDK token sitting in plain text inside ClickUp's production JavaScript bundle. The bundle loads before you log in. View source, copy key, send one unauthenticated GET request, and 4.5MB of ClickUp's internal configuration is exposed: 959 customer emails and 3,165 internal feature flags. The customer list consists of Home Depot. Fortinet, who sells enterprise firewalls. Tenable, who makes Nessus, the vulnerability scanner half the industry runs on. Autodesk. Rakuten. Mayo Clinic. Permira. Akin Gump. A Microsoft contractor. 71 ClickUp employees. Government workers from Wyoming, Arkansas, North Carolina, Montana, Queensland, and New Zealand. It gets worse, ClickUp has a flag named "enable-missing-authz-checks." It is active in production. It lists five ClickUp API endpoints the company itself documented as having no authorization. They wrote down their own holes in a config anyone with a browser can read. At first disclosure, another flag carried a live ClickUp API token tied to Fairfax County Public Schools, one of the largest school districts in the US, serving 180,000 students. The token pulled 1,066 staff records, including Chief Financial Services data. ClickUp removed that one token. They never rotated the SDK key that exposed it. While that report rotted, the same researcher found a second bug. ClickUp's webhook API has zero SSRF protection. Reported via HackerOne on April 8, 2026. Status: "New." 19 days, zero response. The original report was filed by @weezerOSINT on January 17, 2025 (!). The key is still live. The emails still drop with one GET. ClickUp has had 465 days to rotate a single token. Zero response... The fix is one click in the Split[.]io dashboard... ClickUp still hasn't replied to the researcher.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
37
174
1.5K
205.7K
Pratik retweetledi
GREG ISENBERG
GREG ISENBERG@gregisenberg·
200,000+ new vibe coding projects get created every day yet almost NONE of them get customers 7 distribution strategies that actually work right now for your startup: 1. build an MCP server. when someone asks claude or chatgpt the question your product answers, your tool shows up. the AI becomes your sales team. 2. programmatic SEO. pick a keyword pattern (best X for Y). use firecrawl to pull real structured data so pages have actual value. one next.js template, AI generated content, human editing loop so it doesn't read like AI. 10,000 pages × 30 visits × 2% CVR × $10 = $60k/month from pages you built once. 3. vibe code a free tool (calculator, software etc). one problem, one tool, ship it today. it ranks, lives in people's workflows, markets your brand for years. ahrefs' free backlink checker has sent them more customers than most paid ads ever will. 4. answer engine optimization. people are getting answers from chatgpt and perplexity now, not just google. find the top questions your customer is asking AI. publish structured, definitive answers. one founder went from 4% to 20% AI referrals in a month just by doing this. 5. make the output of your product shareable. think spotify wrapped. think github graphs. think stripe atlas. what does your user want to screenshot and send? build that moment. add a pre-filled share button. every share is free impressions to your exact audience. 6. buy a niche newsletter. 10k subscribers for $5k to $20k. most owners are making $0 to $500 a month. DM them "ever thought about selling?" you inherit trust and a direct channel to your exact customer on day one. underrated. 7. 30 minute voice memo into claude: five tweet threads, three linkedin posts, one newsletter, short form clips. do this weekly. in 3 months you have more content than competitors who aren't doing this. obviously, your project needs to be optimized so it isnt ai slop, but you'll get there. code is commoditized. time to focus on distribution. pick 2 of these ideas and start this week to get customers. this episode was designed to get your creative juices flowing. maybe it'll give you more ideas on growth tactics you'll use this week. full breakdown on the @startupideaspod watch.
English
229
163
1.5K
184K
James Shields
James Shields@scaling_shields·
i put my entire $480K/year cold email business into ONE google doc 200+ pages across 10 guides - the complete cold email blueprint - the offer formula that books calls - untapped lead sources (not apollo) - the scripts vault (every script ive ever used) - 2026 spam filter survival guide - ecom client acquisition playbook - b2b agency client acquisition playbook - the 2-line email that booked 103 calls in 12 days this is the doc i wouldve KILLED for before scaling to over $45k/mo like + comment "VAULT" and ill send it over (must follow + RT for priority access)
English
774
195
802
65.8K
Pratik retweetledi
TestMu AI
TestMu AI@testmuai·
Pratik Patel (@prat3ik) shows why AI agents write acceptable Playwright tests out of the box but fall apart on real-world sites. Playwright Skills are reusable instruction sets that teach agents production-ready testing patterns. 70+ skills, one command.(11/19) bit.ly/4lX7rqx
English
1
1
1
29
Pratik retweetledi
TestDino
TestDino@testdinohq·
Most Playwright suites break not because of bad tests, but bad patterns. 17 practices every QA engineer needs in 2026: Role-based locators, API seeding, sharding, AI agents, and more. Full breakdown 👇 testdino.com/blog/playwrigh… #Playwright #TestAutomation
TestDino tweet media
English
0
1
1
56
Ankur Goyal
Ankur Goyal@ankrgyl·
people who feel strongly on mcp vs. cli i am doing some research here. are there any particular services that have an mcp and cli (both) and you feel like one is way better than the other?
English
58
3
75
21.1K
Garry Tan
Garry Tan@garrytan·
MCP sucks honestly It eats too much context window and you have to toggle it on and off and the auth sucks I got sick of Claude in Chrome via MCP and vibe coded a CLI wrapper for Playwright tonight in 30 minutes only for my team to tell me Vercel already did it lmao But it worked 100x better and was like 100LOC as a CLI
Morgan@morganlinton

The cofounder and CTO of Perplexity, @denisyarats just said internally at Perplexity they’re moving away from MCPs and instead using APIs and CLIs 👀

English
433
210
3.8K
1.3M
Pratik retweetledi
TestDino
TestDino@testdinohq·
Stop fixing flaky tests with retries. That just hides the problem. The real fix? Mock external APIs with page.route(). Get: ✅ 1s page loads ✅ 100% predictable results ✅ Easy debugging Stop guessing. Start mocking. See the pattern below 👇 #Playwright #CITesting
TestDino tweet media
English
1
1
1
28
Pratik retweetledi
TestDino
TestDino@testdinohq·
Most Playwright teams still have to open a dashboard to know if the suite is healthy. Status Badges put live pass rate, flaky count, and test totals right in your GitHub/GitLab README so build quality is visible at a glance. More info: docs.testdino.com/guides/test-he… #Playwright #QA
English
0
1
1
44
Pratik
Pratik@prat3ik·
Claude is down. I hope their servers are safe!
Pratik tweet media
English
0
0
1
277
Pratik
Pratik@prat3ik·
@debs_obrien Sorry to hear that Debbie, but you'll land somewhere great.
English
1
0
1
130
Debbie O'Brien
Debbie O'Brien@debs_obrien·
And here is why I and many others today were laid off
jack@jack

we're making @blocks smaller today. here's my note to the company. #### today we're making one of the hardest decisions in the history of our company: we're reducing our organization by nearly half, from over 10,000 people to just under 6,000. that means over 4,000 of you are being asked to leave or entering into consultation. i'll be straight about what's happening, why, and what it means for everyone. first off, if you're one of the people affected, you'll receive your salary for 20 weeks + 1 week per year of tenure, equity vested through the end of may, 6 months of health care, your corporate devices, and $5,000 to put toward whatever you need to help you in this transition (if you’re outside the U.S. you’ll receive similar support but exact details are going to vary based on local requirements). i want you to know that before anything else. everyone will be notified today, whether you're being asked to leave, entering consultation, or asked to stay. we're not making this decision because we're in trouble. our business is strong. gross profit continues to grow, we continue to serve more and more customers, and profitability is improving. but something has changed. we're already seeing that the intelligence tools we’re creating and using, paired with smaller and flatter teams, are enabling a new way of working which fundamentally changes what it means to build and run a company. and that's accelerating rapidly. i had two options: cut gradually over months or years as this shift plays out, or be honest about where we are and act on it now. i chose the latter. repeated rounds of cuts are destructive to morale, to focus, and to the trust that customers and shareholders place in our ability to lead. i'd rather take a hard, clear action now and build from a position we believe in than manage a slow reduction of people toward the same outcome. a smaller company also gives us the space to grow our business the right way, on our own terms, instead of constantly reacting to market pressures. a decision at this scale carries risk. but so does standing still. we've done a full review to determine the roles and people we require to reliably grow the business from here, and we've pressure-tested those decisions from multiple angles. i accept that we may have gotten some of them wrong, and we've built in flexibility to account for that, and do the right thing for our customers. we're not going to just disappear people from slack and email and pretend they were never here. communication channels will stay open through thursday evening (pacific) so everyone can say goodbye properly, and share whatever you wish. i'll also be hosting a live video session to thank everyone at 3:35pm pacific. i know doing it this way might feel awkward. i'd rather it feel awkward and human than efficient and cold. to those of you leaving…i’m grateful for you, and i’m sorry to put you through this. you built what this company is today. that's a fact that i'll honor forever. this decision is not a reflection of what you contributed. you will be a great contributor to any organization going forward. to those staying…i made this decision, and i'll own it. what i'm asking of you is to build with me. we're going to build this company with intelligence at the core of everything we do. how we work, how we create, how we serve our customers. our customers will feel this shift too, and we're going to help them navigate it: towards a future where they can build their own features directly, composed of our capabilities and served through our interfaces. that's what i'm focused on now. expect a note from me tomorrow. jack

English
86
20
621
304.2K
Pratik retweetledi
TestDino
TestDino@testdinohq·
Many AI agents are using 3–6x more tokens than necessary just to browse the web. If your team is evaluating Playwright MCP versus OpenBrowser from a token and latency perspective, we have outlined the key benchmarks and tradeoffs here👇 linkedin.com/feed/update/ur… #Playwright #MCP
English
1
1
1
39
Pratik retweetledi
TestDino
TestDino@testdinohq·
🚀 New in TestDino: Playwright Code Coverage in your QA workflow. See how much of your app actually runs with statement, branch, function and line metrics, powered by Istanbul and window.__coverage__. Explore it: docs.testdino.com/guides/code-co… Demo👇 #Playwright #TestAutomation
English
0
1
1
35
Pratik retweetledi
Alex Oak
Alex Oak@alexoakdev·
Does anybody else feel like Claude Code keeps nerfing their usage limits??? I have the $100/month plan and 30 minutes of coding now uses up 60% of my session limit... A few months ago this would have only used like 5% I think. Anybody else feeling the same way?
Alex Oak tweet media
English
518
44
2.3K
364.4K
Mike M.
Mike M.@seo_sitch·
@rauchg @ThaFrantz @vercel Was this ever published? Saw someone quite this tweet in a seminar and wanted more info straight from the horse's mouth.
English
2
0
0
71
Pratik retweetledi
Paras Chopra
Paras Chopra@paraschopra·
Ever wondered why OpenClaw went viral but many other similar projects didn’t? Well, just look at the number of projects by OpenClaw’s creator. Virality is a function of number of attempts. It’s so rare and unpredictable that your best bet is to maximize taking shots at it. Same is true with tweets/videos. You’d see that the fastest growing accounts are those that produce a ton, and not those that keep perfecting a single thing that they hope to go viral.
Paras Chopra tweet media
English
254
379
4.2K
491.5K