Helmops — Security skill for Claude Code
AI-assisted (vibe-coded) browser-operating agent that enters invoices into an ERP with approvals, failure recovery and audit.
How to install Helmops
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open qwerty12-ai/helmops and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Helmops does
AI-assisted (vibe-coded) browser-operating agent that enters invoices into an ERP with approvals, failure recovery and audit. Built for the Hulchul AI Engineering assignment; scaffolding with Claude, verified and extended by me.
Alternatives in Security
- OpenTag — Open-source, channel-native agent gateway for Slack 499 ★
- Roast Repo — Deliver a brutally honest, technically sharp roast of the current repository 186 ★
- Senior Engineering Partner — A stack-agnostic Claude Code skill: strict code reviewer, pair programmer, debugger, and mentor (Python/Bash/A 148 ★
README
HelmOps - a computer operator for Accounts Payable
**Transparency note:** This project was built for the Hulchul AI Engineering build assignment. I scaffolded it with Claude (vibe-coded) because browser automation with Playwright was new to me. I ran it end to end, verified results against the ERP database, debugged my own edit, and added a `min_amount` goal filter with a test (see ENGINEERING_NOTE.md). I treat this as an experiment in learning a new tool fast with AI assistance. My earlier projects (Reclaim, SignalForge, CursorVault, GitPulse) are separate and hand-built.
Demo video:
https://youtu.be/TfvVkYB4yYM
License:
MIT (see `LICENSE`).
Give it a plain-English goal ("Enter all vendor invoices, ask me before anything over $2,000"). It reads invoice files, **drives a real Chromium browser** to enter them as bills in a mock ERP (MiniLedger), recovers from failures without duplicating anything, asks for approval beyond your authority, pauses on demand, independently audits the ERP afterwards, and writes a report with screenshots.
Stack: Python 3.10+, FastAPI, Playwright (Chromium), MySQL 8.4 (Docker Compose), vanilla-JS dashboard (SSE). Optional free local LLM via Ollama. No API keys, no paid services, synthetic data only.
Run
python -m venv .venv && source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install -r requirements.txt
python -m playwright install chromium
python scripts/make_invoices.py # (already generated, safe to re-run)
docker compose up -d # MySQL for the test ERP (port 3307)
export MYSQL_HOST=127.0.0.1 MYSQL_PORT=3307 MYSQL_USER=helm MYSQL_PASSWORD=helm MYSQL_DATABASE=miniledger
# Windows PowerShell: $env:MYSQL_HOST="127.0.0.1"; $env:MYSQL_PORT="3307"; ... (same names)
> Windows tip: if the headed browser crashes on launch, use your installed Edge/Chrome:
> `$env:HELM_CHANNEL="msedge"` (or `"chrome"`) before `python run.py`.
# No Docker?
Related Skills
Ops Audit
Audit an existing Claude Code harness for runtime assumptions, operational debt, and failure recovery gaps (se
Vibe Security Check Skill
Claude skill for automated security audit for vibe-coded apps. One command, 15 checks, auto-fix. Works with No
Information Security For Vibecoded Apps
An autonomous Application Security (AppSec) prompt and skill module for AI coding assistants (Antigravity, Cur
Aiclean
Audit and clean up a Claude Code setup against Anthropic's current prompt-engineering guidance. Finds stale sc
Engineering Fix
Applies engineering corrections from the last /engineering-audit run. Creates an isolated branch, applies chan
Vibe Audit
Security scanner for AI-built apps. Catches hardcoded secrets, injection vulnerabilities, missing rate limits,
Related Agents
AI Code Security Auditor
Security reviewer for AI-generated and vibe-coded apps — hunts the hardcoded secrets, broken row-level securit
Security AI Generated Code Auditor
Security reviewer for AI-generated and vibe-coded apps — hunts the hardcoded secrets, broken row-level securit
Engine Design Review Feasibility
Before a change you've asked for gets built, checks whether the plan can actually be built, shipped, and run —