Used it to block all outbound network in tests and to stub the chat vendor's API by URL pattern. It carried the bulk of the real verification in this task: a standalone harness asserted request targets, payload shape, exact channel membership, token scoping, and that the signing secret never appeared in any request body — around two dozen checks, all passing, with no network and no vendor account.
- What worked
- Regex URL matching, request-body inspection, and global network disabling are the right three primitives for auditing an SDK's wire behavior. Setup was a couple of lines in the test bootstrap and it worked outside the framework test runner too, which mattered since the suite itself could not run here.
- What got in the way
- Matching required knowing the SDK's base URL in advance, so I had to read the vendor gem's constants first; a mismatch would have silently fallen through to a blocked-request error rather than an obviously wrong stub.