Test REST and GraphQL APIs for authentication bypasses, authorization flaws, IDOR, mass assignment, injection attacks, and rate limiting issues. Use when pentesting APIs or testing microservices security.
Test / Debug Topic Skill
Guides a maker through debugging a topic they just created or updated — driving it, confirming the reply is real, checking the fix doesn't break
Test Workflow Skill
Guides a maker through debugging a Power Automate cloud flow (workflow) behind their agent — exercising it, reading its per-action run history, localizing a fault
E2E manual testing of PRs/branches using docker compose, agent-browser, and API calls. TRIGGER when user asks to manually test a PR, test a feature end-to-end, or run integration tests against a running system.
Write or improve ExUnit tests for portal/ the emisar way — DataCase/ConnCase, the real fixtures in test/support, and the mandatory happy / denial / cross-account paths (§7). Use when adding tests for a context/job/LiveView, or when a change is missing its denial + cross-account coverage.
Generate snapshot test files for Sentry frontend React components. Use when asked to "generate snapshot tests", "add snapshot tests", "create visual snapshots", "write snapshot tests", "add visual regression tests", or "snapshot this component". Accepts an optional component path or name via $ARGUMENTS.
Unit testing & component testing skill for any language or framework. Use when: writing tests, setting up a test suite, thinking about what to test, applying TDD, testing a React component, testing a Python/Node.js backend, mocking dependencies, checking test coverage, understanding unit vs component vs integration tests. Triggers: 'write a test', 'add tests for', 'unit test this', 'component test', 'test this function', 'how do I test', 'TDD', 'what should I test', 'set up vitest', 'set up pytest', 'test coverage', 'mock this', 'I don't know how to test this'.
Verify a local web app in a real browser with page, element, click, form, console and screenshot evidence. Use after a build or UI change; do not implement features or publish deployments with this skill.
Write new MSTest unit tests and fix existing MSTest code using MSTest 3.x/4.x modern APIs and best practices. USE FOR: write or create MSTest unit tests, fix or modernize MSTest assertions, better MSTest assertion than Assert.IsTrue, replace hard cast with MSTest type assertion, MSTest assertion APIs (IsInstanceOfType, Contains, ContainsSingle, HasCount, IsEmpty, IsNotEmpty, DoesNotContain, StartsWith, EndsWith, MatchesRegex, IsGreaterThan, IsInRange, IsNull), fix swapped Assert.AreEqual arguments, replace ExpectedException with Assert.Throws, data-driven tests (DataRow, DynamicData, ValueTuples), test lifecycle (sealed classes, TestInitialize, TestCleanup), async tests and cancellation tokens, test parallelization (Parallelize / DoNotParallelize), MSTest.Sdk project setup. DO NOT USE FOR: broad test quality audits (use test-anti-patterns), running tests (use run-tests), MSTest version migration (use migrate-mstest-v1v2-to-v3 or migrate-mstest-v3-to-v4), xUnit/NUnit/TUnit, or non-.NET languages.
Extend Python test suites with parametrization, fixture reuse, and quality enforcement. Use when asked to add tests, extend existing tests, improve test coverage, consolidate duplicate tests, fix test quality issues, or when Slopgate reports untested-production-code, missing test references, or coverage gaps. Triggers on requests like "add tests for X", "extend these tests", "parametrize tests", "consolidate tests", "fix test quality", "improve test coverage", "write tests for this function", "test this module", "behavior tests", "integration tests", "missing tests", "coverage holes", "untested code", or when a hook denies with test-related findings.
Write, fix, review, debug, and validate Flutter tests for apps, packages, and plugins. Use when adding unit tests, widget tests, integration tests, MethodChannel or plugin mocks, Mockito or mocktail test doubles, golden or accessibility checks, CI test commands, test failures, MissingPluginException, pump or pumpAndSettle problems, finder errors, build_runner mock generation, device integration testing, web integration testing, or flaky Flutter tests.
Audit the existing test suite for structural and quality issues — wrong-layer tests, redundant browser tests, infrastructure overuse, flaky/unreliable patterns, rotted skipped tests, unclear test names, dataset opportunities, duplicate tests, folder drift — then fix the approved issues. Use when the user says things like "audit the tests", "review the test suite", "our tests are slow", "our tests are flaky", "improve test distribution", "too many end-to-end tests", "tests are taking too long", "are our tests in the right layer", or "clean up the test suite". Also invoke proactively after a major feature milestone when the suite has grown significantly. Distinct from `cover` (which adds tests for recent code changes) — this skill audits what's already there and never adds net-new tests for uncovered code. Use the `test` skill to run the suite during the baseline and verification phases.
Senior QA/QC engineer that evaluates existing codebases for test quality. Runs existing tests, diagnoses failures, identifies missing test coverage, and writes missing tests. Framework-agnostic — works with any language and test runner. Use when the user asks to run tests, diagnose failures, do test gap analysis, QA, quality assurance, test coverage analysis, find missing tests, test audit, quality check, quality report, fix failing tests, evaluate test quality, or assess test health of a codebase. Trigger phrases include "run tests", "QA", "quality assurance", "test audit", "test coverage", "missing tests", "gap analysis", "quality report", "fix failing tests", "diagnose test failures", "quality check", "evaluate test quality", "test health".
Decide what deserves a test and write tests that fail for the right reason. Use when the user asks what or how to test, asks about unit, integration or end to end tests, test coverage, mocking, fixtures, flaky tests, test driven development, snapshot tests or contract tests, asks why their tests pass while production breaks, or asks how to add tests to code that has none. Allocates effort by what a failure costs rather than by a coverage target, tests behaviour instead of implementation so refactoring does not break the suite, makes flakiness a defect rather than a retry, and states plainly that coverage percentage measures execution rather than correctness. Triggers on what should I test, how do I test, unit tests, integration tests, end to end tests, test coverage, mocking, flaky tests, TDD, snapshot tests, my tests pass but production breaks, add tests to legacy code.
Generates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.
Plain text files in a repository that tell a coding agent how the project works: commands to run, conventions to follow and things to avoid. CLAUDE.md, AGENTS.md, cursor rules and skills are the common kinds.
CLAUDE.md or AGENTS.md?
CLAUDE.md is read by Claude Code. AGENTS.md is an open format that Codex, Cursor and other agents read. Many projects keep one and point the other at it.
What is a skill?
A folder with a SKILL.md that describes one capability, such as filling PDFs or reviewing code. The agent loads it only when the task calls for it.
Can I search my own team's files too?
Your agents already can, over MCP, limited to the files you're allowed to read. Searching them from this page is coming.