All categories
Testing & QA
Unit tests, integration tests, E2E, QA, validation, and test automation
- 29,138
- 1,215
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse testing & qa skills
Showing 289–312 of 29,138 skills
- Spark Component EnvironmentCreate or update an environment file in the Environment folder in Sources of a spark-ios-component-XXX and add or update unit tests.Votes: 0GitHub stars: 22
- Spark Component ConstantsCreate or update a constants file in the Constants folder in Sources of a spark-ios-component-XXX and add or update unit tests.Votes: 0GitHub stars: 22
- Spark Component Accessibility IdentifierCreate or update a accessibility identifier file in the AccessibilityIdentifier folder in Sources of a spark-ios-component-XXX and add or update unit tests.Votes: 0GitHub stars: 22
- TestRun the full test suite AND expand coverage for the current change — the dedicated testing pass. Its ONLY job is tests. Use after implementing or verifying a change, and whenever the user says "test", "run tests", "cover this", "write tests", or "make sure it's tested". Enforces: nothing is done until the suite is green and every change is covered (with a regression test per bug fixed).Votes: 0GitHub stars: 2
- Plan GatesThe full plan → gate → commit procedure for full-gear work: new features, multi-file refactors, schema/API changes, anything security-sensitive or where the approach is genuinely uncertain. Use whenever a task warrants the "full" gear from the global gears table, or when the user says "plan this", "full workflow", or asks for the adversarial planning panel. Covers Phase 1 (orient, draft, adversarial critics, plan file, approval stop) and Phase 2 (implement on mid-tier agents, five gates — con...Votes: 0GitHub stars: 2
- Parent SyncSync web-ui with a newer parent career-ops release — pull the parent, scope the delta, port providers/fixes, fan out docs ×17, run every gate, ship the parity release end-to-end. Trigger when the user says "обнови родителя", "parent-sync", "возьми новое из родителя", or pastes a santifer/career-ops release URL.Votes: 0GitHub stars: 79
- Playwright InteractivePersistent browser and Electron interaction through `js_repl` for fast iterative UI debugging.Votes: 0GitHub stars: 27,803
- Define GoalHelp the user define a concrete, measurable goal before starting work, especially when they ask to use the goal tool, create a goal, set an objective, clarify success criteria, or turn a fuzzy intention into a quantitative outcome. Use this skill for goal creation and goal refinement only; it does not manage durable snapshots, decision logs, or long-running execution artifacts.Votes: 0GitHub stars: 27,803
- Vector ForgeMutation-driven test vector generation. Finds implementations of a cryptographic algorithm or protocol, runs mutation testing to identify escaped mutants, then generates new test vectors that deliberately exercise the uncovered code paths. Compares before/after mutation kill rates to prove vector effectiveness. Use when generating cryptographic test vectors, measuring Wycheproof coverage gaps, finding escaped mutants via mutation testing, creating cross-implementation test suites, or improvin...Votes: 0GitHub stars: 7,287
- GenotoxicGraph-informed mutation testing triage. Parses codebases with Trailmark, runs mutation testing and necessist, then uses survived mutants, unnecessary test statements, and call graph data to identify false positives, missing test coverage, and fuzzing targets. Use when triaging survived mutants, analyzing mutation testing results, identifying test gaps, finding fuzzing targets from weak tests, running mutation frameworks (including circomvent and cairo-mutants), or using necessist.Votes: 0GitHub stars: 7,287
- WycheproofValidates cryptographic implementations against Project Wycheproof's test vectors, which encode known attacks and edge cases across AES, RSA, ECDSA, ECDH, and more. Covers loading test vectors, mapping result flags onto pass and fail expectations, and reading a failure. Use when testing a crypto implementation against known attacks, checking a library against standard test vectors, or investigating why two implementations disagree on the same input.Votes: 0GitHub stars: 7,287
- RuzzySets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language. Covers harness structure, fuzzing pure Ruby and the native C extensions in gems, and sanitizer builds. Use when fuzzing a Ruby library or gem, testing a Ruby C extension for memory safety, or asking how to fuzz Ruby at all.Votes: 0GitHub stars: 7,287
- Fuzzing ObstaclesPatches past the barriers that stop a fuzzer making progress — checksum and hash verification, magic-value validation, time-based seeds, and other non-deterministic global state. Covers locating the blocking check, neutering it behind a fuzzing build flag, and avoiding the false positives a patch can introduce. Use when a fuzzer is stuck at validation, when coverage shows large regions behind a checksum, or when valid inputs are impractical to generate.Votes: 0GitHub stars: 7,287
- AtherisSets up and runs Atheris, the coverage-guided Python fuzzer built on libFuzzer. Covers TestOneInput harnesses, FuzzedDataProvider, instrumenting both pure Python and native C extensions, and running under AddressSanitizer. Use when fuzzing a Python package, hunting memory corruption in a Python C extension, or choosing between Atheris and Hypothesis for a Python target.Votes: 0GitHub stars: 7,287
- Semgrep Rule CreatorCreates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.Votes: 0GitHub stars: 7,287
- Ton Vulnerability ScannerScans TON (The Open Network) smart contracts for 3 critical vulnerabilities including integer-as-boolean misuse, fake Jetton contracts, and forward TON without gas checks. Use when auditing FunC contracts.Votes: 0GitHub stars: 7,287
- Solana Vulnerability ScannerScans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing. Use when auditing Solana/Anchor programs.Votes: 0GitHub stars: 7,287
- Guidelines AdvisorSmart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Use when asking whether a smart contract project follows development best practices, reviewing on-chain/off-chain split, upgradeability, or delegatecall proxy patterns against guidelines, or seeking recommendations on...Votes: 0GitHub stars: 7,287
- Cairo Vulnerability ScannerScans Cairo/StarkNet smart contracts for 6 critical vulnerabilities including felt252 arithmetic overflow, L1-L2 messaging issues, address conversion problems, and signature replay. Use when auditing StarkNet projects.Votes: 0GitHub stars: 7,287
- Algorand Vulnerability ScannerScans Algorand smart contracts for 11 common vulnerabilities including rekeying attacks, unchecked transaction fees, missing field validations, and access control issues. Use when auditing Algorand projects (TEAL/PyTeal).Votes: 0GitHub stars: 7,287
- Typing Exclusion WorkerPython typing exclusion worker: remove assigned mypy exclusion modules in small scoped batches, fix typing issues, run validation, and produce a structured completion summary. Use when running parallel typing-debt workers or when asked to remove modules from pyproject mypy exclusion overrides.Votes: 0GitHub stars: 1,037
- ReferencesUse this layout when reusable templates, schemas, or static artifacts carry most of the skill's value.Votes: 0GitHub stars: 1,037
- Code ReviewPerform code reviews following Sentry engineering practices. Use when reviewing pull requests, examining code changes, or providing feedback on code quality. Covers security, performance, testing, and design review.Votes: 0GitHub stars: 1,037
- Verify IntegrationVerify that changed components are actually connected into the intended end-to-end system flow. Use when checking imports/exports, registrations, data/control flow, configuration consumption, call paths, and boundary compatibility after implementation.Votes: 0GitHub stars: 67