Skip to content
Back to skills

Boundary Negative Testing

BSecurity

Use when building cases for any input, form, endpoint or state change - boundary values, invalid and hostile data, authz and concurrency cases with a worked example

  • 109 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 19, 2026
ai-agentsgotestingapi

Works with

  • api

Security analysis

B75/100
  • criticalAccesses sensitive system or user directories

Pro shows the line behind each finding and how to fix it

Scanned October 2, 2026

npx -y skills add makifbaysal/tasktrooper --skill boundary-negative-testing --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Boundary Negative Testing?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Boundary Negative Testing
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/makifbaysal-boundary-negative-testing/badge)](https://www.skillsdirectory.com/skills/makifbaysal-boundary-negative-testing)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: boundary-negative-testing
category: qa
description: Use when building cases for any input, form, endpoint or state change - boundary values, invalid and hostile data, authz and concurrency cases with a worked example
---
# Boundary and Negative Testing

## Data catalogue

- **Strings:** empty, whitespace-only, 1 char, max, max+1, 10x max, leading/trailing spaces, emoji/ZWJ, RTL text, combining marks, `<b>x</b>` and `<img src=x onerror=alert(1)>` (must render as inert text, never execute), `' OR 1=1 --` (as literal data), `../../etc/passwd` in a filename-ish field.
- **Numbers:** −1, 0, 1, max, max+1, a decimal where an integer is expected, `1e309`, `NaN`.
- **Dates:** leap day, a DST transition, a timezone boundary, past/future limits the domain implies.
- **Files:** 0 bytes, just over the size limit, wrong MIME type with a correct-looking extension.
- **Collections:** 0 items, 1 item, exactly the page size, page size + 1.
- **Concurrency:** double submit, two sessions editing the same record.
- **Dependency down:** the stubbed dependency returns 5xx/timeout (test-data-and-stubs), or `route "**/api/<dep>/**" --status=500` for a UI-only case.

## Flow-level cases

Unauthorized access, missing resources (404 paths), concurrent/duplicate submission, partial failure of a dependency.

## Recording

Record every boundary you probed as its own test case on the task, passing ones included — absence of evidence is not evidence of absence, and a boundary nobody can see you tried is one the next reader has to try again. A boundary that cannot exist here (the field is an enum, the endpoint is internal-only) is a case too: record it `invalid` with that reason.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…