Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Review Tests

ASecurity

Review a test suite or test plan for coverage, quality, correctness, and maintainability.

10 stars
0 votes
0 copies
0 views
Added 10/6/2026
code-qualitygosqlsecurityperformance

Security Analysis

A100/100

Scanned 10/6/2026

$npx -y skills add tomzx/agents --skill review-tests --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Review Tests?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Review Tests
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tomzx-review-tests/badge)](https://www.skillsdirectory.com/skills/tomzx-review-tests)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: review-tests
description: Review a test suite or test plan for coverage, quality, correctness, and maintainability.
---

# Review Tests

Audits a test suite or test plan and reports findings across five categories: coverage, quality, correctness, maintainability, and missing scenarios.

## Prerequisites

- Apply the shared SDLC conventions in `skills/sdlc/references/shared.md`.
- If no argument is provided, locate the feature directory under `.sdlc/features/` whose frontmatter `issue` field references `$ISSUE_NUMBER`.
- `.sdlc/features/N-<slug>/tests.md`, or a test suite/test plan provided in context or as a file path
- `.sdlc/features/N-<slug>/requirements.md` (optional, improves coverage analysis)

## Steps

1. Read the tests or test plan from `.sdlc/features/N-<slug>/tests.md` if present, otherwise from context or as a file path.
2. Map tests to requirements or acceptance criteria if a spec is available.
3. Identify issues in each category below.
4. Report findings. Omit categories with no findings.
5. Write the findings to `.sdlc/features/N-<slug>/review-tests.md` with frontmatter `artifact: tests`, `verdict` (`approved` if there are no blocking findings, `changes-requested` if the author must address findings, `rejected` for a fundamental flaw), and `reviewed_at: <ISO date>`, and the findings as the body, per `skills/sdlc/references/shared.md`. Record any unresolved open questions in the findings body. For any question that carries meaningful risk to the implementation, also invoke `/create-assumption` to record it formally.

## Review Checklist

### Coverage
- Are all acceptance criteria covered by at least one test?
- Are non-functional requirements (performance, security) verified?
- Are error paths and failure scenarios tested?

### Quality
- Do test names clearly describe what is being tested and the expected outcome?
- Are tests verifying behavior rather than implementation details?
- Is each test independent (no shared mutable state between tests)?
- Is test setup minimal and focused?

### Correctness
- Do assertions actually verify the intended behavior?
- Are assertions specific enough (not just `assert result is not None`)?
- Are mocks and stubs used appropriately without over-mocking?

### Maintainability
- Is test code DRY where it benefits readability?
- Are magic values extracted into named constants or fixtures?
- Will tests break on valid refactors (brittle tests)?

### Missing Scenarios
- Are edge cases covered (empty inputs, boundary values, max/min)?
- Are concurrency or race conditions tested where applicable?
- Are security-relevant paths tested (unauthorized access, injection)?

## Output Format

```markdown
## Coverage

<Findings or "No issues found.">

## Quality

<Findings or "No issues found.">

## Correctness

<Findings or "No issues found.">

## Maintainability

<Findings or "No issues found.">

## Missing Scenarios

<Findings or "No issues found.">
```

## Outcome

If `$OUTCOME_YAML` is set, emit your verdict there per `skills/sdlc/references/shared.md`:

| Verdict | When |
|---|---|
| `approved` | No blocking findings; the subject passes review |
| `changes-requested` | Findings the author must address before it passes |
| `rejected` | Fundamental flaw requiring rework or stopping |

In the same emission, list the findings file under `artifacts:` (`.sdlc/features/N-<slug>/review-tests.md`).

## Example Usage

**Scenario 1: Missing error path**
Tests cover the happy path for user registration but nothing tests what happens when the email already exists.
Report under Missing Scenarios.

**Scenario 2: Brittle test**
A test asserts the exact SQL query string generated by an ORM.
This will break on any ORM upgrade without a behavior change. Report under Maintainability.

**Scenario 3: Weak assertion**
`assert response.status_code == 200` without checking the response body.
Report under Correctness.

## Next Step

Once the findings verdict is `approved`, continue with `/create-implementation`.

Attribution

tomzxtomzx
View sourceSee grades on GitHubMore from tomzx →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman Review

Ultra-compressed code review comments. Cuts noise from PR feedback while preserving the actionable signal. Each comment is one line: location, problem, fix. Use when user says "review this PR", "code review", "review the diff", "/review", or invokes /caveman-review. Auto-triggers when reviewing pull requests.

1100021 votes

Caveman Commit

Ultra-compressed commit message generator. Cuts noise from commit messages while preserving intent and reasoning. Conventional Commits format. Subject ≤50 chars, body only when "why" isn't obvious. Use when user says "write a commit", "commit message", "generate commit", "/commit", or invokes /caveman-commit. Auto-triggers when staging changes.

1100021 votes

Springboot Verification

Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.

2456590 votes

Verification Loop

一个全面的 Claude Code 会话验证系统。

2456590 votes

Django Verification

Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.

2456590 votes
View all in code-quality →