All skills
jeffallan avatar

/test-master

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Generates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/test-master

This session only. Nothing lands on disk.

referencessecurity-testing.md

≈835 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Testing

Authentication Tests

describe('Authentication Security', () => {
  it('rejects invalid credentials', async () => {
    await request(app)
      .post('/api/login')
      .send({ email: 'user@test.com', password: 'wrong' })
      .expect(401);
  });

  it('rejects expired tokens', async () => {
    const expiredToken = createExpiredToken();
    await request(app)
      .get('/api/protected')
      .set('Authorization', `Bearer ${expiredToken}`)
      .expect(401);
  });

  it('rejects tampered tokens', async () => {
    const tamperedToken = validToken.slice(0, -5) + 'xxxxx';
    await request(app)
      .get('/api/protected')
      .set('Authorization', `Bearer ${tamperedToken}`)
      .expect(401);
  });

  it('enforces rate limiting on login', async () => {
    for (let i = 0; i < 6; i++) {
      await request(app)
        .post('/api/login')
        .send({ email: 'user@test.com', password: 'wrong' });
    }

    await request(app)
      .post('/api/login')
      .send({ email: 'user@test.com', password: 'correct' })
      .expect(429);
  });
});

Authorization Tests

describe('Authorization', () => {
  it('denies access to other users resources', async () => {
    await request(app)
      .get('/api/users/other-user-id/data')
      .set('Authorization', `Bearer ${userAToken}`)
      .expect(403);
  });

  it('denies admin routes to regular users', async () => {
    await request(app)
      .delete('/api/admin/users/123')
      .set('Authorization', `Bearer ${regularUserToken}`)
      .expect(403);
  });
});

Input Validation Tests

describe('Input Validation', () => {
  it('rejects SQL injection attempts', async () => {
    await request(app)
      .get('/api/users')
      .query({ search: "'; DROP TABLE users; --" })
      .expect(400);
  });

  it('rejects XSS in input fields', async () => {
    const response = await request(app)
      .post('/api/posts')
      .send({ title: '<script>alert("xss")</script>' })
      .expect(201);

    expect(response.body.title).not.toContain('<script>');
  });

  it('validates file upload types', async () => {
    await request(app)
      .post('/api/upload')
      .attach('file', 'malicious.exe')
      .expect(400);
  });
});

Security Headers Test

describe('Security Headers', () => {
  it('sets security headers', async () => {
    const response = await request(app).get('/');

    expect(response.headers['x-content-type-options']).toBe('nosniff');
    expect(response.headers['x-frame-options']).toBe('DENY');
    expect(response.headers['strict-transport-security']).toBeDefined();
  });
});

Security Test Checklist

Category Tests
Auth Invalid creds, token expiry, tampering
Input SQL injection, XSS, command injection
Access IDOR, privilege escalation
Rate Limit Brute force, API abuse
Headers CSP, HSTS, X-Frame-Options
Data PII exposure, error messages

Quick Reference

Vulnerability Test Approach
SQL Injection '; DROP TABLE-- in inputs
XSS <script>alert(1)</script>
IDOR Access other user's resources
CSRF Missing/invalid tokens
Auth Bypass Missing auth, expired tokens

Source: SKILL.md on GitHub

1 alert17d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub17d

    The skill provides a comprehensive framework and reference guide for software testing, including unit, integration, and security testing. It involves processing user-provided code and API responses, which creates a surface for indirect prompt injection. Automated scanners flagged the documentation link and skill file, likely due to the inclusion of security testing payloads (e.g., SQL injection and XSS strings) used as diagnostic examples in the reference materials.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    1/11 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.1",
  "domain": "quality",
  "triggers": "test, testing, QA, unit test, integration test, E2E, coverage, performance test, security test, regression, test strategy, test automation, test framework, quality metrics, defect, exploratory, usability, accessibility, localization, manual testing, shift-left, quality gate, flaky test, test maintenance",
  "role": "specialist",
  "scope": "testing",
  "output-format": "report",
  "related-skills": "fullstack-guardian, playwright-expert, devops-engineer, debugging-wizard, code-reviewer, feature-forge"
}
  • Testing
  • jest
  • vitest
  • pytest
  • test-automation
  • coverage
  • performance-testing
  • security-testing
  • e2e
  • quality-assurance

README badge

README badge for jeffallan/claude-skills/test-master

Generates test files, test strategies, and coverage analysis across unit, integration, E2E, performance, and security testing. Includes patterns for Jest, pytest, k6, and OWASP security testing, plus guidance on flaky test isolation, mock strategies, and test architecture design.

Generated from the current SKILL.md.

Does this skill cover performance and security testing, or just unit tests?
It covers functional, performance, and security testing. The skill includes reference guides for k6 and Artillery performance testing, OWASP security methods, and unit/integration/E2E test patterns.
What testing frameworks does this skill support?
It provides patterns for Jest, Vitest, pytest, and general E2E frameworks. The core workflow and assertions patterns are framework-agnostic; specific guidance is loaded from reference guides based on your tool choice.
Does this skill help debug flaky tests?
Yes. The core workflow includes a step to isolate flaky test failures by checking ordering dependencies, async handling, and adding stabilization logic or retries.
Can this skill generate test reports and defect documentation?
Yes. The skill outputs test plans with scope, test cases, coverage analysis, findings with severity ratings, and actionable fix recommendations.
Does this skill enforce mocking and isolation practices?
Yes. It requires mocking external dependencies, prohibits production data in tests, and forbids order-dependent tests. The skill enforces that each test runs independently.

Generated from the current SKILL.md. These answers refresh after source changes.