All skills
jeffallan avatar

/test-master

@efebc44
by jeffallanjeffallan/claude-skills12k stars
1,124

Generates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/test-master

This session only. Nothing lands on disk.

referencestdd-iron-laws.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

TDD Iron Laws


The Fundamental Principle

NO PRODUCTION CODE WITHOUT A FAILING TEST FIRST.

This is non-negotiable. If you wrote production code before writing a failing test, delete it and start over. No exceptions.


The Three Iron Laws

Iron Law 1: The Fundamental Rule

"You shall not write any production code unless it is to make a failing test pass."

Every line of production code must have a corresponding test that:

  1. Was written first
  2. Was observed to fail
  3. Now passes because of that code

Iron Law 2: Proof Through Observation

"If you didn't watch the test fail, you don't know if it tests the right thing."

Mandatory verification steps:

  • Write the test
  • Run it and observe the failure
  • Verify the failure message is meaningful
  • Only then implement the fix

A test you've never seen fail proves nothing.

Iron Law 3: The Final Rule

"Production code exists → A test exists that failed first. Otherwise → It's not TDD."

There is no middle ground. Code written without a prior failing test is not test-driven development, regardless of how many tests exist afterward.


The RED-GREEN-REFACTOR Cycle

RED: Write One Minimal Failing Test

// Start with the smallest possible failing test
it('should return 0 for empty array', () => {
  expect(sum([])).toBe(0);
});
// Run: ✗ FAIL - sum is not defined

Requirements:

  • One test at a time
  • Minimal scope
  • Clear failure message
  • Observe the red

GREEN: Implement Simplest Passing Code

// Write only enough code to pass this specific test
function sum(numbers: number[]): number {
  return 0;
}
// Run: ✓ PASS

Requirements:

  • Simplest possible implementation
  • No extra features
  • No optimization
  • Just make it pass

REFACTOR: Improve While Keeping Tests Green

// Now improve the code while tests stay green
function sum(numbers: number[]): number {
  return numbers.reduce((acc, n) => acc + n, 0);
}
// Run: ✓ PASS (still)

Requirements:

  • Tests must stay green
  • Remove duplication
  • Improve clarity
  • No new functionality

Common Rationalizations to Reject

These thoughts indicate you're about to violate TDD:

Rationalization Why It's Wrong
"I can manually test this quickly" Manual testing doesn't prevent regression
"I'll write tests after to save time" You'll skip edge cases and test implementation
"This is too simple to need a test" Simple code changes; tests document expectations
"I've already written the code, I can't delete it now" Sunk cost fallacy; delete it
"I know this works, I've done it before" Your memory isn't documentation
"We're in a hurry" Technical debt costs more than TDD

Practical Application

Starting a New Feature

// 1. RED: Write failing test for simplest behavior
describe('UserValidator', () => {
  it('should reject empty email', () => {
    expect(validateEmail('')).toBe(false);
  });
});

// 2. GREEN: Implement minimal passing code
function validateEmail(email: string): boolean {
  return email.length > 0;
}

// 3. RED: Add next failing test
it('should reject email without @', () => {
  expect(validateEmail('invalid')).toBe(false);
});

// 4. GREEN: Extend to pass both tests
function validateEmail(email: string): boolean {
  return email.length > 0 && email.includes('@');
}

// Continue cycle...

Fixing a Bug

// 1. RED: Write test that exposes the bug
it('should handle negative numbers in sum', () => {
  expect(sum([-1, -2, -3])).toBe(-6);
});
// Run: ✗ FAIL - got 0 instead of -6

// 2. GREEN: Fix the bug
function sum(numbers: number[]): number {
  return numbers.reduce((acc, n) => acc + n, 0);
}
// Run: ✓ PASS

// Bug is now fixed AND protected against regression

Verification Checklist

Before claiming any code is complete:

  • Every production function has corresponding tests
  • Each test was written before its implementation
  • Each test was observed to fail first
  • Tests verify behavior, not implementation
  • Refactoring kept all tests green
  • No production code exists without a test

Content adapted from obra/superpowers by Jesse Vincent (@obra), MIT License.

Source: SKILL.md on GitHub

1 alert17d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub17d

    The skill provides a comprehensive framework and reference guide for software testing, including unit, integration, and security testing. It involves processing user-provided code and API responses, which creates a surface for indirect prompt injection. Automated scanners flagged the documentation link and skill file, likely due to the inclusion of security testing payloads (e.g., SQL injection and XSS strings) used as diagnostic examples in the reference materials.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    1/11 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at efebc44. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.1",
  "domain": "quality",
  "triggers": "test, testing, QA, unit test, integration test, E2E, coverage, performance test, security test, regression, test strategy, test automation, test framework, quality metrics, defect, exploratory, usability, accessibility, localization, manual testing, shift-left, quality gate, flaky test, test maintenance",
  "role": "specialist",
  "scope": "testing",
  "output-format": "report",
  "related-skills": "fullstack-guardian, playwright-expert, devops-engineer, debugging-wizard, code-reviewer, feature-forge"
}
  • Testing
  • jest
  • vitest
  • pytest
  • test-automation
  • coverage
  • performance-testing
  • security-testing
  • e2e
  • quality-assurance

README badge

README badge for jeffallan/claude-skills/test-master

Generates test files, test strategies, and coverage analysis across unit, integration, E2E, performance, and security testing. Includes patterns for Jest, pytest, k6, and OWASP security testing, plus guidance on flaky test isolation, mock strategies, and test architecture design.

Generated from the current SKILL.md.

Does this skill cover performance and security testing, or just unit tests?
It covers functional, performance, and security testing. The skill includes reference guides for k6 and Artillery performance testing, OWASP security methods, and unit/integration/E2E test patterns.
What testing frameworks does this skill support?
It provides patterns for Jest, Vitest, pytest, and general E2E frameworks. The core workflow and assertions patterns are framework-agnostic; specific guidance is loaded from reference guides based on your tool choice.
Does this skill help debug flaky tests?
Yes. The core workflow includes a step to isolate flaky test failures by checking ordering dependencies, async handling, and adding stabilization logic or retries.
Can this skill generate test reports and defect documentation?
Yes. The skill outputs test plans with scope, test cases, coverage analysis, findings with severity ratings, and actionable fix recommendations.
Does this skill enforce mocking and isolation practices?
Yes. It requires mocking external dependencies, prohibits production data in tests, and forbids order-dependent tests. The skill enforces that each test runs independently.

Generated from the current SKILL.md. These answers refresh after source changes.