Security Updates
SmilyOrg/photofield
Check and apply security updates across the photofield project (api/Go, ui/npm, docs/npm, e2e/npm).
A skill your agent uses when planning or reviewing tests for a code change, choosing between unit, focused regression, integration, contract, end-to-end, performance, security, property-based, or…
$ npx skills add AnastasiyaW/codex-claude-code-config --skill testing-strategy -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config testing-strategy --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/development/testing-strategy .claude/skills/testing-strategy && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "testing-strategy" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/testing-strategy into .claude/skills/testing-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-strategy", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/testing-strategyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add AnastasiyaW/codex-claude-code-config --skill testing-strategy -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config testing-strategy --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/development/testing-strategy .agents/skills/testing-strategy && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "testing-strategy" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/testing-strategy into .agents/skills/testing-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-strategy", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AnastasiyaW/codex-claude-code-config --skill testing-strategy -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config testing-strategy --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/development/testing-strategy .cursor/skills/testing-strategy && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "testing-strategy" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/testing-strategy into .cursor/skills/testing-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-strategy", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/AnastasiyaW/codex-claude-code-config.git --path skills/development/testing-strategy--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add AnastasiyaW/codex-claude-code-config --skill testing-strategy -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config testing-strategy --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/development/testing-strategy .gemini/skills/testing-strategy && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "testing-strategy" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/testing-strategy into .gemini/skills/testing-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-strategy", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install AnastasiyaW/codex-claude-code-config testing-strategyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add AnastasiyaW/codex-claude-code-config --skill testing-strategy -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/development/testing-strategy .github/skills/testing-strategy && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "testing-strategy" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/testing-strategy into .github/skills/testing-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-strategy", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add AnastasiyaW/codex-claude-code-config --skill testing-strategy -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install AnastasiyaW/codex-claude-code-config testing-strategy --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/AnastasiyaW/codex-claude-code-config.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/development/testing-strategy .opencode/skills/testing-strategy && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "testing-strategy" agent skill from https://github.com/AnastasiyaW/codex-claude-code-config/tree/main/skills/development/testing-strategy into .opencode/skills/testing-strategy/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "testing-strategy", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
testing-strategyA skill your agent uses when planning or reviewing tests for a code change, choosing between unit, focused regression, integration, contract, end-to-end, performance, security, property-based, or…
Testing Strategy is an agent skill from AnastasiyaW/codex-claude-code-config. Use when planning or reviewing tests for a code change, choosing between unit, focused regression, integration, contract, end-to-end, performance, security, property-based, or agent-evaluation checks; classify change risk first and select the smallest evidence set that proves the behavior. Do not use for a single obvious test command, pure documentation changes, or a full security audit without a testing question.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Testing & QA, covering Test strategy, Agent evaluation and testing and Security review. The repository describes itself as: Claude Code, Codex, and multi-agent configuration system: principles, hooks, skills, and workflow patterns for AI-assisted development. The licence is MIT.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 67709af. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Testing Strategy loads about 2k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 1,049 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from AnastasiyaW/codex-claude-code-config at commit 67709af, republished under its MIT licence (© AnastasiyaW). 1,049 words, ~2,016 tokens.
.claude/skills/testing-strategy/SKILL.md (or your agent's skills folder).Testing is an evidence-selection problem, not a contest to run the largest
suite. Choose the smallest set that can falsify the changed behavior, then add
one higher-level check only when it covers a boundary the lower level cannot.
Keep execution environments reusable, but separate their evidence profiles:
staging-smoke, security-proof, release-attestation, and nightly-stress.
Use harness-feedback when a gate is reported as overloaded or misplaced.
BLOCKED; do not rerun unrelated accepted
code merely because the following environment is unavailable.| Change | Required evidence | Usually deferred |
|---|---|---|
| Docs, comments, formatting only | Link/lint check when relevant | Runtime suite |
| Pure function, local refactor | Fast checks + focused unit/regression tests | Full E2E, mutation |
| Parser, serializer, file, DB, API adapter | Fast + focused + one real boundary/integration check | Browser E2E unless user flow changes |
| Auth, permissions, migrations, concurrency, public API, deployment | Fast + focused + integration/contract + targeted smoke; independent review for non-trivial changes | Full load test unless performance is in scope |
| UI or user journey | Fast + component/focused checks + one stable E2E smoke | Large browser matrix |
| Release or performance claim | All applicable lower levels + fixed benchmark/security/release evidence | Nothing that is part of the claim |
The Stop hook runs the project's fast/default suite only when the working tree
contains code or test changes. Projects with a complex suite may declare
.claude/test-policy.json:
{
"fast": ["python", "-m", "pytest", "-q", "tests/unit"],
"integration": ["python", "-m", "pytest", "-q", "tests/integration"],
"release": ["python", "-m", "pytest", "-q"]
}fast is the automatic Stop gate. integration is additionally selected for
high-risk changes when present. release is explicit or CI-only; do not make
every edit pay the release-suite cost. Optional profiles make the separation
explicit; a staging profile must not contain release-signing requirements.
An agent must report: revision, changed scope, commands actually run, exit status, relevant counts, environment constraints, and checks not run with a reason. “Tests passed” without command output or a durable evidence file is not proof. A generated test is a candidate until it reproduces the failure or asserts a stable contract; do not add broad snapshot tests merely to inflate coverage.
For a confirmed bug use bug-reproducer: reproduce first, then fix, then run
the same test again. For a large/high-risk change use proof-verify: a fresh
context must produce the final verdict. For a safe structural refactor use
refactoring-safely and characterization tests before the transformation.
skip/xfail to make red tests look
green. A flaky test needs a cause, a bounded quarantine reason, or a fix.release-attestation.| Symptom | Likely cause | Action |
|---|---|---|
| Stop gate runs in a docs-only change | Project has no Git-visible status or a broad override | Check git status; keep the default command scoped in .claude/test-policy.json |
| Fast suite passes, integration fails | A real boundary was changed or mocked away | Add/fix the boundary test; do not weaken the fast gate |
| E2E is flaky | Timing, shared state, browser/environment dependency | Make state isolated and waits explicit; reduce E2E to a stable smoke |
| Generated test passes without exposing the bug | Test asserts implementation details or never goes red | Reproduce the pre-fix failure and assert the user-visible invariant |
| Agent claims completion with skipped checks | Missing evidence contract or verifier | Record the skip reason and run proof-verify for high-risk work |
| Agent says the harness is too strict or blocks smoke | Profiles are coupled or a gate is misplaced | Invoke harness-feedback; capture the blocker, split profiles, and rerun the reduced smoke |
| A later audit asks to repeat a green earlier stage | Proof identity was not recorded, or its source/input changed | Check the stage receipt; reuse a sealed matching receipt or record a superseding stage |
© AnastasiyaW, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/development/testing-strategy of AnastasiyaW/codex-claude-code-config.
Open the folder on GitHubat commit 67709af
Testing Strategy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Testing Strategy this skillAnastasiyaW/codex-claude-code-config | 154 | — | ~2k | Automated safety check: Pass | MIT | |
| Security UpdatesSmilyOrg/photofield | 608 | — | ~808 | Automated safety check: Pass | MIT | |
| Moai Ref Testing Pyramidmodu-ai/moai-adk | 1.2k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Testing QAaiskillstore/marketplace | 433 | 3 repos | ~1.2k | Automated safety check: Pass | None | |
| Testingnotque/vexjoy-agent | 441 | — | ~4.7k | Automated safety check: Notes | MIT | |
| Plan Testsgenkovich/sdd | 171 | — | ~3.1k | Automated safety check: Pass | MIT |
SmilyOrg/photofield
Check and apply security updates across the photofield project (api/Go, ui/npm, docs/npm, e2e/npm).
modu-ai/moai-adk
Test pyramid strategy, coverage targets, test patterns, and quality metrics reference.
aiskillstore/marketplace
Comprehensive testing and QA workflow covering unit testing, integration testing, E2E testing, browser automation, and quality assurance.
notque/vexjoy-agent
Testing: TDD, E2E, preferred patterns, test-value audits, verification, agent testing.
genkovich/sdd
A skill your agent uses to turn a feature's acceptance criteria into a test plan before any test is written — a table that maps every spec.md §5 acceptance criterion to at least one test, names the…
HKUDS/OpenHarness
Validates OpenHarness features by running real multi-turn agent loops with live LLM calls against an unfamiliar codebase, checking actual tool execution.
AnastasiyaW/codex-claude-code-config
Find likely software bugs in a codebase, rank concrete bug candidates, and prove or reject them with focused regression tests before proposing a fix.
AnastasiyaW/codex-claude-code-config
A skill your agent uses when implementing Motion or Framer Motion in React/JavaScript: interactive UI components, micro-interactions, gestures, layout or page transitions, and scroll-based animation.
AnastasiyaW/codex-claude-code-config
Plan-based verification - freeze acceptance criteria before building, then verify after with an independent fresh-context agent (the builder must not verify their own work).
AnastasiyaW/codex-claude-code-config
Написание и запуск Claude Code dynamic workflows (JS-оркестратор субагентов).
AnastasiyaW/codex-claude-code-config
A skill your agent uses when: NotebookLM, notebooklm MCP, large documentation sets, courses, books, papers, or citation-backed research are mentioned.
AnastasiyaW/codex-claude-code-config
Validate a proposed DeepSeek API integration before any key or project context is sent: check thinking-mode tool-call history, strict-schema assumptions, bounded output, and provider data boundaries.
Categories
A skill your agent uses when planning or reviewing tests for a code change, choosing between unit, focused regression, integration, contract, end-to-end, performance, security, property-based, or…. Testing Strategy is an agent skill from AnastasiyaW/codex-claude-code-config. Use when planning or reviewing tests for a code change, choosing between unit, focused regression, integration, contract, end-to-end, performance, security, property-based, or agent-evaluation checks; classify change risk first and select the smallest evidence set that proves the behavior.
Testing Strategy fits situations like: reviewing tests for a code change; choosing between unit; focused regression; agent-evaluation checks.
Run `npx skills add AnastasiyaW/codex-claude-code-config --skill testing-strategy -a claude-code`. Or copy the skill folder (skills/development/testing-strategy in AnastasiyaW/codex-claude-code-config) into .claude/skills/testing-strategy in your project. Claude Code loads it when a task matches its description.
Run `npx skills add AnastasiyaW/codex-claude-code-config --skill testing-strategy -a codex`. Or copy the skill folder (skills/development/testing-strategy in AnastasiyaW/codex-claude-code-config) into .agents/skills/testing-strategy in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add AnastasiyaW/codex-claude-code-config --skill testing-strategy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/testing-strategy, .gemini/skills/testing-strategy, .github/skills/testing-strategy and .opencode/skills/testing-strategy in your project.
Going by SKILL.md and its folder, Testing Strategy needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Testing Strategy is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Testing Strategy: Security Updates (SmilyOrg/photofield, 608 stars), Moai Ref Testing Pyramid (modu-ai/moai-adk, 1.2k stars), Testing QA (aiskillstore/marketplace, 433 stars) and Testing (notque/vexjoy-agent, 441 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
AnastasiyaW (a GitHub user) maintains it in AnastasiyaW/codex-claude-code-config, which has 154 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 9, 2026.
Source: AnastasiyaW/codex-claude-code-config on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.