Agent skill

Directed Test Input Generator

by ArabelaTso in ArabelaTso/Skills-4-SE

Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code.

Apache-2.0Auto-check passedSecurity

Install Directed Test Input Generator

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill directed-test-input-generator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE directed-test-input-generator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/directed-test-input-generator .claude/skills/directed-test-input-generator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
directed-test-input-generator
GitHub stars
253
Token cost
~3k tokens
SKILL.md length
349 words
Files
6 (incl. scripts, references)
Skills in repo
151
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code.

  • Works in 10 steps: Path Analysis and Extraction → Constraint-Based Input Generation → Edge Case Generation → …
  • Targeting uncovered branches
  • SKILL.md covers Overview, Quick Start, Core Techniques and Common Use Cases, plus 4 more sections
  • Runs Python scripts from its folder; calls python

What it does

Directed Test Input Generator is an agent skill from ArabelaTso/Skills-4-SE. Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code. Use when: (1) Targeting uncovered branches or specific execution paths, (2) Need coverage-guided test generation, (3) Want to leverage LLM understanding of code semantics for meaningful test inputs, (4) Testing boundary conditions and edge cases systematically, (5) Combining symbolic reasoning with fuzzing. Provides path analysis, constraint solving, coverage-guided strategies, and LLM-driven semantic generation…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/coverage_strategies.md`, `references/llm_patterns.md` and `scripts/input_generator.py`).

It sits in Security, covering Fuzzing and Test generation. It works with Python. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Targeting uncovered branches
  • Specific execution paths
  • Need coverage-guided test generation
  • Want to leverage LLM understanding of code semantics for meaningful test inputs

Example prompts

  • “/directed-test-input-generator”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Path Analysis and Extraction
  2. Constraint-Based Input Generation
  3. Edge Case Generation
  4. Coverage-Guided Generation
  5. LLM-Driven Semantic Generation
  6. Start with Symbolic Analysis
  7. Generate Diverse Inputs
  8. Use Coverage Feedback
  9. Validate Generated Inputs
  10. Prioritize Hard-to-Reach Paths

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Directed Test Input Generator loads about 3k tokens when it runs, and up to ~9.9k if it reads all its reference files. Until then it costs about 147 tokens; SKILL.md has 349 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~147
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 349 words, ~3,020 tokens.

Download SKILL.mdSave it as .claude/skills/directed-test-input-generator/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
directed-test-input-generator
description
Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code. Use when: (1) Targeting uncovered branches or specific execution paths, (2) Need coverage-guided test generation, (3) Want to leverage LLM understanding of code semantics for meaningful test inputs, (4) Testing boundary conditions and edge cases systematically, (5) Combining symbolic reasoning with fuzzing. Provides path analysis, constraint solving, coverage-guided strategies, and LLM-driven semantic generation for comprehensive test input creation.

Directed Test Input Generator

Generate test inputs that target specific code paths and hard-to-reach behaviors using program analysis, coverage feedback, and LLM-driven semantic understanding.

Overview

Directed test input generation combines multiple techniques to create test inputs that explore specific execution paths:

  1. Path Analysis: Extract control flow paths and their constraints
  2. Constraint Solving: Generate inputs satisfying path conditions
  3. Coverage Guidance: Use coverage feedback to iteratively reach new paths
  4. LLM Semantic Understanding: Leverage code understanding for meaningful inputs

Quick Start

Basic Workflow
python
# 1. Analyze code to extract paths
from scripts.path_analyzer import analyze_code_paths

paths = analyze_code_paths(source_code)

# 2. Generate inputs for each path
from scripts.input_generator import generate_test_suite

test_suite = generate_test_suite(paths)

# 3. Execute tests and measure coverage
for path_id, test_data in test_suite.items():
    result = execute_test(function, test_data['inputs'])
    verify_coverage(result, test_data['target_line'])

Core Techniques

1. Path Analysis and Extraction

Extract execution paths and their constraints from code:

python
from scripts.path_analyzer import analyze_code_paths, print_paths

source = """
def validate_age(age, country):
    if age < 0:
        raise ValueError("Invalid age")
    if age < 18:
        return "minor"
    if age >= 65 and country == "US":
        return "senior_us"
    return "adult"
"""

paths = analyze_code_paths(source)
print_paths(paths)

# Output:
# Path #0: exception handler (ValueError) (line 3)
#   Conditions:
#     - age < 0
#
# Path #1: if branch (line 5)
#   Conditions:
#     - age >= 0
#     - age < 18
#
# Path #2: if branch (line 7)
#   Conditions:
#     - age >= 0
#     - age >= 18
#     - age >= 65
#     - country == US
2. Constraint-Based Input Generation

Generate inputs that satisfy specific path constraints:

python
from scripts.input_generator import TestInputGenerator

generator = TestInputGenerator()

# Generate input for path: age >= 65 AND country == "US"
constraints = {
    "age": ["age >= 65"],
    "country": ["country == US"]
}

inputs = generator.generate_for_path(constraints)
# Result: {"age": 65, "country": "US"}
3. Edge Case Generation

Generate boundary values systematically:

python
from scripts.input_generator import EdgeCaseGenerator

# Generate edge cases for integer type
edge_cases = EdgeCaseGenerator.generate_edge_cases(int)
# [0, -1, 1, -2147483648, 2147483647, ...]

# Generate boundary values around a threshold
boundaries = EdgeCaseGenerator.generate_boundary_values(">", 65)
# [64, 65, 66, 67] - values around the boundary
4. Coverage-Guided Generation

Iteratively generate inputs to maximize coverage:

python
def coverage_guided_testing(function, max_iterations=100):
    """
    Generate test inputs guided by coverage feedback.
    """
    covered_lines = set()
    test_corpus = []

    # Start with initial inputs
    current_inputs = generate_seed_inputs(function)

    for i in range(max_iterations):
        # Execute and measure coverage
        new_coverage = execute_with_coverage(function, current_inputs)

        if new_coverage - covered_lines:
            # New coverage reached - save inputs
            test_corpus.append(current_inputs)
            covered_lines.update(new_coverage)

        # Mutate inputs to explore new paths
        current_inputs = mutate_toward_uncovered(current_inputs, covered_lines)

    return test_corpus

See coverage_strategies.md for detailed coverage-guided strategies.

5. LLM-Driven Semantic Generation

Use LLM understanding of code semantics to generate meaningful inputs:

python
# Example: LLM generates semantically appropriate inputs
function_code = """
def book_flight(passenger_age, departure_date, destination_country):
    # ... booking logic
"""

# LLM understands parameter semantics and generates realistic inputs:
llm_generated = [
    {
        "passenger_age": 35,           # Adult
        "departure_date": "2026-06-15",  # Future date
        "destination_country": "US"      # Valid country code
    },
    {
        "passenger_age": 8,            # Child passenger
        "departure_date": "2026-07-20",
        "destination_country": "UK"
    },
    {
        "passenger_age": 72,           # Senior citizen
        "departure_date": "2026-08-10",
        "destination_country": "CA"
    }
]

See llm_patterns.md for comprehensive LLM-driven generation patterns.

Common Use Cases

Use Case 1: Target Specific Branch

Generate input to reach an uncovered branch:

python
# Target: age > 100 branch
def check_age(age):
    if age > 100:
        return "exceptionally_old"  # Want to test this
    return "normal"

# Analyze paths
paths = analyze_code_paths(check_age_source)
target_path = paths[0]  # age > 100 path

# Generate input
generator = TestInputGenerator()
constraints = target_path.get_constraints()
test_input = generator.generate_for_path(constraints)
# Result: {"age": 101}

# Test
assert check_age(**test_input) == "exceptionally_old"
Use Case 2: Systematic Boundary Testing

Test all boundaries in a function:

python
def calculate_discount(age, is_premium):
    if age < 18:
        return 0.0
    elif age < 65:
        return 0.1 if is_premium else 0.05
    else:
        return 0.2 if is_premium else 0.15

# Generate boundary test suite
boundaries = [
    {"age": 17, "is_premium": False},  # Just below 18
    {"age": 18, "is_premium": False},  # Exactly 18
    {"age": 19, "is_premium": True},   # Just above 18
    {"age": 64, "is_premium": False},  # Just below 65
    {"age": 65, "is_premium": True},   # Exactly 65
    {"age": 66, "is_premium": False},  # Just above 65
]

for inputs in boundaries:
    result = calculate_discount(**inputs)
    print(f"{inputs} -> {result}")
Use Case 3: Coverage-Driven Exploration

Maximize code coverage through iterative generation:

python
def complex_function(x, y, z):
    if x > 10:
        if y < 5:
            if z == 0:
                return "path_A"  # Hard to reach
    elif x < 0:
        if y > 10:
            return "path_B"
    return "default"

# Coverage-guided approach
covered = set()
test_inputs = []

# Iteration 1: Try random input
input_1 = {"x": 5, "y": 3, "z": 1}
coverage_1 = execute_with_coverage(complex_function, input_1)
# Covers: default path

# Iteration 2: Mutate toward uncovered (x > 10)
input_2 = {"x": 11, "y": 7, "z": 1}
coverage_2 = execute_with_coverage(complex_function, input_2)
# Covers: x > 10 but not y < 5

# Iteration 3: Refine toward (y < 5)
input_3 = {"x": 11, "y": 4, "z": 1}
coverage_3 = execute_with_coverage(complex_function, input_3)
# Covers: x > 10 and y < 5 but not z == 0

# Iteration 4: Target (z == 0)
input_4 = {"x": 11, "y": 4, "z": 0}
result = complex_function(**input_4)
# SUCCESS: Reached "path_A"

Advanced Strategies

Hybrid Approach: Combining Techniques
python
def hybrid_test_generation(function_source):
    """
    Combine multiple techniques for comprehensive coverage.
    """
    # 1. Symbolic analysis - extract paths
    paths = analyze_code_paths(function_source)

    # 2. Constraint solving - generate initial inputs
    symbolic_inputs = [generate_for_path(p.get_constraints()) for p in paths]

    # 3. Edge case generation - add boundary values
    edge_inputs = generate_edge_cases_for_function(function_source)

    # 4. LLM semantic generation - add realistic scenarios
    llm_inputs = query_llm_for_realistic_inputs(function_source)

    # 5. Coverage-guided refinement - fill gaps
    all_inputs = symbolic_inputs + edge_inputs + llm_inputs
    coverage = measure_coverage(all_inputs)

    # 6. Mutate to reach remaining uncovered paths
    refined_inputs = coverage_guided_mutation(all_inputs, coverage)

    return refined_inputs
Branch Distance Minimization

Guide input generation toward uncovered branches:

python
def minimize_branch_distance(target_condition, current_input):
    """
    Adjust input to get closer to satisfying target condition.

    Example:
        Target: x > 100
        Current: x = 50
        Distance: 100 - 50 + 1 = 51

        New input: x = 101 (distance = 0)
    """
    variable = target_condition.variable
    operator = target_condition.operator
    threshold = target_condition.value

    if operator == ">":
        return {**current_input, variable: threshold + 1}
    elif operator == "<":
        return {**current_input, variable: threshold - 1}
    elif operator == ">=":
        return {**current_input, variable: threshold}
    elif operator == "<=":
        return {**current_input, variable: threshold}
    elif operator == "==":
        return {**current_input, variable: threshold}

    return current_input

Reference Documentation

Detailed Coverage Strategies

See coverage_strategies.md for:

  • Branch distance minimization
  • Gradient-based input adjustment
  • Symbolic constraint solving
  • Mutation-based fuzzing
  • Hybrid coverage-guided + LLM approaches
LLM-Driven Patterns

See llm_patterns.md for:

  • Semantic input generation
  • Path-directed generation with LLM
  • Domain knowledge integration
  • Adversarial input generation
  • Property-based test generation
  • Multi-step scenario generation

Best Practices

1. Start with Symbolic Analysis

Extract paths first to understand what needs to be tested:

python
paths = analyze_code_paths(source)
print(f"Found {len(paths)} paths to cover")
2. Generate Diverse Inputs

Combine multiple generation strategies:

  • Constraint solving for known paths
  • Edge cases for boundaries
  • LLM for semantic realism
  • Fuzzing for unexpected cases
3. Use Coverage Feedback

Monitor coverage and adjust strategy:

python
if coverage_improvement < 0.01:
    # Switch from symbolic to fuzzing
    switch_to_mutation_based()
4. Validate Generated Inputs

Always check that generated inputs are valid:

python
def validate_input(inputs, function_signature):
    required_params = get_parameters(function_signature)
    assert all(p in inputs for p in required_params)
5. Prioritize Hard-to-Reach Paths

Focus on paths requiring specific conditions:

python
# Prioritize deeply nested conditions
priority_paths = [p for p in paths if len(p.conditions) > 3]

Tools Reference

Scripts

path_analyzer.py - Extract control flow paths and constraints from Python code

bash
python scripts/path_analyzer.py < your_code.py

input_generator.py - Generate test inputs satisfying path constraints

bash
python scripts/input_generator.py --paths paths.json
Example Workflow
python
from scripts.path_analyzer import analyze_code_paths
from scripts.input_generator import generate_test_suite

# 1. Analyze code
source = open("my_module.py").read()
paths = analyze_code_paths(source)

# 2. Generate inputs
test_suite = generate_test_suite(paths)

# 3. Run tests
for path_id, test_data in test_suite.items():
    print(f"Testing path {path_id}: {test_data['description']}")
    result = my_function(**test_data['inputs'])
    print(f"  Result: {result}")

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/directed-test-input-generator of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/coverage_strategies.md
  • references/llm_patterns.md
  • scripts/__pycache__/path_analyzer.cpython-36.pyc
  • scripts/input_generator.py
  • scripts/path_analyzer.py

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Directed Test Input Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Directed Test Input Generator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Directed Test Input Generator this skillArabelaTso/Skills-4-SE253—~3kAutomated safety check: PassApache-2.0
Kernel Testingmohitmishra786/low-level-dev-skills253—~1.4kAutomated safety check: PassMIT
Vibe Fuzz Parser Inputsash1794/vibe-engineering162—~689Automated safety check: PassMIT
Concurrency Fuzzing Testingdzhalaevd/Donatello135—~3.3kAutomated safety check: PassApache-2.0
Simplified Python Fuzzeropensage-agent/opensage-adk127—~228Automated safety check: PassApache-2.0
Fuzzing Pythonbenchflow-ai/skillsbench1.8k—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Kernel Testing

    mohitmishra786/low-level-dev-skills

    Linux kernel testing skill for KUnit, kselftest, syzkaller, and LTP.

    253 GitHub stars~1.4k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Vibe Fuzz Parser Inputs

    ash1794/vibe-engineering

    Generates fuzz test scaffolding for parsers handling external input (YAML, JSON, config files, user input).

    162 GitHub stars~689 tokensUpdated today
    Testing & QAAuto-check passed
  • Concurrency Fuzzing Testing

    dzhalaevd/Donatello

    Use as the lead skill when Python tests must expose scheduler/interleaving bugs in asyncio, threading, queues, workers, databases, caches, or mixed-concurrency code

    135 GitHub stars~3.3k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Simplified Python Fuzzer

    opensage-agent/opensage-adk

    Run a Python fuzzer script (provided as a string) for a fixed duration.

    127 GitHub stars~228 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Fuzzing Python

    benchflow-ai/skillsbench

    Creating fuzz driver for Python libraries using LibFuzzer. An agent skill from benchflow-ai/skillsbench.

    1.8k GitHub stars~4.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Adk Verify Snippets

    google/adk-python

    Official

    Checks that every Python code block in a Markdown file actually compiles and runs, by extracting each block to a temporary file, executing it in an isolated subprocess, and writing a pass/fail…

    22k GitHub stars~1.4k tokensUpdated today
    Testing & QAAuto-check passed

More from ArabelaTso/Skills-4-SE

All 151 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Directed Test Input Generator

What does Directed Test Input Generator do?

Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code. Directed Test Input Generator is an agent skill from ArabelaTso/Skills-4-SE. Generate targeted test inputs to reach specific code paths and hard-to-reach behaviors in Python code.

When should I use Directed Test Input Generator?

Directed Test Input Generator fits situations like: targeting uncovered branches; specific execution paths; need coverage-guided test generation; want to leverage LLM understanding of code semantics for meaningful test inputs.

How do I install Directed Test Input Generator in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill directed-test-input-generator -a claude-code`. Or copy the skill folder (skills/directed-test-input-generator in ArabelaTso/Skills-4-SE) into .claude/skills/directed-test-input-generator in your project. Claude Code loads it when a task matches its description.

How do I install Directed Test Input Generator in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill directed-test-input-generator -a codex`. Or copy the skill folder (skills/directed-test-input-generator in ArabelaTso/Skills-4-SE) into .agents/skills/directed-test-input-generator in your project. Codex loads it when a task matches its description.

Can I use Directed Test Input Generator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill directed-test-input-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/directed-test-input-generator, .gemini/skills/directed-test-input-generator, .github/skills/directed-test-input-generator and .opencode/skills/directed-test-input-generator in your project.

What does Directed Test Input Generator need to run?

Going by SKILL.md and its folder, Directed Test Input Generator needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Directed Test Input Generator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Directed Test Input Generator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Directed Test Input Generator use?

Directed Test Input Generator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Directed Test Input Generator use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.8k tokens, read only when the agent opens those files.

What are the alternatives to Directed Test Input Generator?

Skills that share tags, products or a category with Directed Test Input Generator: Kernel Testing (mohitmishra786/low-level-dev-skills, 253 stars), Vibe Fuzz Parser Inputs (ash1794/vibe-engineering, 162 stars), Concurrency Fuzzing Testing (dzhalaevd/Donatello, 135 stars) and Simplified Python Fuzzer (opensage-agent/opensage-adk, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Directed Test Input Generator?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 151 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.