Official agent skill

Cws Iouring Coverage

by DataDog in DataDog/datadog-agent

Audit CWS (runtime-security) iouring functional-test coverage and add a functional test for any iouring opcode whose operation CWS observes but that is not exercised through iouring.

OfficialApache-2.0Auto-check passedTesting & QA

Install Cws Iouring Coverage

skills CLI
$ npx skills add DataDog/datadog-agent --skill cws-iouring-coverage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DataDog/datadog-agent cws-iouring-coverage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DataDog/datadog-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cws-iouring-coverage .claude/skills/cws-iouring-coverage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cws-iouring-coverage
GitHub stars
3.8k
Token cost
~1.2k tokens
SKILL.md length
567 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit CWS (runtime-security) iouring functional-test coverage and add a functional test for any iouring opcode whose operation CWS observes but that is not exercised through iouring.

  • Works in 4 steps: Rule scope. The test process is… → Submit. iour, err := iouring.New(1);… → Kernel gate, not errno skip. Gate… → …
  • Auditing iouring test coverage
  • SKILL.md covers Principle: tests are the only…, The audit: build three lists,…, Writing the io_uring test and Verify, plus 1 more section
  • Calls go; reaches man7.org

What it does

Cws Iouring Coverage is an agent skill from DataDog/datadog-agent, published by the product's own GitHub organization. Audit CWS (runtime-security) iouring functional-test coverage and add a functional test for any iouring opcode whose operation CWS observes but that is not exercised through iouring. Test-driven — coverage is judged by tests, never by reading eBPF/hook internals. Use when auditing iouring test coverage or after new IORINGOP opcodes appear.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Test coverage and Test-driven development. The repository describes itself as: Main repository for Datadog Agent. The licence is Apache-2.0.

When your agent uses it

  • Auditing iouring test coverage
  • After new IORINGOP opcodes appear

Example prompts

  • “/cws-iouring-coverage”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Rule scope. The test process is testsuite. Many rules are scoped to
  2. Submit. iour, err := iouring.New(1); submit the op; read the result; in the validation
  3. Kernel gate, not errno skip. Gate "kernel too old for this opcode" deterministically at
  4. ebpfless. Only matters if the parent test is in the available list (~-prefixed

What it can do on your machine

Read from SKILL.md and the folder at commit 20eff25. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • man7.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cws Iouring Coverage loads about 1.2k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 567 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DataDog/datadog-agent at commit 20eff25, republished under its Apache-2.0 licence (© DataDog). 567 words, ~1,151 tokens.

Download SKILL.mdSave it as .claude/skills/cws-iouring-coverage/SKILL.md (or your agent's skills folder).
name
cws-iouring-coverage
description
Audit CWS (runtime-security) io_uring functional-test coverage and add a functional test for any io_uring opcode whose operation CWS observes but that is not exercised through io_uring. Test-driven — coverage is judged by tests, never by reading eBPF/hook internals. Use when auditing io_uring test coverage or after new IORING_OP_ opcodes appear.

CWS io_uring test coverage audit

For every io_uring operation CWS observes, there must be a functional test that issues the operation through io_uring and asserts the event fires. This skill finds the gaps and fills them.

Principle: tests are the only arbiter

Coverage is decided by tests, nothing else. Do not read eBPF programs or C hooks (anything under pkg/security/ebpf/) to judge coverage — implementation is out of scope and misleads. The only question is: does an io_uring test exist for this operation, and does it pass?

The one io_uring-specific fact (it's a test assertion, not implementation): io_uring completes asynchronously, so every io_uring test must assert event.async == true.

The audit: build three lists, then intersect

List A — io_uring opcodes. WebFetch https://man7.org/linux/man-pages/man2/io_uring_enter.2.html and list every IORING_OP_* with the syscall it performs (e.g. IORING_OP_SOCKET → socket(2)). Offline fallback: the iouring-go fork is replaced in go.mod — import path stays github.com/iceber/iouring-go, but source on disk is under $(go env GOMODCACHE)/github.com/lebauce/iouring-go@*/syscall/types.go.

List B — tested syscalls. Read pkg/security/tests/. A syscall is tested when a test issues it as the triggering action (inside the func() error {…} passed to WaitSignal/runSyscallTester) and asserts an event — not when it only appears as setup. Build the list from test bodies, not event names: the asserted event may be named differently.

List C — tested io_uring opcodes. grep -rn 'iouring\.\|io_uring' pkg/security/tests/*.go. Mostly t.Run("io_uring", …) subtests plus a few standalone funcs.

Conclude, per opcode in A:

  • syscall ∉ B → out of scope (CWS doesn't observe it; no io_uring test expected).
  • syscall ∈ B → in scope; then opcode ∈ C → tested, else → gap.

Write a test for every gap.

Show full SKILL.md (309 more words)Show less

Writing the io_uring test

Model on an existing subtest (open_test.go → t.Run("io_uring", …)). For each gap:

  1. Rule scope. The test process is testsuite. Many rules are scoped to process.file.name == "syscall_tester"; reuse the parent rule only if it already admits testsuite (e.g. in [ "syscall_tester", "testsuite" ]), otherwise add a new rule scoped to process.file.name == "testsuite". Check the parent's ruleDefs first.
  2. Submit. iour, err := iouring.New(1); submit the op; read the result; in the validation callback assert event type, key fields, and event.async == true.
  3. Kernel gate, not errno skip. Gate "kernel too old for this opcode" deterministically at the top of the subtest: checkKernelCompatibility(t, "io_uring <op> needs Linux X.Y", func(kv *kernel.Version) bool { return kv.Code < kernel.VersionCode(X, Y, 0) }). Don't skip on a negative errno — a malformed raw SQE returns one too, so skipping would hide the gap behind a green test. On a supported kernel, treat an unexpected negative result as a failure (return fmt.Errorf(...)). (A library prep helper can't be malformed, so an errno skip there is harmless.)
  4. ebpfless. Only matters if the parent test is in the available list (~-prefixed entries) in pkg/security/tests/main_linux.go — those prefix-match subtests and pull yours into the ebpfless run, where io_uring is unsupported. If so, add an exclude entry. The match is exact on the full t.Name(), so prefer a flat sibling name (TestOpen/io_uring_ftruncate, not a nested TestOpen/io_uring/ftruncate).

No prep helper in the fork? The fork wraps only a subset. For other opcodes build a raw SQE with a custom iouring.PrepRequest using the helpers in pkg/security/tests/iouring_test.go (extend them as needed). This is the one place you may touch an opcode's low-level shape.

Verify

  • gofmt -l <your files> (no output = OK).
  • Run the test via the harness: dda inv security-agent.functional-tests --skip-linters --testflags="-test.run <YourTest>". Green = covered, red = the gap is real.

Report

Report the per-opcode classification (out of scope / tested / gap) and the test files added or changed.

© DataDog, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/cws-iouring-coverage of DataDog/datadog-agent.

Open the folder on GitHubat commit 20eff25

Compare with similar skills

Cws Iouring Coverage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cws Iouring Coverage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cws Iouring Coverage this skillDataDog/datadog-agent3.8k—~1.2kAutomated safety check: PassApache-2.0
Designing TestsCloudAI-X/opencode-workflow275—~2.9kAutomated safety check: PassMIT
Automated Test Planningtestdouble/han279—~6.7kAutomated safety check: PassMIT
Test Writerhamzafarooq/claude-code-starter145—~345Automated safety check: PassMIT
Manual Test Planningtestdouble/han279—~2.9kAutomated safety check: PassMIT
Test Experteinverne/dotfiles121—~2.3kAutomated safety check: PassGPL-3.0

Similar skills

  • Designing Tests

    CloudAI-X/opencode-workflow

    Guides test strategy, TDD/BDD approaches, test coverage planning, and testing best practices.

    275 GitHub stars~2.9k tokensUpdated 9 mo ago
    Testing & QAAuto-check passed
  • Produce a standalone test plan by analyzing code for test coverage gaps and edge cases.

    279 GitHub stars~6.7k tokensUpdated 7 days ago
    Testing & QAAuto-check passed
  • Test Writer

    hamzafarooq/claude-code-starter

    Write unit tests for any function — happy path, edge cases, and error cases.

    145 GitHub stars~345 tokensUpdated 25 days ago
    Testing & QAAuto-check passed
  • Manual Test Planning

    testdouble/han

    Produce a plain-language manual test plan from the context supplied to it — an executive summary, a high-level list of named tests, and a detail section per test with the steps a person follows by…

    279 GitHub stars~2.9k tokensUpdated 7 days ago
    Testing & QAAuto-check passed
  • Test Expert

    einverne/dotfiles

    Testing methodologies, test-driven development (TDD), unit and integration testing, and testing best practices across multiple frameworks.

    121 GitHub stars~2.3k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Ab Test Mission

    ayoubben18/ab-method

    Add retroactive test coverage for code that was not written test-first.

    192 GitHub stars~342 tokensUpdated 7 days ago
    Testing & QAAuto-check passed

More from DataDog/datadog-agent

All 35 skills in this repo
  • Triage CI Failure

    DataDog/datadog-agent

    Official

    Classify a failed CI as either caused by an active incident, flakiness, or a true code regression.

    3.8k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Elicit

    DataDog/datadog-agent

    Official

    Run a structured discovery session to build an Allium specification through conversation.

    3.8k GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Follow PR

    DataDog/datadog-agent

    Official

    Monitor the current PR's GitLab pipeline to completion, then report success, auto-fix, or investigate a failure.

    3.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Create Epic Recap

    DataDog/datadog-agent

    Official

    A skill your agent uses when an engineer or manager asks to recap, summarize, or post an update on a Jira Epic — a progress update for an in-progress Epic (how far along it is, what's shipped so…

    3.8k GitHub stars~5k tokensUpdated today
    Auto-check: notes
  • Explain Lading Config

    DataDog/datadog-agent

    Official

    Explains a lading.yaml config file from the regression test suite, using the lading Rust source as ground truth for field meanings and defaults.

    3.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Distill

    DataDog/datadog-agent

    Official

    Extract an Allium specification from an existing codebase. An agent skill from DataDog/datadog-agent.

    3.8k GitHub starsUsed in 1 repo~7k tokens
    Auto-check passed

Categories

Questions about Cws Iouring Coverage

What does Cws Iouring Coverage do?

Audit CWS (runtime-security) iouring functional-test coverage and add a functional test for any iouring opcode whose operation CWS observes but that is not exercised through iouring. Cws Iouring Coverage is an agent skill from DataDog/datadog-agent, published by the product's own GitHub organization. Audit CWS (runtime-security) iouring functional-test coverage and add a functional test for any iouring opcode whose operation CWS observes but that is not exercised through iouring.

When should I use Cws Iouring Coverage?

Cws Iouring Coverage fits situations like: auditing iouring test coverage; after new IORINGOP opcodes appear.

How do I install Cws Iouring Coverage in Claude Code?

Run `npx skills add DataDog/datadog-agent --skill cws-iouring-coverage -a claude-code`. Or copy the skill folder (.agents/skills/cws-iouring-coverage in DataDog/datadog-agent) into .claude/skills/cws-iouring-coverage in your project. Claude Code loads it when a task matches its description.

How do I install Cws Iouring Coverage in Codex?

Run `npx skills add DataDog/datadog-agent --skill cws-iouring-coverage -a codex`. Or copy the skill folder (.agents/skills/cws-iouring-coverage in DataDog/datadog-agent) into .agents/skills/cws-iouring-coverage in your project. Codex loads it when a task matches its description.

Can I use Cws Iouring Coverage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DataDog/datadog-agent --skill cws-iouring-coverage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cws-iouring-coverage, .gemini/skills/cws-iouring-coverage, .github/skills/cws-iouring-coverage and .opencode/skills/cws-iouring-coverage in your project.

What does Cws Iouring Coverage need to run?

Going by SKILL.md and its folder, Cws Iouring Coverage needs the command-line tools its instructions call (go).

Does Cws Iouring Coverage access the network?

SKILL.md names 1 domain. In commands or code: man7.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cws Iouring Coverage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cws Iouring Coverage use?

Cws Iouring Coverage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cws Iouring Coverage use?

About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cws Iouring Coverage?

Skills that share tags, products or a category with Cws Iouring Coverage: Designing Tests (CloudAI-X/opencode-workflow, 275 stars), Automated Test Planning (testdouble/han, 279 stars), Test Writer (hamzafarooq/claude-code-starter, 145 stars) and Manual Test Planning (testdouble/han, 279 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cws Iouring Coverage?

DataDog (a GitHub organization, an official publisher) maintains it in DataDog/datadog-agent, which has 3,757 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on October 8, 2026.

Source: DataDog/datadog-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.