Write correct and complete RSpec tests for Doorkeeper. An agent skill from doorkeeper-gem/doorkeeper.

MITAuto-check passedTesting & QA

Install Testing

skills CLI
$ npx skills add doorkeeper-gem/doorkeeper --skill testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install doorkeeper-gem/doorkeeper testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/doorkeeper-gem/doorkeeper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/testing .claude/skills/testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
testing
GitHub stars
5.5k
Token cost
~1.6k tokens
SKILL.md length
359 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Write correct and complete RSpec tests for Doorkeeper. An agent skill from doorkeeper-gem/doorkeeper.

  • Works in 5 steps: Happy path — the feature works as intended → Error cases — invalid input, missing… → Edge cases — nil values, empty strings,… → …
  • Adding specs for new features
  • SKILL.md covers Test Organization, Spec Conventions, Test Patterns and What to Test, plus 2 more sections
  • Calls bundle

What it does

Testing is an agent skill from doorkeeper-gem/doorkeeper. Write correct and complete RSpec tests for Doorkeeper. Use when adding specs for new features, writing regression tests for bug fixes, or reviewing test coverage for a change.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Debugging, OAuth and OpenID Connect and Test coverage. It works with Ruby on Rails. The repository describes itself as: Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. The licence is MIT.

When your agent uses it

  • Adding specs for new features
  • Writing regression tests for bug fixes
  • Reviewing test coverage for a change

Example prompts

  • “/testing”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Happy path — the feature works as intended
  2. Error cases — invalid input, missing parameters, unauthorized access
  3. Edge cases — nil values, empty strings, boundary conditions
  4. Configuration interaction — does it respect relevant config options?
  5. Backward compatibility — does existing behavior still pass?

What it can do on your machine

Read from SKILL.md and the folder at commit 80f4eba. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bundle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Testing loads about 1.6k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 359 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from doorkeeper-gem/doorkeeper at commit 80f4eba, republished under its MIT licence (© doorkeeper-gem). 359 words, ~1,615 tokens.

Download SKILL.mdSave it as .claude/skills/testing/SKILL.md (or your agent's skills folder).
name
testing
description
Write correct and complete RSpec tests for Doorkeeper. Use when adding specs for new features, writing regression tests for bug fixes, or reviewing test coverage for a change.

Testing

When writing or modifying tests in Doorkeeper, use this skill to ensure tests are correct, complete, and follow project conventions.

Test Organization

What you're testingWhere to put the spec
OAuth request/response flow (integration)spec/requests/flows/
Endpoint behavior (HTTP layer)spec/requests/endpoints/
Controller logic (unit)spec/controllers/
Model behavior & mixinsspec/models/doorkeeper/
OAuth protocol logic (unit)spec/lib/oauth/
Configurationspec/lib/config_spec.rb
Generatorsspec/generators/
Routingspec/routing/
Grape integrationspec/grape/

Spec Conventions

Style
ruby
# frozen_string_literal: true

require "spec_helper"

RSpec.describe Doorkeeper::OAuth::SomeClass do
  describe "#method_name" do
    context "when condition is met" do
      it "does the expected thing" do
        # arrange, act, assert
      end
    end
  end
end
Require Line

All specs use require "spec_helper". The spec_helper loads the dummy Rails app, database, factories, and support helpers — it covers both unit and integration needs.

Note: A legacy spec_helper_integration file exists but is just a compatibility wrapper around spec_helper. Do not use it in new specs.

Factories

Factories are in spec/factories.rb. Use FactoryBot:

ruby
let(:application) { FactoryBot.create(:application) }
let(:access_token) { FactoryBot.create(:access_token, application: application) }
let(:access_grant) { FactoryBot.create(:access_grant, application: application) }
Helper Methods

Reuse helpers from spec/support/helpers/:

  • model_helper.rb — client_exists, create_resource_owner, token/grant existence checks
  • request_spec_helper.rb — json_response, should_have_status, url_should_have_param, basic_auth_header_for_client
  • url_helper.rb — token_endpoint_url, authorization_endpoint_url, refresh_token_endpoint_url
  • config_helper.rb — config_is_set (temporarily override config in a block)
  • authorization_request_helper.rb — resource_owner_is_authenticated, default_scopes_exist
Configuration Changes in Tests

Use config_is_set or the Doorkeeper.configure block (resets after each test):

ruby
before do
  config_is_set(:access_token_expires_in, 100)
end

Test Patterns

Request/Flow Specs (most important)
ruby
RSpec.describe "Authorization Code Flow" do
  let(:application) { FactoryBot.create(:application) }
  let(:resource_owner) { User.create!(name: "owner", password: "password") }

  before do
    default_scopes_exist :public
    resource_owner_is_authenticated resource_owner
  end

  it "issues an access token" do
    visit authorization_endpoint_url(client: application)
    click_on "Authorize"

    code = current_params["code"]
    post token_endpoint_url, params: {
      grant_type: "authorization_code",
      code: code,
      redirect_uri: application.redirect_uri,
      client_id: application.uid,
      client_secret: application.secret,
    }

    expect(response).to have_http_status(:ok)
    expect(json_response["access_token"]).to be_present
  end
end
OAuth Unit Specs
ruby
RSpec.describe Doorkeeper::OAuth::AuthorizationCodeRequest do
  subject(:request) do
    described_class.new(server, grant, client, params)
  end

  let(:server) do
    double :server,
           access_token_expires_in: 2.days,
           refresh_token_enabled?: false,
           custom_access_token_expires_in: lambda { |context|
             context.grant_type == Doorkeeper::OAuth::AUTHORIZATION_CODE ? 1234 : nil
           }
  end

  let(:resource_owner) { FactoryBot.create :resource_owner }
  let(:grant) do
    FactoryBot.create :access_grant,
                      resource_owner_id: resource_owner.id,
                      resource_owner_type: resource_owner.class.name
  end
  let(:client) { grant.application }
  let(:redirect_uri) { client.redirect_uri }
  let(:params) { { redirect_uri: redirect_uri } }

  before do
    allow(server).to receive(:option_defined?).with(:custom_access_token_expires_in).and_return(true)
  end

  describe "#authorize" do
    it "issues a new token for the client" do
      expect { request.authorize }.to change { client.reload.access_tokens.count }.by(1)
    end

    it "revokes the grant" do
      expect { request.authorize }.to(change { grant.reload.accessible? })
    end
  end

  describe "#validate" do
    it "requires the grant to be accessible" do
      grant.revoke
      request.validate
      expect(request.error).to eq(Doorkeeper::Errors::InvalidGrant)
    end

    it "requires the client" do
      request = described_class.new(server, grant, nil, params)
      request.validate
      expect(request.error).to eq(Doorkeeper::Errors::InvalidClient)
    end
  end
end

What to Test

For new features:
  1. Happy path — the feature works as intended
  2. Error cases — invalid input, missing parameters, unauthorized access
  3. Edge cases — nil values, empty strings, boundary conditions
  4. Configuration interaction — does it respect relevant config options?
  5. Backward compatibility — does existing behavior still pass?
Show full SKILL.md (135 more words)Show less
For bug fixes:
  1. Regression test — reproduce the exact bug scenario, verify it's fixed
  2. Related edge cases — similar situations that might also be affected
For security fixes:
  1. The vulnerability is no longer exploitable
  2. The fix doesn't break legitimate use cases
  3. Error responses don't leak information

Common Pitfalls

  • Don't use sleep — use Timecop.travel or Timecop.freeze instead
  • Don't hardcode token values — let the system generate them
  • Don't test private methods directly — test through the public interface
  • Don't forget scopes — many features are scope-dependent, set them up explicitly
  • Use Timecop for time-dependent tests (expiration, token lifetime)

Verification

  1. Run new specs in isolation: bundle exec rspec spec/path/to/new_spec.rb
  2. Run the full related directory: bundle exec rspec spec/lib/oauth/
  3. Run full suite: bundle exec rake spec
  4. Specs must pass in any order (--order random)

© doorkeeper-gem, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/testing of doorkeeper-gem/doorkeeper.

Open the folder on GitHubat commit 80f4eba

Compare with similar skills

Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Testing this skilldoorkeeper-gem/doorkeeper5.5k—~1.6kAutomated safety check: PassMIT
Test Gap Auditgithub/awesome-copilot40k—~3.4kAutomated safety check: PassMIT
Test BlindspotsNeeeophytee/finding-unknowns-skills343—~676Automated safety check: PassMIT
Fieldworks Test Coveragesillsdev/FieldWorks110—~1.1kAutomated safety check: PassCustom licence
Write Testsopenplayerjs/openplayerjs649—~1.8kAutomated safety check: PassMIT
Test Specialisttravisjneuman/.claude101—~3.7kAutomated safety check: PassMIT

Similar skills

  • Test Gap Audit

    github/awesome-copilot

    Official

    Run a read-only audit for missing, weak, stale, or mis-scoped test coverage.

    40k GitHub stars~3.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Test Blindspots

    Neeeophytee/finding-unknowns-skills

    Find consequential behavior that a passing test suite does not establish, using focused exploratory checks.

    343 GitHub stars~676 tokensUpdated 9 days ago
    Testing & QAAuto-check passed
  • Fieldworks Test Coverage

    sillsdev/FieldWorks

    Check that new or changed FieldWorks code is actually exercised by tests, using test.ps1 -Coverage.

    110 GitHub stars~1.1k tokensUpdated today
    Testing & QAAuto-check passed
  • Write Tests

    openplayerjs/openplayerjs

    Write or extend Jest tests for OpenPlayerJS to this repo's exact conventions — makeCore factories, typed internals handles instead of as any, media property mocking, fake timers, ads/vast mocks, and…

    649 GitHub stars~1.8k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Test Specialist

    travisjneuman/.claude

    Test-writing patterns for JS/TS, Python, Go, and Rust (unit, integration, E2E, visual regression).

    101 GitHub stars~3.7k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Firewall AI Gateway Debug

    vercel-labs/vercel-openclaw-archived

    Official

    Firewall and Vercel AI Gateway debugging for vercel-openclaw: network policy allowlists, OIDC token refresh, AI Gateway transform rules, firewall learning/enforcement, and sandbox.update…

    117 GitHub stars~550 tokensUpdated 4 mo ago
    DevelopmentAuto-check passed

More from doorkeeper-gem/doorkeeper

  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Code Quality

    doorkeeper-gem/doorkeeper

    Maintain code health and architecture standards when implementing features or refactoring Doorkeeper.

    5.5k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Dependency Safety

    doorkeeper-gem/doorkeeper

    Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper.

    5.5k GitHub stars~931 tokensUpdated yesterday
    Auto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Rfc Compliance

    doorkeeper-gem/doorkeeper

    Verify OAuth protocol implementations stay aligned with relevant RFCs.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Testing

What does Testing do?

Write correct and complete RSpec tests for Doorkeeper. An agent skill from doorkeeper-gem/doorkeeper. Testing is an agent skill from doorkeeper-gem/doorkeeper. Write correct and complete RSpec tests for Doorkeeper.

When should I use Testing?

Testing fits situations like: adding specs for new features; writing regression tests for bug fixes; reviewing test coverage for a change.

How do I install Testing in Claude Code?

Run `npx skills add doorkeeper-gem/doorkeeper --skill testing -a claude-code`. Or copy the skill folder (.agents/skills/testing in doorkeeper-gem/doorkeeper) into .claude/skills/testing in your project. Claude Code loads it when a task matches its description.

How do I install Testing in Codex?

Run `npx skills add doorkeeper-gem/doorkeeper --skill testing -a codex`. Or copy the skill folder (.agents/skills/testing in doorkeeper-gem/doorkeeper) into .agents/skills/testing in your project. Codex loads it when a task matches its description.

Can I use Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add doorkeeper-gem/doorkeeper --skill testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/testing, .gemini/skills/testing, .github/skills/testing and .opencode/skills/testing in your project.

What does Testing need to run?

Going by SKILL.md and its folder, Testing needs the command-line tools its instructions call (bundle).

Does Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Testing use?

Testing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Testing use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Testing?

Skills that share tags, products or a category with Testing: Test Gap Audit (github/awesome-copilot, 40k stars), Test Blindspots (Neeeophytee/finding-unknowns-skills, 343 stars), Fieldworks Test Coverage (sillsdev/FieldWorks, 110 stars) and Write Tests (openplayerjs/openplayerjs, 649 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Testing?

doorkeeper-gem (a GitHub organization) maintains it in doorkeeper-gem/doorkeeper, which has 5,522 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 6, 2026.

Source: doorkeeper-gem/doorkeeper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.