Agent skill

Test Audit

by every-app in every-app/open-seo

Invoke whenever writing, changing, reviewing, or sweeping Vitest tests in this repo.

MITAuto-check passedTesting & QA

Install Test Audit

skills CLI
$ npx skills add every-app/open-seo --skill test-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install every-app/open-seo test-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/every-app/open-seo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/test-audit .claude/skills/test-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
test-audit
GitHub stars
23k
Token cost
~2.8k tokens
SKILL.md length
1,549 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Invoke whenever writing, changing, reviewing, or sweeping Vitest tests in this repo.

  • Works in 4 steps: What observable behavior, invariant, or… → What credible regression makes it fail? → Why does existing coverage not already… → …
  • Asked to add tests
  • SKILL.md covers Authoring gate, Junk patterns, Value bar and Discovery, plus 7 more sections
  • Calls pnpm and git

What it does

Test Audit is an agent skill from every-app/open-seo. Invoke whenever writing, changing, reviewing, or sweeping Vitest tests in this repo. Authoring gate for new or changed tests, plus an audit workflow for low-value, implementation-coupled, or duplicative tests and the test-only production seams they keep alive. Use when asked to add tests, review tests, clean up tests, or when a PR touches .test.ts.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Unit testing. It works with Vitest. The repository describes itself as: Open source alternative to Semrush and Ahrefs. The licence is MIT.

When your agent uses it

  • Asked to add tests
  • A PR touches .test.ts

Example prompts

  • “/test-audit”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. What observable behavior, invariant, or independent contract does it protect?
  2. What credible regression makes it fail?
  3. Why does existing coverage not already catch that failure? Each contract has
  4. Does it need a production seam (export, flag, wrapper, injection hook) that

What it can do on your machine

Read from SKILL.md and the folder at commit deb4491. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Test Audit loads about 2.8k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 1,549 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from every-app/open-seo at commit deb4491, republished under its MIT licence (© every-app). 1,549 words, ~2,823 tokens.

Download SKILL.mdSave it as .claude/skills/test-audit/SKILL.md (or your agent's skills folder).
name
test-audit
description
Invoke whenever writing, changing, reviewing, or sweeping Vitest tests in this repo. Authoring gate for new or changed tests, plus an audit workflow for low-value, implementation-coupled, or duplicative tests and the test-only production seams they keep alive. Use when asked to add tests, review tests, clean up tests, or when a PR touches *.test.ts.
metadata.internal
true

Test Audit

Three modes, one value bar. Authoring mode gates every new or changed test at write time. Audit mode runs focused sweeps for tests that re-assert source, duplicate stronger proof, couple behavior to implementation, or keep test-only production seams alive. Campaign mode reviews every test file with a per-test verdict when the maintainer asks to prune the whole suite; see Campaign mode. Optimize for confidence, not deletion count. Land one coherent batch per PR; continue broad audits as separate follow-ups.

The repository's own rules live in the "Testing" section of AGENTS.md. This skill is the procedure for applying them; when the two disagree, AGENTS.md wins and this file needs an update.

Authoring gate

Before adding a test, answer four questions. A missing answer means do not add it yet:

  1. What observable behavior, invariant, or independent contract does it protect?
  2. What credible regression makes it fail?
  3. Why does existing coverage not already catch that failure? Each contract has one primary owner at the strongest boundary (usually the service or the MCP tool handler, not the repository or a private helper). Another layer needs its own distinct risk. Prefer extending a table-driven case or a shared factory (ga4-test-fixtures.ts, tool-test-support.ts) over a near-duplicate test, and consolidate duplicated setup in the same change.
  4. Does it need a production seam (export, flag, wrapper, injection hook) that no production caller needs? If yes, test at the real boundary instead. Grep the whole repo for callers, not just src/; scripts/ counts.

Then check the test against every junk pattern; a match fails the gate unless the retention bar names the contract it independently guards. A test that would break under behavior-preserving refactoring is asserting implementation, not behavior; rewrite it at the owning boundary before landing it.

Bug regression tests must fail on the pre-fix code for the intended reason and pass after the fix. A regression test that never demonstrably failed proves the mock, not the fix. One regression at the owner boundary covers the bug; do not replay it at every layer it crosses.

Junk patterns

The shared checklist for both modes. The authoring gate rejects a new test that matches one; audits hunt for existing tests that do.

Repo-specific (each is a AGENTS.md rule):

  • per-test await import() or vi.resetModules() without a comment explaining which module-level state must reset;
  • a production class re-declared inside a test instead of imported from a leaf module (ga4Errors.ts, gscErrors.ts are the pattern);
  • mockReset / mockClear ceremonies in beforeEach (Vitest clearMocks is already on);
  • fixtures longer than the assertions that read them, or inline copies of a shape that already has a factory;
  • Zod schemas or third-party libraries re-tested through the module under test;
  • an output-schema round-trip repeated in every happy path;
  • Drizzle builder chains mocked (select().from().where() with vi.fn() chains); repositories are tested through services or real SQL;
  • argument forwarding to a mock asserted when the mapping is not the contract (billing params and telemetry events are the contract; internal helper arguments are not).

General:

  • assertion-free coverage probes;
  • self-comparisons, and expected values produced by the helper or renderer under test;
  • copied fixtures, inventories, manifests, or export lists;
  • exact source, import, or string greps;
  • private predicate or call-shape tests duplicated at real boundaries;
  • duplicate invocations of the same contract;
  • tests whose only purpose is preserving test-only exports or wrappers;
  • dead production code whose only callers are tests;
  • mocks that implement the asserted behavior, or one identical mock standing in for different APIs;
  • negative controls that pass for an unrelated reason, such as a denial from a different guard or a rejection the production path never reaches;
  • names or fixtures that promise more than the input exercises.

Value bar

Tests justify their maintenance cost by protecting behavior, a credible regression, or an independently meaningful contract. In an audit, an existing test that must change for behavior-preserving source reorganization is suspect, not automatically deletable; the authoring gate still rejects new ones.

Before judging a candidate, read the complete test and its production owner, the entry point, callers, callees, sibling implementations, overlapping tests, and relevant git history. When the test claims dependency-backed behavior (DataForSEO response shapes, Autumn, Better Auth, Drizzle), inspect the dependency source or types directly.

Discovery

Keep discovery read-only and report evidence before editing. For broad scope, run parallel read-only lanes (Explore subagents work well):

  • src/server/mcp/ and src/server/mcp/tools/;
  • src/server/lib/, src/server/auth/, src/server/billing/, src/server/workflows/, src/serverFunctions/;
  • src/server/features/;
  • src/client/, src/shared/, src/lib/, src/types/, scripts/, web/tests/, plus a cross-cutting grep sweep for the repo-specific patterns above.

Prefer a few high-confidence candidates over a large speculative inventory.

Campaign mode

Use only when the maintainer explicitly asks for a suite-wide prune. Run the pipeline in two phases with disjoint file slices so agents never edit the same file:

  1. Review, read-only. Split every *.test.ts into 6-8 slices balanced by line count and grouped by directory. One reviewer per slice reads each test file and its production owner completely and writes a report with a table per file: test name, DELETE / MERGE / KEEP, one-line evidence naming the code change that would fail it or the test that already owns it. The report also lists test-only production seams (with callers checked in src/, scripts/, tests/badseo/, web/), test support that becomes unused, whole files to delete, and a "risky calls" section. Reviewers do not edit.
  2. Apply, per slice. One applier per slice re-verifies each DELETE and MERGE against the source before acting, keeps anything whose evidence does not hold, folds MERGE rows into table-driven siblings, deletes newly unused fixtures and mocks, and skips every risky item, listing it back for the maintainer. If a deletion's justification cites a test in another slice, the applier confirms that test still exists at the end of its run.

Rules that hold throughout a campaign:

  • The only permitted non-test edit is removing an export keyword from a helper whose remaining callers are all tests. Knip fails ci:check on the orphaned export otherwise. Never remove parameters, delete branches, or change behavior in the same change, even when a test looks like the only reason the code exists; report those as follow-ups.
  • Route modules under src/routes/ and barrel files keep their exports.
  • Use pnpm exec prettier --write <files>; pnpm format:write ignores arguments and formats the whole repository.
  • After all slices land, run the full suite in normal order and with two or three --sequence.shuffle.tests --sequence.seed=<n> runs. Removing reset ceremony can surface latent order dependence; fix it by setting the mock's default in beforeEach, never by restoring the ceremony.
Show full SKILL.md (476 more words)Show less

Retention bar

Keep a test when it independently enforces a public API, MCP tool contract, Zod boundary schema, config, migration, storage (both SQLite and Postgres), billing, auth, security, default, prompt-byte, or package contract. Also keep:

  • call ordering when order is observable behavior;
  • regressions with a credible failure mode;
  • source inspection when it is the cheapest independent guard: it fails when the contract changes (a user-facing key, byte, or path) and survives an identifier-only refactor. The pinned SAM skill roster in samSkills.test.ts and the unique-index parity check in src/db/schema-parity.test.ts are this kind;
  • a retained test that fails on the baseline: treat it as a possible product bug, reproduce it, and repair the owner rather than deleting it.

Static or slow is not a deletion reason. A test that resembles implementation may still be the independent contract; prove otherwise before removing it.

Candidate evidence

Record every field before editing. A missing field means the candidate is not ready for deletion:

  • exact test name and location;
  • what failure it can actually detect;
  • non-test callers of the covered production or support seam, including scripts/, tests/badseo/, and web/ (a profiling script is still a caller);
  • stronger remaining owner-boundary proof, or why no proof is needed;
  • relevant history and the reason the test or seam exists;
  • production or test-support deletion unlocked;
  • risk and the focused validation command.

Edit shape

Choose one coherent owner-boundary batch. Delete obsolete test-only exports, wrappers, and dead production paths instead of preserving aliases (Knip will flag survivors in pnpm ci:check). Move retained regressions to their canonical owners. Consolidate repeated assertions into one table-driven case.

Prefer net-negative production LOC. Do not add replacement tests that restate the same implementation, and do not convert uncertain candidates into cleanup to increase deletion counts.

Validation

Never edit tests while Vitest is running in the checkout.

  1. Run the owner and sibling tests: pnpm exec vitest run <path-or-filter>.
  2. For a removed source grep or static assertion, run the executable that owns the real contract (for example pnpm sync-plugin-skills for plugin skill drift).
  3. pnpm format:write, then pnpm ci:check (prettier, knip, tsc, oxlint, plugin-skill sync). Knip failing on a now-unused export means delete the export, not re-add a test.
  4. Run the full suite once: pnpm test.
  5. Inspect git diff --numstat; report production/tooling separately from tests and test support.

Landing

Commit, push, or open a PR only when authorized. Use the merge-ready skill for the review and PR flow. If a verified finding exposes a recurring invariant that .greptile/ does not capture, use maintain-greptile-rules; do not promote one-off cleanups into permanent rules. Log repository friction met along the way with papercuts.

Handoff

Report:

  • removed low-value categories and the root cause behind them;
  • production owner simplifications;
  • retained false positives and why they remain valuable;
  • focused and full proof actually run, with real output;
  • production versus test LOC;
  • PR and merge state;
  • named follow-ups.

© every-app, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/test-audit of every-app/open-seo.

Open the folder on GitHubat commit deb4491

Compare with similar skills

Test Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Test Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Test Audit this skillevery-app/open-seo23k—~2.8kAutomated safety check: PassMIT
Test Writing WorkflowiOfficeAI/AionUi33k1 repos~1.2kAutomated safety check: PassApache-2.0
Vitestsupabase/supabase111k12 repos~1.1kAutomated safety check: PassApache-2.0
Test GuardamElnagdy/guard-skills1.3k2 repos~2.1kAutomated safety check: PassMIT
Control UI E2Eopenclaw/openclaw392k—~2.9kAutomated safety check: PassMIT
Adding LLM MCP ToolsTriliumNext/Trilium38k—~2.5kAutomated safety check: PassAGPL-3.0

Similar skills

  • Test Writing Workflow

    iOfficeAI/AionUi

    Sets the test-writing workflow for the repository: risk-first scenario lists, behavior-focused Vitest tests, a full run before each commit and a coverage target.

    33k GitHub starsUsed in 1 repo~1.2k tokens
    Testing & QAAuto-check passed
  • Vitest

    supabase/supabase

    Official

    Vitest API and config reference (Jest-compatible) — mocking with vi., spies, fake timers, coverage configuration, fixtures, snapshots, and test filtering.

    111k GitHub starsUsed in 12 repos~1.1k tokens
    Testing & QAAuto-check passed
  • Test Guard

    amElnagdy/guard-skills

    Reviews newly written or edited tests against nine rules that cut test bloat, such as mock-heavy checks and near-duplicate cases, before they are committed.

    1.3k GitHub starsUsed in 2 repos~2.1k tokens
    Testing & QAAuto-check passed
  • Control UI E2E

    openclaw/openclaw

    A skill your agent uses when designing, testing, fixing, or extending the OpenClaw Control UI GUI, including UI stress-test galleries with feedback inputs, Vitest + Playwright end-to-end checks…

    392k GitHub stars~2.9k tokensUpdated today
    Testing & QAAuto-check passed
  • Adding LLM MCP Tools

    TriliumNext/Trilium

    A skill your agent uses when adding, changing, or reviewing an LLM/MCP tool in Trilium (the defineTools definitions under packages/trilium-core/src/services/llm/tools/ —…

    38k GitHub stars~2.5k tokensUpdated today
    Testing & QAAuto-check passed
  • Concept Page Test Writer

    leonardomso/33-js-concepts

    Generates Vitest tests for every runnable code example on a JavaScript concept documentation page, following a four-phase extraction and conversion process.

    67k GitHub stars~5.5k tokensUpdated 28 days ago
    Testing & QAAuto-check passed

More from every-app/open-seo

All 19 skills in this repo
  • Papercuts

    every-app/open-seo

    Log genuine, recurring repository friction to .agents/PAPERCUTS.md — confusing setup, a flaky repo command or script, a misleading in-repo error, stale generated files, or a non-obvious gotcha that…

    23k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Evaluate Skill

    every-app/open-seo

    Test a candidate OpenSEO skill end to end by running fresh, isolated Codex sessions against the local backend and scoring the reports they save.

    23k GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Simple Issue Description

    every-app/open-seo

    Turn a rough bug report, feature request, support note, or pull request into a short, plain-language issue focused on the problem and desired behavior.

    23k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Create Repo Skill

    every-app/open-seo

    Create or update a skill in this repository the right way — canonical home in .agents/skills, internal-vs-public marking, symlink mirroring into .claude/skills, and public docs registration for…

    23k GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Deslop

    every-app/open-seo

    Remove AI writing patterns from prose so it reads like a person wrote it.

    23k GitHub stars~602 tokensUpdated 2 days ago
    Auto-check passed
  • Observability Triage

    every-app/open-seo

    Triage OpenSEO production errors in Cloudflare Workers Observability — verified query recipes, counting gotchas, and a known-noise filter list applied automatically.

    23k GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Test Audit

What does Test Audit do?

Invoke whenever writing, changing, reviewing, or sweeping Vitest tests in this repo. Test Audit is an agent skill from every-app/open-seo. Invoke whenever writing, changing, reviewing, or sweeping Vitest tests in this repo.

When should I use Test Audit?

Test Audit fits situations like: asked to add tests; A PR touches .test.ts.

How do I install Test Audit in Claude Code?

Run `npx skills add every-app/open-seo --skill test-audit -a claude-code`. Or copy the skill folder (.agents/skills/test-audit in every-app/open-seo) into .claude/skills/test-audit in your project. Claude Code loads it when a task matches its description.

How do I install Test Audit in Codex?

Run `npx skills add every-app/open-seo --skill test-audit -a codex`. Or copy the skill folder (.agents/skills/test-audit in every-app/open-seo) into .agents/skills/test-audit in your project. Codex loads it when a task matches its description.

Can I use Test Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add every-app/open-seo --skill test-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/test-audit, .gemini/skills/test-audit, .github/skills/test-audit and .opencode/skills/test-audit in your project.

What does Test Audit need to run?

Going by SKILL.md and its folder, Test Audit needs the command-line tools its instructions call (pnpm and git).

Does Test Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Test Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Test Audit use?

Test Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Test Audit use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Test Audit?

Skills that share tags, products or a category with Test Audit: Test Writing Workflow (iOfficeAI/AionUi, 33k stars), Vitest (supabase/supabase, 111k stars), Test Guard (amElnagdy/guard-skills, 1.3k stars) and Control UI E2E (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Test Audit?

every-app (a GitHub organization) maintains it in every-app/open-seo, which has 22,680 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 6, 2026.

Source: every-app/open-seo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.