Agent skill

Tracing Requirements To Code

by jaktestowac in jaktestowac/awesome-copilot-for-testers

Builds and maintains bidirectional traceability between requirements and the tests that verify them: extracts a matrix from an existing codebase, annotates tests with requirement IDs, finds orphan…

MITAuto-check passedDevelopment

Install Tracing Requirements To Code

skills CLI
$ npx skills add jaktestowac/awesome-copilot-for-testers --skill tracing-requirements-to-code -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jaktestowac/awesome-copilot-for-testers tracing-requirements-to-code --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jaktestowac/awesome-copilot-for-testers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tracing-requirements-to-code .claude/skills/tracing-requirements-to-code && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tracing-requirements-to-code
GitHub stars
116
Token cost
~3.2k tokens
SKILL.md length
1,719 words
Files
5
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Builds and maintains bidirectional traceability between requirements and the tests that verify them: extracts a matrix from an existing codebase, annotates tests with requirement IDs, finds orphan…

  • Works in 8 steps: Establish the requirement source → Extract what the tests actually verify → Annotate at the source → …
  • A suite exists but nobody can say what it proves
  • SKILL.md covers When to Use, Operating Principles, Workflow and Common Failure Modes, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Tracing Requirements To Code is an agent skill from jaktestowac/awesome-copilot-for-testers. Builds and maintains bidirectional traceability between requirements and the tests that verify them: extracts a matrix from an existing codebase, annotates tests with requirement IDs, finds orphan tests and uncovered requirements, verifies that each link is real, and enforces linkage in CI. Use when a suite exists but nobody can say what it proves, when an auditor or stakeholder asks which tests cover a requirement, when a traceability matrix has gone stale, or when a requirement changes and its blast radius must…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `resources/extracting-an-rtm.md`, `resources/id-and-annotation-conventions.md` and `resources/orphan-and-drift-detection.md`).

It sits in Development, covering Spec-driven development. The repository describes itself as: 👨💻 Instructions, prompts, and chat modes to help You with test automation for GitHub Copilot 🤖. The licence is MIT.

When your agent uses it

  • A suite exists but nobody can say what it proves
  • Stakeholder asks which tests cover a requirement
  • A traceability matrix has gone stale
  • A requirement changes and its blast radius must be found

Example prompts

  • “Use the tracing-requirements-to-code skill to build and maintains bidirectional traceability between requirements and the tests that verify them…”
  • “/tracing-requirements-to-code”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Establish the requirement source
  2. Extract what the tests actually verify
  3. Annotate at the source
  4. Verify the links
  5. Find the orphans
  6. Automate and gate
  7. Handle change
  8. Report

What it can do on your machine

Read from SKILL.md and the folder at commit 8910672. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tracing Requirements To Code loads about 3.2k tokens when it runs. Until then it costs about 139 tokens; SKILL.md has 1,719 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~139
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jaktestowac/awesome-copilot-for-testers at commit 8910672, republished under its MIT licence (© jaktestowac). 1,719 words, ~3,156 tokens.

Download SKILL.mdSave it as .claude/skills/tracing-requirements-to-code/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
tracing-requirements-to-code
description
Builds and maintains bidirectional traceability between requirements and the tests that verify them: extracts a matrix from an existing codebase, annotates tests with requirement IDs, finds orphan tests and uncovered requirements, verifies that each link is real, and enforces linkage in CI. Use when a suite exists but nobody can say what it proves, when an auditor or stakeholder asks which tests cover a requirement, when a traceability matrix has gone stale, or when a requirement changes and its blast radius must be found.
argument-hint
Test suite path, where requirements live (tracker, PRD, specs), any existing matrix or ID convention, and whether the goal is a one-off extraction or an…
user-invocable
true

Tracing Requirements to Code

Use this skill when the tests already exist and the question is what they actually verify.

Traceability is usually taught forward: take a specification, derive requirements, plan tests. That is requirements-test-coverage-mapper, and it is the right skill when you start from a document. This skill handles the other and more common situation: a live codebase, hundreds of tests, requirements scattered across a tracker and three documents, and no reliable statement of which test proves what.

The insistence that makes this worth doing: a traceability link is a claim, not a record. A test tagged @req REQ-014 claims to verify REQ-014, and nothing about writing the tag makes that true. An unverified matrix is worse than no matrix, because it converts ignorance into documented confidence, and it is exactly the artifact people reach for when deciding what not to test.

When to Use

  • a suite exists and nobody can say which requirement a given test serves
  • someone asks "which tests cover this requirement" and the answer takes a day
  • a matrix was built once, was accurate that week, and has not been true since
  • a requirement is changing and its affected tests must be found
  • tests exist that nobody can trace to any requirement
  • an audit, certification, or customer questionnaire needs coverage evidence

Operating Principles

  • Traceability runs both ways. Requirement to test finds coverage gaps. Test to requirement finds orphan tests, and nobody looks in that direction.
  • A link is verified or it is a guess. The test must fail when the requirement's behaviour is broken. Until it has been seen to, the link is unconfirmed and labelled as such.
  • Extract from evidence, not from titles. A test called "validates the discount rule" is a hypothesis about what it does. The assertions are the evidence.
  • The matrix lives in the code, not in a spreadsheet. A link stored beside the test moves when the test moves. A link in a document rots the first time anyone refactors.
  • Orphans are findings in both directions. An uncovered requirement is a coverage gap. An orphan test is either an undocumented requirement or a test of nothing, and both are worth knowing.
  • Drift is the default. Links rot silently through renames, deletions, and refactors. Without a CI check, the matrix is accurate on the day it is written and decreasingly true afterwards.

Workflow

Phase 0: Establish the requirement source

Before touching tests, fix what a requirement is in this project and where the authoritative list lives:

  • an issue tracker with stable keys (PROJ-1234)
  • acceptance criteria inside stories
  • a PRD or specification document
  • a regulatory or contractual requirement list
  • none of the above, in which case the first deliverable is a requirement inventory derived from the code and the tracker, marked as derived rather than authoritative

Record the ID scheme, and whether IDs are stable. An ID that changes when a ticket moves project is not usable as a link target, and discovering that after annotating 400 tests is expensive.

./resources/id-and-annotation-conventions.md covers choosing a scheme that survives.

Phase 1: Extract what the tests actually verify

Work through ./resources/extracting-an-rtm.md. The method, in short:

  1. Inventory the tests. Every test, its file, its title, its level.
  2. Read the assertions, not the titles. What behaviour would have to break for this test to fail?
  3. Group by behaviour, not by file. Several tests often serve one requirement, and one god test sometimes serves five.
  4. Map to requirements where the mapping is defensible.
  5. Label the confidence of each mapping: stated (the test or its commit names the requirement), inferred (the behaviour clearly matches), guessed (it plausibly relates).

Do not silently promote a guess. A matrix that distinguishes stated from guessed is honest and usable; one that flattens them is a document nobody should trust and everybody will.

Phase 2: Annotate at the source

Move each defensible link into the code, next to the test it describes.

ts
test('rejects a card that expired last month @req:REQ-014', async ({ page }) => { ... });

Per-runner spellings, the machine-readable formats, and the trade-offs between tags, annotations, and comments are in ./resources/id-and-annotation-conventions.md.

Rules that decide whether this survives:

  • one canonical form, chosen once and used everywhere, so a generator can parse it
  • machine-readable, because a convention nothing checks is a convention that decays
  • at the test level, not the file level, unless every test in the file genuinely serves the same requirement
  • many-to-many is normal: one test may serve several requirements and one requirement needs several tests

The phase that separates this from bookkeeping. For each link, and at minimum for every link on a high-risk requirement:

  1. Break the behaviour the requirement describes.
  2. Run the linked test.
  3. Confirm it fails, and that the failure names something recognizable.
  4. Record the link as verified with the date.

A link that survives step 3 with a passing test is a false claim in the matrix. Fix the test or remove the link; do not leave it as documented coverage.

This is the same standard unslop-tests and migrating-tests-to-playwright apply, for the same reason: a test that has never been observed failing has unmeasured value, and a matrix built on such tests inherits that.

Verifying every link in a large suite is not affordable. Verify by risk, record the coverage of the verification itself, and state what was taken on trust.

Phase 4: Find the orphans

Cross the two directions and take all four quadrants seriously. ./resources/orphan-and-drift-detection.md has the triage.

Has a testNo test
Has a requirementCovered, verify the linkCoverage gap
No requirementOrphan testOut of scope
  • Coverage gap: a requirement nothing verifies. Route to designing-functional-tests or requirements-test-coverage-mapper.
  • Orphan test: the direction nobody looks. It is one of three things, and the distinction matters:
    • an undocumented requirement, which is the valuable case. The behaviour matters, someone tested it, nobody wrote it down. Write it down.
    • a test of a removed feature, which should be deleted.
    • a test that proves nothing, which unslop-tests should judge.

Reporting orphan tests as a single count wastes them. Classify each one.

Show full SKILL.md (718 more words)Show less
Phase 5: Automate and gate

A matrix maintained by hand is a matrix that is true once. ./resources/traceability-automation.md has a generator that parses annotations and emits the matrix, plus the CI gate.

Enforce, in increasing order of strictness, and adopt them in this order:

  1. Every annotation references a requirement that exists. Cheap, catches typos and deleted tickets immediately.
  2. Every high-risk requirement has at least one linked test. Scoped to a declared critical set rather than everything.
  3. New tests carry an annotation. Applied to changed files only, so the backlog does not block every pull request.
  4. No requirement loses its last link without an explicit acknowledgement.

Introduce a gate against changed files first. A gate that fails on a pre-existing backlog of 300 unannotated tests gets disabled in a week, and then nothing is enforced at all.

Phase 6: Handle change

When a requirement changes, the matrix is what tells you what to revisit. The procedure is in ./resources/traceability-automation.md:

  • find every test linked to the changed requirement
  • classify each: still valid, needs updating, now wrong
  • update the tests and the links in the same change
  • when a requirement is removed, its tests are deleted or re-linked, never left pointing at nothing

Requirement changes are the main source of drift, and they are the moment traceability pays for itself. Hand the wider retest question to analyzing-regression-scope.

Phase 7: Report

./resources/traceability-automation.md has the report shape. It states:

  • coverage per requirement, with the link confidence and verification status
  • uncovered requirements, ranked by risk
  • orphan tests, classified rather than counted
  • links that could not be verified, and why
  • drift found since the last run
  • what the matrix does not cover, which is the line that keeps it from being over-quoted

Common Failure Modes

  • a matrix in a spreadsheet, accurate the day it was written, quietly wrong within a month
  • links inferred from test titles, so a misleadingly named test becomes documented coverage
  • stated and guessed mappings flattened into one column
  • links recorded and never verified, converting ignorance into documented confidence
  • orphan tests reported as a number rather than classified
  • annotating in a format nothing parses, so nothing checks it
  • a CI gate switched on against the whole backlog, then disabled and never restored
  • a requirement edited without touching the tests linked to it
  • treating full traceability as achievable everywhere, rather than mandatory on the risky part and best-effort elsewhere

Resource Map

  • ./resources/id-and-annotation-conventions.md - choosing a stable ID scheme, per-runner annotation spellings for Playwright, Vitest, Jest, and Cucumber, and the many-to-many cases
  • ./resources/extracting-an-rtm.md - building the matrix from an existing codebase: reading assertions rather than titles, confidence labels, and a worked extraction
  • ./resources/orphan-and-drift-detection.md - the four quadrants, orphan-test classification, the ways links rot, and the triage table
  • ./resources/traceability-automation.md - a generator script, the staged CI gate, the change-impact procedure, and the report template
  • requirements-test-coverage-mapper - the forward direction: designing coverage from a PRD before the tests exist. Use that one to plan, this one to verify what was built.
  • verifying-acceptance-criteria - when the question is whether a specific build meets its criteria, rather than which test covers what
  • analyzing-regression-scope - when a requirement change needs its full retest blast radius, beyond the linked tests
  • unslop-tests - when an orphan test needs judging on whether it proves anything
  • designing-functional-tests - when an uncovered requirement needs its tests designed
  • documenting-test-suites - where the ID convention and the matrix's location belong permanently
  • assessing-release-readiness - which consumes the uncovered-requirement list as release evidence

Definition of Done

This skill is complete when:

  • the authoritative requirement source and its ID stability are recorded
  • every mapping carries a confidence label of stated, inferred, or guessed, and guesses are not promoted silently
  • defensible links live in the code beside their tests, in one canonical machine-readable form
  • every link on a high-risk requirement has been verified by breaking the behaviour and observing the test fail, with the date recorded
  • links that could not be verified are labelled unverified rather than omitted
  • both directions are crossed: uncovered requirements ranked by risk, and orphan tests classified as undocumented requirement, dead test, or proves-nothing
  • a generator produces the matrix from the annotations rather than a human maintaining it
  • a CI gate is enforced against changed files at minimum, and the staged escalation is recorded
  • the change procedure updates tests and links together
  • the report states what the matrix does not cover

© jaktestowac, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in skills/tracing-requirements-to-code of jaktestowac/awesome-copilot-for-testers.

  • SKILL.md
  • resources/extracting-an-rtm.md
  • resources/id-and-annotation-conventions.md
  • resources/orphan-and-drift-detection.md
  • resources/traceability-automation.md

Open the folder on GitHubat commit 8910672

Compare with similar skills

Tracing Requirements To Code next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tracing Requirements To Code compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tracing Requirements To Code this skilljaktestowac/awesome-copilot-for-testers116—~3.2kAutomated safety check: PassMIT
OpenSpec Bulk Change ArchiverFission-AI/OpenSpec71k3 repos~5.6kAutomated safety check: PassMIT
Speckit ConstitutionWeihanLi/WeihanLi.Common24211 repos~2.1kAutomated safety check: PassApache-2.0
Speckit Taskstoissueskunstmusik/blue15419 repos~2kAutomated safety check: PassGPL-3.0
Speckit Analyzekunstmusik/blue15418 repos~3kAutomated safety check: PassGPL-3.0
Review Spdzhu1090093659/spec_driven_develop984—~1.5kAutomated safety check: PassMIT

Similar skills

  • Archives several completed OpenSpec changes in one operation, checking the codebase to resolve spec conflicts rather than archiving blindly.

    71k GitHub starsUsed in 3 repos~5.6k tokens
    DevelopmentAuto-check passed
  • Speckit Constitution

    WeihanLi/WeihanLi.Common

    Create or update the project constitution from interactive or provided principle inputs, ensuring all dependent templates stay in sync.

    242 GitHub starsUsed in 11 repos~2.1k tokens
    DevelopmentAuto-check passed
  • Speckit Taskstoissues

    kunstmusik/blue

    Convert existing tasks into actionable, dependency-ordered GitHub issues for the feature based on available design artifacts.

    154 GitHub starsUsed in 19 repos~2k tokens
    DevelopmentAuto-check passed
  • Speckit Analyze

    kunstmusik/blue

    Perform a non-destructive cross-artifact consistency and quality analysis across spec.md, plan.md, and tasks.md after task generation.

    154 GitHub starsUsed in 18 repos~3k tokens
    DevelopmentAuto-check passed
  • Review Spd

    zhu1090093659/spec_driven_develop

    Findings-first code review workflow for AI coding agents. An agent skill from zhu1090093659/spec_driven_develop.

    984 GitHub stars~1.5k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Speckit Plan

    kunstmusik/blue

    Execute the implementation planning workflow using the plan template to generate design artifacts.

    154 GitHub starsUsed in 18 repos~2.1k tokens
    DevelopmentAuto-check passed

More from jaktestowac/awesome-copilot-for-testers

All 13 skills in this repo
  • API Playwright Test Developer

    jaktestowac/awesome-copilot-for-testers

    Writes and reviews API automation tests with Playwright Test, covering setup/teardown, assertions, data management, and hybrid API+UI flows.

    116 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Assessing Comprehension Debt

    jaktestowac/awesome-copilot-for-testers

    Measures the risk that code shipped without anyone understanding it: a teach-back attestation on high-risk changes, a risk band from changed-code complexity, diff size and whether a human…

    116 GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Creating Orchestration Packs

    jaktestowac/awesome-copilot-for-testers

    Creates agent orchestration packs: cooperating .agent.md files with an orchestrator, subagents, matched handoffs, minimal tool grants, and a shared handoff packet contract.

    116 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Creating Plugins

    jaktestowac/awesome-copilot-for-testers

    Packages repository skills as installable Copilot plugins: marketplace registration, plugin.json manifests, generated skill copies, and the sync check CI enforces.

    116 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Governing Quality Waivers

    jaktestowac/awesome-copilot-for-testers

    Turns "we will skip this check for now" into a dated, attributed, expiring waiver with a stated reason and owner, inventories the silent skips already hiding in a repo - skipped tests, disabled lint…

    116 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Recording Change Intent

    jaktestowac/awesome-copilot-for-testers

    Requires an externalised rationale for high-risk changes - new public exports, new endpoints, auth edits, migrations, removed guards - recorded as an Intent commit trailer, an ADR reference, or a…

    116 GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Tracing Requirements To Code

What does Tracing Requirements To Code do?

Builds and maintains bidirectional traceability between requirements and the tests that verify them: extracts a matrix from an existing codebase, annotates tests with requirement IDs, finds orphan…. Tracing Requirements To Code is an agent skill from jaktestowac/awesome-copilot-for-testers. Builds and maintains bidirectional traceability between requirements and the tests that verify them: extracts a matrix from an existing codebase, annotates tests with requirement IDs, finds orphan tests and uncovered requirements, verifies that each link is real, and enforces linkage in CI.

When should I use Tracing Requirements To Code?

Tracing Requirements To Code fits situations like: A suite exists but nobody can say what it proves; stakeholder asks which tests cover a requirement; A traceability matrix has gone stale; A requirement changes and its blast radius must be found.

How do I install Tracing Requirements To Code in Claude Code?

Run `npx skills add jaktestowac/awesome-copilot-for-testers --skill tracing-requirements-to-code -a claude-code`. Or copy the skill folder (skills/tracing-requirements-to-code in jaktestowac/awesome-copilot-for-testers) into .claude/skills/tracing-requirements-to-code in your project. Claude Code loads it when a task matches its description.

How do I install Tracing Requirements To Code in Codex?

Run `npx skills add jaktestowac/awesome-copilot-for-testers --skill tracing-requirements-to-code -a codex`. Or copy the skill folder (skills/tracing-requirements-to-code in jaktestowac/awesome-copilot-for-testers) into .agents/skills/tracing-requirements-to-code in your project. Codex loads it when a task matches its description.

Can I use Tracing Requirements To Code in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jaktestowac/awesome-copilot-for-testers --skill tracing-requirements-to-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tracing-requirements-to-code, .gemini/skills/tracing-requirements-to-code, .github/skills/tracing-requirements-to-code and .opencode/skills/tracing-requirements-to-code in your project.

What does Tracing Requirements To Code need to run?

SKILL.md names no scripts, command-line tools or credentials: Tracing Requirements To Code is instructions for the agent only.

Does Tracing Requirements To Code access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Tracing Requirements To Code safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tracing Requirements To Code use?

Tracing Requirements To Code is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tracing Requirements To Code use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tracing Requirements To Code?

Skills that share tags, products or a category with Tracing Requirements To Code: OpenSpec Bulk Change Archiver (Fission-AI/OpenSpec, 71k stars), Speckit Constitution (WeihanLi/WeihanLi.Common, 242 stars), Speckit Taskstoissues (kunstmusik/blue, 154 stars) and Speckit Analyze (kunstmusik/blue, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tracing Requirements To Code?

jaktestowac (a GitHub user) maintains it in jaktestowac/awesome-copilot-for-testers, which has 116 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on August 26, 2026.

Source: jaktestowac/awesome-copilot-for-testers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.