Agent skill

Test Audit

by jiangzhe in jiangzhe/doradb

Audit Doradb test contracts and assertion quality with deterministic tooling and read-only semantic review.

Apache-2.0Auto-check passedDevelopment

Install Test Audit

skills CLI
$ npx skills add jiangzhe/doradb --skill test-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jiangzhe/doradb test-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jiangzhe/doradb.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/test-audit .claude/skills/test-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
test-audit
GitHub stars
121
Token cost
~2.2k tokens
SKILL.md length
1,055 words
Files
2
Skills in repo
10
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit Doradb test contracts and assertion quality with deterministic tooling and read-only semantic review.

  • Asked to run test-audit
  • SKILL.md covers Select Scope and Run, Contract Writing Principle, Semantic Review and Report
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Check Purpose/Expected documentation

What it does

Test Audit is an agent skill from jiangzhe/doradb. Audit Doradb test contracts and assertion quality with deterministic tooling and read-only semantic review. Use when asked to run test-audit, check Purpose/Expected documentation, review test assertions or overlapping scenarios, or generate the test inventory. Supports current-branch changes, staged changes, and explicit Rust targets. Do not use merely to run tests or review unrelated coding style.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development. It works with Rust. The repository describes itself as: DoraDB - Async Rust storage engine. The licence is Apache-2.0.

When your agent uses it

  • Asked to run test-audit
  • Check Purpose/Expected documentation
  • Review test assertions
  • Overlapping scenarios

Example prompts

  • “/test-audit”

What it can do on your machine

Read from SKILL.md and the folder at commit 78c6c3d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and rust).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Test Audit loads about 2.2k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 1,055 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jiangzhe/doradb at commit 78c6c3d, republished under its Apache-2.0 licence (© jiangzhe). 1,055 words, ~2,189 tokens.

Download SKILL.mdSave it as .claude/skills/test-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
test-audit
description
Audit Doradb test contracts and assertion quality with deterministic tooling and read-only semantic review. Use when asked to run test-audit, check Purpose/Expected documentation, review test assertions or overlapping scenarios, or generate the test inventory. Supports current-branch changes, staged changes, and explicit Rust targets. Do not use merely to run tests or review unrelated coding style.

Test Audit Workflow

Run the existing auditor, then review the behavior protected by the selected tests. Source comments are authoritative; generated inventories are evidence, not approvals. This workflow is read-only apart from generated reports. Do not edit or stage source, consolidate/delete tests, or hand-edit reports. Do not implicitly run formatting, Clippy, or storage suites.

Select Scope and Run

Run commands from the repository root. Without an explicit target, audit whole working-tree Rust files changed against the current branch's merge base:

bash
audit_base="$(rtk git merge-base origin/main HEAD)" &&
tools/test_audit.rs check --diff-base "$audit_base"

If resolving the base fails, report the error; do not substitute another base. Honor an explicitly requested mode instead of combining selectors:

RequestCommand
Staged changestools/test_audit.rs check --staged
File or directorytools/test_audit.rs check --force-path <file-or-dir>
Explicit comparison committools/test_audit.rs check --diff-base <rev>
Inventory onlytools/test_audit.rs inventory

Repeat --force-path for multiple targets. Directories select only direct .rs children. An explicit diff base is compared directly, without another implicit merge-base calculation. Inventories and staged/diff selection exclude the root tools/ directory. Default/diff inventories also exclude untracked files until staged. Explicit tool or untracked targets are checked without entering the inventory. Every test in a selected file needs a contract, even when only production code changed.

Use the diff or explicit targets to identify the review scope: all commands generate the full inventory, so its contents alone do not identify selected files. Staged mode audits index blobs. Review those same contents, using rtk git show ':<repo-relative-file>' when needed, rather than working-tree replacements. Other checks review working-tree sources. Inspect related helpers and production code in that same snapshot.

Reports default to target/test-audit/test-inventory.csv and target/test-audit/test-inventory.md; honor an explicitly requested --output-dir.

For semantic deduplication requests, append --analyze-duplicates to the chosen command. This writes test-duplicate-candidates.md beside the inventories; ordinary checks and CI do not enable it. Inventory mode analyzes all inventoried tests; check mode analyzes only selected files, including explicitly forced tool or untracked sources without adding them to the inventory. A later invocation clears stale candidate output even when the option is absent.

Candidates compare bodies within one file and enclosing module declaration. The pilot reports whole-body similarity of at least 85% or shorter-body overlap of at least 95%, preserving identifiers and literal values. Bodies under 30 tokens are excluded and counted. Calls and assertion summaries are syntactic; macros, helper bodies, and types are not resolved. Scores measure structural overlap, not the probability of semantic equivalence, and never fail a check.

  • Exit 0 from a check: proceed to semantic review. If no files/tests were selected, report that there was nothing to review in the requested scope.
  • Exit 1: report the selected contract violations and fresh report locations; leave semantic review incomplete until the mechanical check passes.
  • Exit 2 or an execution failure: report the tooling error and stop. Do not present existing report files as results of this failed invocation.
  • An inventory-only request reports completeness and duplicate candidates; successful generation does not establish a contract or semantic-review pass.

For source-discovery boundaries, field rules, and gradual adoption, use Unit Testing. In particular, documented means structurally valid, not behaviorally verified. Conditions are source-local and unevaluated; macros are not expanded.

Contract Writing Principle

Keep Purpose: and Expected: concise and focused on intent. Purpose: names the protected behavior and distinguishing scenario; Expected: states the semantic guarantee. Prefer a short sentence per field. Describe boundaries, errors, and lifecycle distinctions conceptually; leave concrete inputs, returned values, IDs, counts, timestamps, byte sequences, and diagnostic strings in the test body. Do not narrate execution steps or enumerate assertions.

rust
/// Purpose: Protect descriptor decoding at payload boundaries.
/// Expected: Valid payloads preserve metadata and opaque bytes.

This is a semantic review principle, not a numeric-content or length restriction for the mechanical auditor.

Show full SKILL.md (465 more words)Show less

Semantic Review

When style-audit has already passed its mechanical gates for the same selected files and source snapshot, reuse those gates and its fresh inventory. If a deduplication request needs a candidate report, run the optional analysis for the same selected files and snapshot. Do not broaden to all inventoried files.

  • Review contracts against the writing principle above, then connect each test's Purpose and Expected fields to its actual assertions or explicit oracle. Check input boundaries, errors, cleanup, and final state. Identify expectations derived from the implementation itself that could reproduce the same defect instead of detecting it.
  • Examine state and schedule setup. Record seeds, operation-generation details, and synchronization predicates where relevant. A documented seed alone does not establish reproducibility; elapsed time should not establish readiness.
  • Inspect exact duplicate-contract candidates plus nearby tests and shared procedures, even when wording differs. Text matches are neither exhaustive semantic overlap detection nor proof of redundancy.
  • For deduplication, review module-local structural pairs for repeated setup, parameterized cases, or potentially subsumed behavior. Inspect differing tokens, assertions, conditions, and panic attributes; follow the actual helper implementations. Review short wrappers separately. Absence of candidates is not a semantic pass, and pairwise similarities do not form equivalence groups.
  • Treat long, similar setup as a useful shared-helper extraction candidate, even when the tests protect different behaviors. Preserve each test's distinct operations and assertions. Extraction often reduces similarity or leaves wrappers below the 30-token cutoff; rerun analysis after an authorized refactor to check whether the pair remains.
  • Keep consolidation within the owning module by default. Cross-module review requires an explicit scope request and must account for different test layers.
  • Before recommending consolidation, account for feature/backend conditions, public/component contracts, owner/lifecycle differences, input boundaries, and independent oracles. Preserve named cases and case-specific diagnostics. Record why intentional overlap remains or how each behavior would be preserved.

Report

Keep the result concise and distinguish mechanical status from semantic findings:

  • State the selector, audited snapshot, and selected file/test counts separately from global inventory counts. Report no changes rather than a repository-wide pass when the selected scope is empty.
  • List mechanical findings as path:line rule - message. List semantic findings with source locations, the claimed behavior, and the assertion or setup gap.
  • Summarize reviewed scope, retained overlap, and any review limitations. Do not imply that tests were executed or that unreviewed tests were verified.
  • Link the fresh CSV/Markdown reports when generation succeeded, including checks that exited 1. Do not treat unrelated legacy gaps as selected failures.
  • When optional analysis ran, link its candidate report, state its scope and short-body exclusions, and distinguish useful consolidation candidates from intentional overlap. Preserve named inputs, independent expectations, and lifecycle coverage in any recommendation.

If required tooling is unavailable, report that limitation. Perform a manual fallback only when explicitly requested, and identify it as a partial review.

© jiangzhe, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/test-audit of jiangzhe/doradb.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 78c6c3d

Compare with similar skills

Test Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Test Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Test Audit this skilljiangzhe/doradb121—~2.2kAutomated safety check: PassApache-2.0
Migrate Core Code to Submodulestinyhumansai/openhuman42k—~2.6kAutomated safety check: PassGPL-3.0
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Rust Best Practicesfarm-fe/farm5.6k3 repos~1.1kAutomated safety check: PassMIT
RTK Rust Design Patternsrtk-ai/rtk83k—~1.9kAutomated safety check: PassApache-2.0
Release Skillsnexmoe/eve4213 repos~3.3kAutomated safety check: PassNone

Similar skills

  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    42k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.

    5.6k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Describes seven Rust design patterns for the RTK CLI filter modules, with when to use each, RTK examples, and notes on when a pattern is overkill.

    83k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release Skills

    nexmoe/eve

    Universal release workflow. An agent skill from nexmoe/eve.

    421 GitHub starsUsed in 3 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed

More from jiangzhe/doradb

All 10 skills in this repo
  • Backlog

    jiangzhe/doradb

    Manage backlog todo documents in docs/backlogs with deterministic tooling.

    121 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Issue Rfc

    jiangzhe/doradb

    Create and list GitHub Issues for Doradb RFC documents with deterministic scripts.

    121 GitHub stars~519 tokensUpdated today
    Auto-check passed
  • Issue Task

    jiangzhe/doradb

    Create and list GitHub Issues for Doradb task documents with deterministic scripts.

    121 GitHub stars~719 tokensUpdated today
    Auto-check passed
  • Rfc Create

    jiangzhe/doradb

    Design and formalize Doradb RFC documents through evidence-gated research, materially different architectural proposals, two review rounds, and explicit draft and formalization approvals.

    121 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Rfc Resolve

    jiangzhe/doradb

    Resolve completed or superseded Doradb RFC programs after implementation tasks, tests, review, and verification are complete.

    121 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Style Audit

    jiangzhe/doradb

    Audit branch-diff Rust files, or explicitly requested file/directory Rust targets, for Doradb coding style using deterministic tooling and concise read-only review.

    121 GitHub stars~951 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Test Audit

What does Test Audit do?

Audit Doradb test contracts and assertion quality with deterministic tooling and read-only semantic review. Test Audit is an agent skill from jiangzhe/doradb. Audit Doradb test contracts and assertion quality with deterministic tooling and read-only semantic review.

When should I use Test Audit?

Test Audit fits situations like: asked to run test-audit; check Purpose/Expected documentation; review test assertions; overlapping scenarios.

How do I install Test Audit in Claude Code?

Run `npx skills add jiangzhe/doradb --skill test-audit -a claude-code`. Or copy the skill folder (.agents/skills/test-audit in jiangzhe/doradb) into .claude/skills/test-audit in your project. Claude Code loads it when a task matches its description.

How do I install Test Audit in Codex?

Run `npx skills add jiangzhe/doradb --skill test-audit -a codex`. Or copy the skill folder (.agents/skills/test-audit in jiangzhe/doradb) into .agents/skills/test-audit in your project. Codex loads it when a task matches its description.

Can I use Test Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jiangzhe/doradb --skill test-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/test-audit, .gemini/skills/test-audit, .github/skills/test-audit and .opencode/skills/test-audit in your project.

What does Test Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Test Audit is instructions for the agent only.

Does Test Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Test Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Test Audit use?

Test Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Test Audit use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Test Audit?

Skills that share tags, products or a category with Test Audit: Migrate Core Code to Submodules (tinyhumansai/openhuman, 42k stars), OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Rust Best Practices (farm-fe/farm, 5.6k stars) and RTK Rust Design Patterns (rtk-ai/rtk, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Test Audit?

jiangzhe (a GitHub user) maintains it in jiangzhe/doradb, which has 121 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 9, 2026.

Source: jiangzhe/doradb on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.