Agent skill

Test Audit

by KeeForge in KeeForge/KeeForge

Assess KeeForge test quality, redundant coverage, and test-support complexity; audit a selected subsystem or apply an authoring checklist while changing tests.

GPL-3.0Auto-check passedProduct & Project Management

Install Test Audit

skills CLI
$ npx skills add KeeForge/KeeForge --skill test-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install KeeForge/KeeForge test-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/KeeForge/KeeForge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/test-audit .claude/skills/test-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
test-audit
GitHub stars
111
Token cost
~2.1k tokens
SKILL.md length
1,069 words
Files
3 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
GPL-3.0

At a glance

Assess KeeForge test quality, redundant coverage, and test-support complexity; audit a selected subsystem or apply an authoring checklist while changing tests.

  • Pruning requests
  • SKILL.md covers Scope and authority, Authoring checklist, Discovery and retention and Candidate evidence, plus 1 more section
  • Calls git
  • Tasks that involve Feature launches and release readiness

What it does

Test Audit is an agent skill from KeeForge/KeeForge. Assess KeeForge test quality, redundant coverage, and test-support complexity; audit a selected subsystem or apply an authoring checklist while changing tests. Use for test audits, consolidation, and pruning requests. Release readiness across changes belongs to pre-release-review; ordinary test authoring needs only the checklist, not an audit campaign.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/campaign.md`).

It sits in Product & Project Management, covering Feature launches and release readiness. The repository describes itself as: KeePass-compatible password manager for iPhone, iPad, and Mac. The licence is GPL-3.0.

When your agent uses it

  • Pruning requests
  • Tasks that involve Feature launches and release readiness

Example prompts

  • “/test-audit”

What it can do on your machine

Read from SKILL.md and the folder at commit 2778b90. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Test Audit loads about 2.1k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,069 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from KeeForge/KeeForge at commit 2778b90, republished under its GPL-3.0 licence (© KeeForge). 1,069 words, ~2,090 tokens.

Download SKILL.mdSave it as .claude/skills/test-audit/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
test-audit
description
Assess KeeForge test quality, redundant coverage, and test-support complexity; audit a selected subsystem or apply an authoring checklist while changing tests. Use for test audits, consolidation, and pruning requests. Release readiness across changes belongs to pre-release-review; ordinary test authoring needs only the checklist, not an audit campaign.

KeeForge Test Audit

Improve regression protection and reduce maintenance without losing distinct contracts. Test count and deleted lines are not success criteria. Adapted from OpenClaw's test-audit for KeeForge's XCTest, shared platform targets, and independent compatibility gates.

Scope and authority

Read root and affected folder guidance, including local overrides. For an audit, pin the reviewed commit and record dirty files separately. Establish the subsystem and whether the request covers discovery, cleanup, or a complete campaign. Default an audit to read-only discovery and a report under the main checkout's shared scratch/test-audit/; tests may create build artifacts. Find the main checkout with git worktree list --porcelain. A plan-only request excludes test execution and file writes unless requested separately. Apply existing user authorization rather than asking again. An audit alone does not authorize source/test fixes, issue mutations, commits, or pushing.

Use pre-release-review for change-driven release readiness. When working within that static review, contribute coverage gaps to its action list without running tests or creating a separate report. For ordinary test changes, apply the checklist below without producing a separate audit report.

Authoring checklist

Before adding or changing a test, identify:

  • The observable outcome or independent contract and a credible regression it detects.
  • The production boundary that owns the behavior and why existing tests do not already catch that regression. Extend a case table or shared fixture when it expresses the same contract without obscuring distinct failure paths.
  • An expectation independent of the behavior under test. A mock should supply inputs, record effects, or simulate an external boundary; it must not implement the outcome the test claims to prove.
  • Any injection or support needed, and why it is the smallest reliable way to exercise the real owner. Constructor injection, fake transports, clocks, notification centers, and system-store fakes can be necessary for deterministic, headless tests. Remove unnecessary hooks, not testability itself.

For bug regressions, demonstrate failure on the old behavior for the intended reason and success with the repair when feasible; record any unverified control explicitly. Use a disposable checkout or reversible isolated patch for controls, preserving user changes. A failing build or an unrelated guard is not a regression control.

Discovery and retention

Read KeeForgeTests/AGENTS.md and relevant support/fixture guidance before judging overlap. Read KeeForgeMac/README.md's testing table for affected Mac behavior, and .github/AGENTS.md, ci_scripts/README.md, and actual target/scheme selection for execution coverage. Read each candidate test in full, its production owner, callers, relevant callees, overlapping suites, and history. Inspect dependency code or types when a claim relies on a dependency contract.

Look for assertions that merely mirror implementation, expected values computed by the same helper under test, assertion-free execution, mocks supplying the alleged result, negative cases rejected by the wrong guard, duplicated scenarios at the same boundary, stale test-only paths, or names claiming more than assertions establish. These are investigation leads, not automatic deletion rules.

Preserve distinct guarantees:

  • Shared iOS/Mac execution, compile guards, and Mac App Store/direct-build differences can expose different failures. Check actual CI routing and skips; compiling a test does not prove it executes. Mac UI tests are local-only.
  • Parser/XML, encrypted-container, in-memory edit, save safety, and compatibility suites have separate owners in the test docs. Foreign-authored inputs and KeePassXC opening KeeForge output are independent evidence. In-process round trips cannot replace an external oracle; the external reader cannot inspect every preserved byte.
  • Keep the compatibility harness's one assertion-bearing execution per artifact scenario, complete artifact inventory, and external expectations. Do not duplicate expensive KDF work to produce artifacts or shrink the matrix to improve timings.
  • Security boundaries, defaults, migration/storage formats, localization catalogs, entitlements, extension membership, and release tooling can justify static or exact value checks. Judge the independent contract, not the assertion's appearance.
  • Unit tests do not replace real focus/keyboard/window interactions or system AutoFill panels. Prefer headless tests where they reach the behavior; retain the smallest distinct UI proof. Screenshot captures are visual evidence, not assertion-free junk.

Do not delete a baseline failure because it is inconvenient. Separate product defects, test defects, environment failures, skips, and unknown causes before recommending work. Retain uncertain coverage pending evidence. Slow execution alone is not a removal case.

Show full SKILL.md (392 more words)Show less

Candidate evidence

For every proposed repair, consolidation, or deletion, record:

  • Exact test name and location; what it actually detects, including unique edge cases.
  • Production/support seam and its non-test callers, or evidence that it has none.
  • The retained test(s) that cover the same failure, with assertions and execution destinations, or why no meaningful contract would be lost. Name any assertions that must move before removal.
  • Relevant history explaining the test or seam; mark missing history as uncertainty.
  • Production/support simplification actually unlocked, if any; do not manufacture one.
  • Risk, focused validation commands, and whether each result is observed or proposed.

Prefer a few supported findings over a speculative deletion list. Keep the report short: actionable findings, retained false positives that matter, verification limits, and the next coherent batch. Put detailed evidence beside it under scratch/.

Cleanup and validation

When cleanup is authorized, change one coherent production boundary at a time. Move unique assertions into their retained owner before removing coverage or support. Honor the stable-core restrictions; test cleanup is not permission to redesign crypto or serialization. Update affected test maps and CI selections when ownership moves.

Run the smallest affected XCTest classes with -only-testing: using the repository's device preference, global Xcode lock, and full-log requirements. Coordinate execution centrally when agents are involved; do not edit files underneath an active test run. Tie local and reused CI evidence to the actual tested revision, dirty source state, target, and destination. Results from another revision do not validate this one; missing provenance remains unverified. Inspect Git status after verification for generated source or catalog changes and keep them separate from the audited revision. Check the executed tests and skips as well as the verdict; zero executed tests is not a pass. Expand verification only for affected contracts or unresolved concerns.

Use the compatibility suites and platform gates required by the repository when creation, edits, parsing/writing, or save behavior changes. Validate the artifact gate when its harness changes. Check Cloud partition validation when classes or schemes move. Full UI suites require the user's explicit request. Finish with git diff --check and inspect source, test, and support changes separately.

For an exhaustive subsystem campaign, read campaign.md. Otherwise stop after the requested scope. Report checks actually run, failures and limits, preserved contracts, and remaining work; distinguish completed discovery from validated cleanup. Follow local Git guidance for any authorized landing operations.

© KeeForge, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .agents/skills/test-audit of KeeForge/KeeForge.

  • SKILL.md
  • agents/openai.yaml
  • references/campaign.md

Open the folder on GitHubat commit 2778b90

Compare with similar skills

Test Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Test Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Test Audit this skillKeeForge/KeeForge111—~2.1kAutomated safety check: PassGPL-3.0
.NET MAUI Release Readinessdotnet/maui23k—~15kAutomated safety check: PassMIT
Release ValidationMesh-LLM/mesh-llm3.5k—~2.6kAutomated safety check: PassApache-2.0
Final Release Reviewopenai/openai-agents-python30k—~5.4kAutomated safety check: PassMIT
Final Release Reviewopenai/openai-agents-js3.9k—~4kAutomated safety check: PassMIT
Acceptance Demo GeneratorChachamaru127/claude-code-harness3.2k—~3.4kAutomated safety check: NotesMIT

Similar skills

  • Official

    Produces evidence-backed ship-readiness verdicts for .NET MAUI Servicing Releases and Previews, and drafts public-safe release handoff pages from the result.

    23k GitHub stars~15k tokensUpdated yesterday
    Product & Project ManagementAuto-check passed
  • Release Validation

    Mesh-LLM/mesh-llm

    A skill your agent uses when validating a MeshLLM release candidate or current HEAD against the last GitHub release, assembling the canonical feature/fix/modification inventory, testing locally…

    3.5k GitHub stars~2.6k tokensUpdated today
    Product & Project ManagementAuto-check passed
  • Final Release Review

    openai/openai-agents-python

    Official

    Assess a Python SDK release candidate or release plan against the previous release and recommend ship or block.

    30k GitHub stars~5.4k tokensUpdated today
    Product & Project ManagementAuto-check passed
  • Final Release Review

    openai/openai-agents-js

    Official

    Assess a JS SDK release candidate or release plan against the previous release and recommend ship or block.

    3.9k GitHub stars~4k tokensUpdated yesterday
    Product & Project ManagementAuto-check passed
  • Acceptance Demo Generator

    Chachamaru127/claude-code-harness

    Renders a single HTML page showing each acceptance criterion as verified or not, with a ship, wait, or reject recommendation for non-engineers.

    3.2k GitHub stars~3.4k tokensUpdated 3 days ago
    Product & Project ManagementAuto-check: notes
  • Schematic

    blader/schematic

    Reverse engineer a detailed product and technical specification document from a git branch's implementation.

    239 GitHub stars~2.2k tokensUpdated 7 mo ago
    Product & Project ManagementAuto-check passed

More from KeeForge/KeeForge

All 9 skills in this repo
  • Ship Release

    KeeForge/KeeForge

    Ship an accepted, soaked KeeForge candidate across iOS, Mac App Store, and direct Mac.

    111 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Publish App Store Version

    KeeForge/KeeForge

    Prepare and publish an already-built KeeForge iOS or macOS version through the App Store Connect API using an API key.

    111 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed
  • Keeforge GitHub Issues

    KeeForge/KeeForge

    Create, edit, comment on, close, reopen, classify, or change project fields for issues in KeeForge/KeeForge.

    111 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Pre Release Review

    KeeForge/KeeForge

    Statically review KeeForge changes since a shipped release for behavior risks, documentation inconsistencies, i18n gaps, and missing test coverage.

    111 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Respin Release

    KeeForge/KeeForge

    Replace an unshipped KeeForge candidate after a fix on an existing release branch.

    111 GitHub stars~844 tokensUpdated yesterday
    Auto-check passed
  • Triage Feedback

    KeeForge/KeeForge

    Triage product feedback by inspecting its message and attachments, checking implementation and existing issues, classifying each concern, and drafting a reporter response.

    111 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about Test Audit

What does Test Audit do?

Assess KeeForge test quality, redundant coverage, and test-support complexity; audit a selected subsystem or apply an authoring checklist while changing tests. Test Audit is an agent skill from KeeForge/KeeForge. Assess KeeForge test quality, redundant coverage, and test-support complexity; audit a selected subsystem or apply an authoring checklist while changing tests.

When should I use Test Audit?

Test Audit fits situations like: pruning requests; tasks that involve Feature launches and release readiness.

How do I install Test Audit in Claude Code?

Run `npx skills add KeeForge/KeeForge --skill test-audit -a claude-code`. Or copy the skill folder (.agents/skills/test-audit in KeeForge/KeeForge) into .claude/skills/test-audit in your project. Claude Code loads it when a task matches its description.

How do I install Test Audit in Codex?

Run `npx skills add KeeForge/KeeForge --skill test-audit -a codex`. Or copy the skill folder (.agents/skills/test-audit in KeeForge/KeeForge) into .agents/skills/test-audit in your project. Codex loads it when a task matches its description.

Can I use Test Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add KeeForge/KeeForge --skill test-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/test-audit, .gemini/skills/test-audit, .github/skills/test-audit and .opencode/skills/test-audit in your project.

What does Test Audit need to run?

Going by SKILL.md and its folder, Test Audit needs the command-line tools its instructions call (git).

Does Test Audit access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Test Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Test Audit use?

Test Audit is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Test Audit use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 620 tokens, read only when the agent opens those files.

What are the alternatives to Test Audit?

Skills that share tags, products or a category with Test Audit: .NET MAUI Release Readiness (dotnet/maui, 23k stars), Release Validation (Mesh-LLM/mesh-llm, 3.5k stars), Final Release Review (openai/openai-agents-python, 30k stars) and Final Release Review (openai/openai-agents-js, 3.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Test Audit?

KeeForge (a GitHub organization) maintains it in KeeForge/KeeForge, which has 111 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 6, 2026.

Source: KeeForge/KeeForge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.