Agent skill

Test Audit

by openclaw in openclaw/openclaw-enterprise

Gate new or changed Enterprise tests and audit existing tests for observable behavior, credible regressions, duplicate coverage, and test-only production seams.

MITAuto-check passed

Install Test Audit

skills CLI
$ npx skills add openclaw/openclaw-enterprise --skill test-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/openclaw-enterprise test-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/openclaw-enterprise.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/test-audit .claude/skills/test-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
test-audit
GitHub stars
359
Token cost
~1.1k tokens
SKILL.md length
527 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Gate new or changed Enterprise tests and audit existing tests for observable behavior, credible regressions, duplicate coverage, and test-only production seams.

  • Works in 4 steps: What observable behavior, invariant, or… → What credible regression makes it fail? → Why does existing coverage not already… → …
  • SKILL.md covers Authoring gate, Audit and retention, Validate and hand off and Provenance
  • Calls node, pnpm and git

What it does

Test Audit is an agent skill from openclaw/openclaw-enterprise. Gate new or changed Enterprise tests and audit existing tests for observable behavior, credible regressions, duplicate coverage, and test-only production seams.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: The Enterprise-grade Control Plane for modern agentic workloads. The licence is MIT.

Example prompts

  • “/test-audit”

Requirements

  • Docker

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. What observable behavior, invariant, or independent contract does it protect?
  2. What credible regression makes it fail?
  3. Why does existing coverage not already catch that failure? Prefer extending
  4. Does it need an export, flag, wrapper, or injection hook that no production

What it can do on your machine

Read from SKILL.md and the folder at commit 96faf10. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • pnpm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Test Audit loads about 1.1k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 527 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/openclaw-enterprise at commit 96faf10, republished under its MIT licence (© openclaw). 527 words, ~1,126 tokens.

Download SKILL.mdSave it as .claude/skills/test-audit/SKILL.md (or your agent's skills folder).
name
test-audit
description
Gate new or changed Enterprise tests and audit existing tests for observable behavior, credible regressions, duplicate coverage, and test-only production seams.

Test Audit

Use the authoring gate when writing or changing tests. For a requested audit, inspect the selected scope before proposing edits; keep each batch coherent. Read repository test integrity rules first. Use fixture and scenario conventions when extracting reusable setup, builders, or contract suites. Keep expected outcomes independent of the implementation and resource ownership explicit.

Authoring gate

Before adding a test, answer all four questions:

  1. What observable behavior, invariant, or independent contract does it protect?
  2. What credible regression makes it fail?
  3. Why does existing coverage not already catch that failure? Prefer extending an existing case or fixture over duplicating the same proof.
  4. Does it need an export, flag, wrapper, or injection hook that no production caller needs? If so, test at the real owning boundary instead.

A missing answer means the test is not ready. Demonstrate that a bug regression test fails on the pre-fix implementation for the intended reason and passes with the repair. If that comparison cannot run, report the gap rather than claiming the regression was proved. Do not replace real behavior with a self-fulfilling mock or copy application logic into a fixture.

Audit and retention

Read the complete candidate test, production owner, callers, overlapping tests, relevant history, and CI selection. Inspect the dependency contract when the test claims dependency-backed behavior.

Look for assertion-free probes, self-comparisons, source-string assertions, copied inventories, duplicate contract invocations, private call-shape assertions, and exports or wrappers retained only for tests. These are candidates, not automatic deletions. A test that fails after behavior-preserving refactoring may need to move to a stable boundary.

Retain independent API, Driver, storage, security, configuration, protocol, packaging, generated-artifact, or architecture contract checks. Observable call ordering and credible regressions remain valuable. Static or slow tests are not low-value merely because of their form; source inspection can be an independent guard, but checking a SQL string does not prove database behavior.

Before deleting or rewriting a candidate, record:

Show full SKILL.md (206 more words)Show less
  • Exact test name and path, and the failure it can detect.
  • Non-test callers of any covered production seam.
  • Stronger remaining proof, or why the behavior no longer needs coverage.
  • Relevant history, intended simplification, risk, and focused validation command.

Keep uncertain candidates and explain why. Within the authorized audit scope, remove confirmed obsolete test-only seams with their tests; do not preserve aliases or add new production seams to replace them. Optimize confidence rather than deletion counts. Report potential product changes separately.

Validate and hand off

Use enterprise-testing to choose the smallest real proof. Run commands from the repository root, for example:

sh
node --test tests/conformance/contracts.test.mjs
node --test tests/integration/console-api.test.mjs
git diff --check

Select actual owner/sibling files for the change; the examples are not mandatory targets. Use pnpm test:conformance or pnpm test:integration when broader contracts warrant them. Persistence and runtime claims require the existing PostgreSQL, Docker, or Kubernetes procedures. Do not edit inputs while tests run. Retain integration-test comments that explain intent and invariants.

After audit edits, use deslop for behavior-neutral cleanup before requested autoreview. Report changed candidates, retained false positives, production versus test changes, exact proof and skips, and unresolved gaps. Follow contribution rules for authorized commits and PRs; an audit does not authorize a merge or another workstream.

Provenance

Adapted from OpenClaw; see source and intentional adaptations.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/test-audit of openclaw/openclaw-enterprise.

Open the folder on GitHubat commit 96faf10

Compare with similar skills

Test Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Test Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Test Audit this skillopenclaw/openclaw-enterprise359—~1.1kAutomated safety check: PassMIT
Orch Change Featureaffaan-m/ECC274k1 repos~420Automated safety check: PassMIT
PR Feedback Quality Gatenexu-io/open-design100k—~572Automated safety check: PassApache-2.0
Change Verification Gatefengshao1227/ccg-workflow5.9k—~511Automated safety check: NotesMIT
Gateplugin87/ux-ui-agent-skills1.5k—~532Automated safety check: PassMIT
Make Changesremix-run/remix33k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Orchestrate altering an existing, working feature to new desired behavior — update its tests to the new spec, change the implementation to match, review, and gated commit.

    274k GitHub starsUsed in 1 repo~420 tokens
    Auto-check passed
  • PR Feedback Quality Gate

    nexu-io/open-design

    Safely track pull request feedback, resolve review comments or merge conflicts, validate fixes, and use a read-only cross-review before committing or pushing follow-up changes.

    100k GitHub stars~572 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Change Verification Gate

    fengshao1227/ccg-workflow

    Analyzes a code diff for documentation sync, test coverage and impact scope, warning when docs or tests lag behind a design-level change or a large edit.

    5.9k GitHub stars~511 tokensUpdated 22 days ago
    DevelopmentAuto-check: notes
  • Gate

    plugin87/ux-ui-agent-skills

    Run the one-command quality gate and report the real N/N result.

    1.5k GitHub stars~532 tokensUpdated today
    Frontend & DesignAuto-check passed
  • Make Changes

    remix-run/remix

    Create or update Remix repo change files under packages//.changes.

    33k GitHub stars~2.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Brain Ingest Gate

    garrytan/gbrain

    Pre-write quality gate for content entering the brain. An agent skill from garrytan/gbrain.

    31k GitHub stars~3.9k tokensUpdated today
    Testing & QAAuto-check passed

More from openclaw/openclaw-enterprise

All 9 skills in this repo
  • Local Dev

    openclaw/openclaw-enterprise

    Develop OpenClaw Enterprise changes with proportional verification and source-backed flow documentation for non-trivial behavior.

    359 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Technical Writing

    openclaw/openclaw-enterprise

    Write, organize, name, edit, or review Enterprise developer documentation, specifications, and technical instructions; ground claims in current source and finish with a plain-language cleanup.

    359 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Enterprise Testing

    openclaw/openclaw-enterprise

    Select proportional Enterprise validation and diagnose exact CI runs, distinguishing product, harness, infrastructure, and credential failures.

    359 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Mermaid Diagrams

    openclaw/openclaw-enterprise

    Create or refine readable Mermaid diagrams for changes, architecture, lifecycles, and dependencies in Markdown documents and PR descriptions.

    359 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Design Review

    openclaw/openclaw-enterprise

    Assess designs, public interfaces, state ownership, readability, and refactor proposals when the task calls for design review or structural simplification; not for unrelated routine edits.

    359 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Deslop

    openclaw/openclaw-enterprise

    Clean only the current Enterprise diff before autoreview, preserving behavior, security boundaries, required TODOs, and useful test-intent comments.

    359 GitHub stars~739 tokensUpdated today
    Auto-check passed

Questions about Test Audit

What does Test Audit do?

Gate new or changed Enterprise tests and audit existing tests for observable behavior, credible regressions, duplicate coverage, and test-only production seams. Test Audit is an agent skill from openclaw/openclaw-enterprise. Gate new or changed Enterprise tests and audit existing tests for observable behavior, credible regressions, duplicate coverage, and test-only production seams.

How do I install Test Audit in Claude Code?

Run `npx skills add openclaw/openclaw-enterprise --skill test-audit -a claude-code`. Or copy the skill folder (.agents/skills/test-audit in openclaw/openclaw-enterprise) into .claude/skills/test-audit in your project. Claude Code loads it when a task matches its description.

How do I install Test Audit in Codex?

Run `npx skills add openclaw/openclaw-enterprise --skill test-audit -a codex`. Or copy the skill folder (.agents/skills/test-audit in openclaw/openclaw-enterprise) into .agents/skills/test-audit in your project. Codex loads it when a task matches its description.

Can I use Test Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw-enterprise --skill test-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/test-audit, .gemini/skills/test-audit, .github/skills/test-audit and .opencode/skills/test-audit in your project.

What does Test Audit need to run?

Going by SKILL.md and its folder, Test Audit needs the command-line tools its instructions call (node, pnpm and git). Our summary lists: Docker.

Does Test Audit access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Test Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Test Audit use?

Test Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Test Audit use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Test Audit?

Skills that share tags, products or a category with Test Audit: Orch Change Feature (affaan-m/ECC, 274k stars), PR Feedback Quality Gate (nexu-io/open-design, 100k stars), Change Verification Gate (fengshao1227/ccg-workflow, 5.9k stars) and Gate (plugin87/ux-ui-agent-skills, 1.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Test Audit?

openclaw (a GitHub organization) maintains it in openclaw/openclaw-enterprise, which has 359 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.

Source: openclaw/openclaw-enterprise on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.