Agent skill

Ripwire Write Tests

by redhat-et in redhat-et/ripwire

Write tests for EXISTING code that has none — 'this is untested, add coverage', 'add a safety net first'; also verify a new test reaches its intended code.

Apache-2.0Auto-check: notesTesting & QA

Install Ripwire Write Tests

skills CLI
$ npx skills add redhat-et/ripwire --skill ripwire-write-tests -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install redhat-et/ripwire ripwire-write-tests --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ripwire-write-tests .claude/skills/ripwire-write-tests && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ripwire-write-tests
GitHub stars
2.4k
Token cost
~1.1k tokens
SKILL.md length
539 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Write tests for EXISTING code that has none — 'this is untested, add coverage', 'add a safety net first'; also verify a new test reaches its intended code.

  • Works in 3 steps: Untested integration seams — ripwire… → The tested=1 coverage lens — ripwire… → Pick the target — prefer a seam over a…
  • Tasks that involve Test generation
  • SKILL.md covers Find the gap, Write it with the right contract, Verify the test actually… and Output
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ripwire Write Tests is an agent skill from redhat-et/ripwire. Write tests for EXISTING code that has none — 'this is untested, add coverage', 'add a safety net first'; also verify a new test reaches its intended code. Finds what no test reaches: --seams ranks untested cross-module edges, --callers gives the outside contract. Diff test selection → change-check. For one target one --seams or --callers pass suffices.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Test generation. The repository describes itself as: The ripgrep of AI context: a zero-dependency C++23 CLI + MCP server for coding agents. Find what you want without reading the repo, then check you built what you meant — blast… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Test generation

Example prompts

  • “this is untested, add coverage”
  • “add a safety net first”
  • “/ripwire-write-tests”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Untested integration seams — ripwire --seams --legend=compact → lists cross-module call edges no
  2. The tested=1 coverage lens — ripwire --metrics --legend=compact --top-k=50 (or --for="", which
  3. Pick the target — prefer a seam over a symbol lacking tested=1 when both are candidates; a seam test

What it can do on your machine

Read from SKILL.md and the folder at commit 255dc19. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ripwire Write Tests loads about 1.1k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 539 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from redhat-et/ripwire at commit 255dc19, republished under its Apache-2.0 licence (© redhat-et). 539 words, ~1,056 tokens.

Download SKILL.mdSave it as .claude/skills/ripwire-write-tests/SKILL.md (or your agent's skills folder).
name
ripwire-write-tests
description
Write tests for EXISTING code that has none — 'this is untested, add coverage', 'add a safety net first'; also verify a new test reaches its intended code. Finds what no test reaches: --seams ranks untested cross-module edges, --callers gives the outside contract. Diff test selection → change-check. For one target one --seams or --callers pass suffices.
allowed-tools
Bash, Read

Writing tests with ripwire

Routing: • Vetting a diff you already wrote (does it have test cover) → ripwire-change-check. • Judging whether your OWN code got better/worse → ripwire-quality-bar. • Don't know which symbol is even the bug → ripwire-find-bug. • Not sure which skill? → ripwire-router.

<dir> = repo root. This skill answers "what should I write a test for, and what does it need to cover" — not "is my diff safe" (that's change-check).

Find the gap

  1. Untested integration seams — ripwire <dir> --seams --legend=compact → <seams> lists cross-module call edges no test reaches. These are the highest-value targets: a bug here crosses a boundary silently, and one test per seam buys the most coverage per line written. Scope with <dir> = a subsystem to focus the seam list.
  2. The tested=1 coverage lens — ripwire <dir> --metrics --legend=compact --top-k=50 (or --for="<area>", which carries the same lens inline) → tested="1" means an indexed test-path symbol transitively reaches this production symbol. On these explicit metric surfaces the attribute is omitted when no indexed test reaches it; the binary never prints a fabricated zero. Cross an omitted tested with in= (fan-in): a widely-relied-on function with no indexed safety net is a sharper priority than an uncovered leaf. Shell/subprocess test coverage remains outside the call graph, so absence is a structural finding, not proof that no external test exists.
  3. Pick the target — prefer a seam over a symbol lacking tested=1 when both are candidates; a seam test proves two modules cooperate correctly, a unit test on one function does not.

Write it with the right contract

  1. The contract from OUTSIDE — ripwire <dir> --callers=SYM --legend=compact for the symbol you're testing. Callers show the preconditions and argument shapes callers actually rely on — write the test against that observed contract, not just the signature.
  2. The body, to know what branches exist — ripwire <dir> --expand=SYM --legend=compact → full source + callee signatures. Cover the branches; don't just re-assert the happy path the caller already exercises.
Show full SKILL.md (222 more words)Show less

Verify the test actually registers

  1. Confirm it's wired in — ripwire <dir> --affected=<the file you just changed> --legend=compact should now list your new test file among the tests that transitively reach the changed code. If it doesn't show up, the test harness isn't discovering the new file (wrong naming convention, missing registration) — fix that before trusting the coverage. 6b. Read what an existing test already covers — ripwire <dir> --exercises=test/<harness> --legend=compact lists the non-test symbols that test transitively calls into, ranked. Use it before writing anything to avoid re-covering ground a neighbouring harness already holds, and use it as the first call when an existing test FAILS and you only have its name. (A non-test path refuses — the verb is the test/non-test partition; for "what does this file call", use --callees.)
  2. Close the loop with the gate — once --affected proves the test registers, ripwire <dir> --test-gate --legend=compact on the symbol's file should now go green (the symbol drops out of the untested-blast-radius list). This is the same TDAD-parity gate ripwire-change-check runs before merge — writing the test here is what makes it pass there.

Output

Name the seam or symbol lacking tested=1 chosen and why (seam > high-fan-in symbol > leaf), the contract drawn from --callers, and confirmation from --affected that the new test registers. Re-run --seams/--metrics afterward — the gap you targeted should be gone.

© redhat-et, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ripwire-write-tests of redhat-et/ripwire.

Open the folder on GitHubat commit 255dc19

Compare with similar skills

Ripwire Write Tests next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ripwire Write Tests compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ripwire Write Tests this skillredhat-et/ripwire2.4k—~1.1kAutomated safety check: NotesApache-2.0
Emcaklofas/kicad-happy1.3k1 repos~2.8kAutomated safety check: PassMIT
Swig Testswig/swig6.3k—~2.3kAutomated safety check: PassCustom licence
Generate Test Cases342164796/generate-test-cases1191 repos~2.9kAutomated safety check: PassNone
Verify Cc Safety Netkenryu42/cc-safety-net1.6k—~2kAutomated safety check: PassMIT
Wioworkersio/skills180—~5.8kAutomated safety check: PassMIT

Similar skills

  • Emc

    aklofas/kicad-happy

    EMC pre-compliance risk analysis for KiCad PCB designs — 18 check categories, 44 rule IDs covering ground planes, decoupling, I/O filtering, switching harmonics, clock routing, differential pair…

    1.3k GitHub starsUsed in 1 repo~2.8k tokens
    Testing & QAAuto-check passed
  • Swig Test

    swig/swig

    Run SWIG test suite for specific languages. An agent skill from swig/swig.

    6.3k GitHub stars~2.3k tokensUpdated today
    Testing & QAAuto-check passed
  • Generate Test Cases

    342164796/generate-test-cases

    自主学习型测试文档生成器。从需求文档(Markdown)生成测试用例 XMind 文件,支持持久化记忆和持续学习。当用户提到"生成测试用例"、"根据需求生成测试"时触发。

    119 GitHub starsUsed in 1 repo~2.9k tokens
    Testing & QAAuto-check passed
  • Verify Cc Safety Net

    kenryu42/cc-safety-net

    Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence.

    1.6k GitHub stars~2k tokensUpdated today
    Testing & QAAuto-check passed
  • Wio

    workersio/skills

    Testing workflow skill for finding high-value test candidates, writing focused tests, generating realistic workloads, reviewing test value, and diagnosing test-suite health.

    180 GitHub stars~5.8k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed
  • File Server

    microsoft/WindowsProtocolTestSuites

    Official

    ALWAYS LOAD THIS SKILL when working with FileServer, SMB, SMB2, SMB3, CIFS, file sharing, MS-SMB2, MS-FSCC, MS-FSA, MS-DFSC, MS-FSRVP, MS-RSVD, MS-SQOS, or any file server protocol test…

    567 GitHub stars~4.1k tokensUpdated 22 days ago
    Testing & QAAuto-check passed

More from redhat-et/ripwire

All 19 skills in this repo
  • Ripwire Output Emission

    redhat-et/ripwire

    Rules for writing and converting formatted output in ripwire's C++ source with its emit helpers, keeping every printed byte identical to the old printf output.

    2.4k GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Ripwire Change Check

    redhat-et/ripwire

    Checks whether a working-tree diff or a pull request is safe to merge: blast radius, tests to run, contract breaks, branch conflicts and stranded work.

    2.4k GitHub stars~4.3k tokensUpdated 2 days ago
    Auto-check: notes
  • Ripwire Graph Query

    redhat-et/ripwire

    Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

    2.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check: notes
  • Ripwire Subsystem Handoff

    redhat-et/ripwire

    Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.

    2.4k GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Ripwire Code Navigation

    redhat-et/ripwire

    Answers questions about a named symbol, such as its callers, what it calls, the path between two symbols or the downstream impact of changing it, using the ripwire CLI.

    2.4k GitHub stars~4.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Contributor guide for reading clang optimization remarks while editing ripwire's own C++, deciding between a source change and a build change such as LTO or PGO.

    2.4k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check: notes

Categories

Questions about Ripwire Write Tests

What does Ripwire Write Tests do?

Write tests for EXISTING code that has none — 'this is untested, add coverage', 'add a safety net first'; also verify a new test reaches its intended code. Ripwire Write Tests is an agent skill from redhat-et/ripwire. Write tests for EXISTING code that has none — 'this is untested, add coverage', 'add a safety net first'; also verify a new test reaches its intended code.

When should I use Ripwire Write Tests?

Ripwire Write Tests fits situations like: tasks that involve Test generation.

How do I install Ripwire Write Tests in Claude Code?

Run `npx skills add redhat-et/ripwire --skill ripwire-write-tests -a claude-code`. Or copy the skill folder (skills/ripwire-write-tests in redhat-et/ripwire) into .claude/skills/ripwire-write-tests in your project. Claude Code loads it when a task matches its description.

How do I install Ripwire Write Tests in Codex?

Run `npx skills add redhat-et/ripwire --skill ripwire-write-tests -a codex`. Or copy the skill folder (skills/ripwire-write-tests in redhat-et/ripwire) into .agents/skills/ripwire-write-tests in your project. Codex loads it when a task matches its description.

Can I use Ripwire Write Tests in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redhat-et/ripwire --skill ripwire-write-tests -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ripwire-write-tests, .gemini/skills/ripwire-write-tests, .github/skills/ripwire-write-tests and .opencode/skills/ripwire-write-tests in your project.

What does Ripwire Write Tests need to run?

SKILL.md names no scripts, command-line tools or credentials: Ripwire Write Tests is instructions for the agent only. Its frontmatter pre-approves these tools: Bash, Read.

Does Ripwire Write Tests access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ripwire Write Tests safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ripwire Write Tests use?

Ripwire Write Tests is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ripwire Write Tests use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ripwire Write Tests?

Skills that share tags, products or a category with Ripwire Write Tests: Emc (aklofas/kicad-happy, 1.3k stars), Swig Test (swig/swig, 6.3k stars), Generate Test Cases (342164796/generate-test-cases, 119 stars) and Verify Cc Safety Net (kenryu42/cc-safety-net, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ripwire Write Tests?

redhat-et (a GitHub organization) maintains it in redhat-et/ripwire, which has 2,412 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 4, 2026.

Source: redhat-et/ripwire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.