Agent skill

Redamon Testing

by samugit83 in samugit83/redamon

How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie.

MITAuto-check passedSecurity

Install Redamon Testing

skills CLI
$ npx skills add samugit83/redamon --skill redamon-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install samugit83/redamon redamon-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/redamon-testing .claude/skills/redamon-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
redamon-testing
GitHub stars
2.9k
Token cost
~1.8k tokens
SKILL.md length
689 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie.

  • Tasks that involve Penetration testing
  • SKILL.md covers When to Use, Critical Rules, Assert the command a wrapper… and Where a test goes, and its tier, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Unit testing

What it does

Redamon Testing is an agent skill from samugit83/redamon. How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie. Trigger: editing any test.py, .test.ts(x) or tests/.sh; a test that is red, skipped or xfailed; a request to "run the tests", "make it green" or check coverage; editing redamon.sh cmdtest, tooling/scripts/pytestisolated.py, any conftest.py or any pytest.ini.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing, Unit testing and Containers. It works with pytest, Docker and Neo4j. The repository describes itself as: Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and… The licence is MIT.

When your agent uses it

  • Tasks that involve Penetration testing
  • Tasks that involve Unit testing
  • Tasks that involve Containers

Example prompts

  • “run the tests”
  • “make it green”
  • “/redamon-testing”

Requirements

  • Python 3
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 34ab441. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Redamon Testing loads about 1.8k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 689 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from samugit83/redamon at commit 34ab441, republished under its MIT licence (© samugit83). 689 words, ~1,761 tokens.

Download SKILL.mdSave it as .claude/skills/redamon-testing/SKILL.md (or your agent's skills folder).
name
redamon-testing
description
How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie. Trigger: editing any test_*.py, *.test.ts(x) or tests/*.sh; a test that is red, skipped or xfailed; a request to "run the tests", "make it green" or check coverage; editing redamon.sh cmd_test, tooling/scripts/pytest_isolated.py, any conftest.py or any pytest.ini.
license
MIT
metadata.author
redamon
metadata.version
1.0.0
metadata.scope
root
metadata.auto_invoke
Adding or editing a test file in any section, Investigating a red, skipped or xfailed test, Changing test tiers, conftest.py, pytest.ini, or the runner in…

When to Use

  • Writing or fixing a test anywhere in the repo, or deciding where a new test goes.
  • A test is red/skipped/xfailed and you must decide whether it is real.
  • You were asked to run the suite or verify a change "works".

The repo-wide rule "never validate with host pytest, use the Docker gate" lives in the root AGENTS.md CRITICAL RULES; this skill is everything after that: isolation, tiers, and how to write a test that asserts something.


Critical Rules

  • NEVER run pytest across a whole tree in one process. Many tests stub langchain/langgraph into sys.modules and bake tool objects against a fake @tool at import time, so whichever file collects first decides for all of them. You get phantom failures in files you never touched (classically a coroutine was expected, got <MagicMock>). Run ./redamon.sh test, or one file / node id. The gate exists for this: tooling/scripts/pytest_isolated.py runs each FILE in its own subprocess.
  • NEVER "fix" source because a test went red in a multi-file run. Re-run that one file in isolation first; if it passes alone the failure was pollution, not a bug.
  • NEVER print("SKIP..."); return to skip a test. pytest records that as PASSED while asserting nothing. Use self.skipTest(...) inside a TestCase or pytest.skip(...) in a bare function.
  • NEVER read a green gate as "the live checks passed". A self-skipping test that needs a service prints SKIP and exits 0, and the gate containers have no Neo4j, so the live-graph schema checks in recon/tests/test_schema_catalog.py SKIP in every CI run. Their hermetic counterparts in recon/tests/test_graph_writes_documented.py do run. Neither sees everything: the code scan cannot see the ~22 labels written with SET n += $props (the names are built in Python and appear in no file), and the live graph cannot see a feature this deployment never ran. After a schema change, run the live one against a stack before believing it.
  • NEVER rewrite an assertion so it passes. If a test reveals a real bug, mark it @pytest.mark.xfail(strict=True, reason=...) and say so. Tests must not enshrine bugs.
  • NEVER put a recon test in the root tests/ folder. Root tests/ runs in the agent image; recon files there must be listed in _ROOT_RECON_TESTS at redamon.sh:4476 or they run against the wrong image and fail on imports. New recon tests go in recon/tests/.
  • NEVER add a third-party import to a test without checking it is in the section image. Only pytest, pytest-cov, pytest-xdist, pytest-asyncio (requirements-test.txt) are guaranteed; anything else errors the whole file at collection. Prefer unittest.mock and the stdlib.
  • ALWAYS assert behaviour, not execution. For a tool wrapper, assert both the parsed result and the command that was built. Verify the patch target against the source (recon/tests/test_arjun.py broke when subprocess.run became Popen and the mocks kept targeting run).
  • ALWAYS make a test that needs a stack, binary, service or git HEAD skip cleanly. A hard failure on a missing prerequisite is a bug in the test.

Show full SKILL.md (203 more words)Show less

Assert the command a wrapper BUILDS (the direction most often skipped)

python
from recon.helpers.nuclei_helpers import build_nuclei_command   # the seam under test

cmd = build_nuclei_command(targets_file="/tmp/t.txt", output_file="/tmp/o.jsonl",
                           docker_image="projectdiscovery/nuclei:latest", dast_mode=True)
assert "-dast" in cmd            # the flag we asked for is present
assert cmd.count("-dast") == 1   # and not duplicated by a second code path

Reference: recon/tests/test_nuclei_two_pass.py. For a wrapper that also parses tool output, mock the tool (patch subprocess.run) and assert both the parsed result and the command from mock_run.call_args.

Where a test goes, and its tier

Tier is auto-assigned by filename in each conftest.py (live checked first). An explicit @pytest.mark.{unit,integration,live} wins, on the file or on a single test - the gate passes the tier to pytest as -m, so an opted-out test inside a unit-named file really is skipped:

Filename containsTierMeaning
live_, _live, _smoke, smoke_liveneeds a stack/service; self-skips
_integration.py, _skill.py, _e2eintegrationcross-layer / heavy deps
anything elseunithermetic; this is the gate
TestingPut it inTier
recon module / tool wrapperrecon/tests/unit
agent graph, nodes, tools, promptsagentic/tests/unit
graph_db, knowledge_base, supply_chain_*, mcproot tests/unit
redamon.sh / compose / deploy shell logictests/*_test.shbash, in the gate (shell section)
webapp React/TSnext to the source *.test.ts(x)vitest

Commands

bash
./redamon.sh test                 # unit gate, every section + webapp vitest; must be 100% green
./redamon.sh test all             # unit + integration (NOT live)
./redamon.sh test coverage        # per-section floor via REDAMON_COV_FLOOR
./agentic/run_tests.sh            # agent section only; per-file isolated
./agentic/run_tests.sh tests/test_foo.py::TestX::test_y   # single node id (already isolated)

An unbuilt image is skipped, not failed - read the section headers before trusting "all green".


Resources

© samugit83, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/redamon-testing of samugit83/redamon.

Open the folder on GitHubat commit 34ab441

Compare with similar skills

Redamon Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Redamon Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Redamon Testing this skillsamugit83/redamon2.9k—~1.8kAutomated safety check: PassMIT
Slow TestsUKGovernmentBEIS/inspect_ai2.9k—~1.4kAutomated safety check: PassMIT
Code PatternsAedelon/claude-code-blueprint120—~1.2kAutomated safety check: PassCustom licence
Flowfile Debugging PlaybookEdwardvaneechoud/Flowfile370—~6.3kAutomated safety check: PassMIT
Flowfile Testing And ValidationEdwardvaneechoud/Flowfile370—~8.3kAutomated safety check: NotesMIT
Maintainer Testing ReleaseVectorSpaceLab/AREX-Skill328—~697Automated safety check: PassAGPL-3.0

Similar skills

  • Slow Tests

    UKGovernmentBEIS/inspect_ai

    Run the gated test classes that plain pytest skips (slow Docker/sandbox tests, live model-provider API tests, flaky tests, trio variants).

    2.9k GitHub stars~1.4k tokensUpdated today
    Testing & QAAuto-check passed
  • Code Patterns

    Aedelon/claude-code-blueprint

    Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Flowfile Debugging Playbook

    Edwardvaneechoud/Flowfile

    Symptom-to-cause triage playbook for Flowfile (core/worker/kernel/frontend/AI) — covers "no such table" DB cascades (two distinct causes), import-time Alembic migration corruption, silent…

    370 GitHub stars~6.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Flowfile Testing And Validation

    Edwardvaneechoud/Flowfile

    Exact per-package pytest/vitest/playwright commands, the registered pytest markers and which need Docker, the testutils Docker fixture matrix, the shared-test-DB isolation model and its failure…

    370 GitHub stars~8.3k tokensUpdated yesterday
    Testing & QAAuto-check: notes
  • Maintainer Testing Release

    VectorSpaceLab/AREX-Skill

    Use this quip-miner sub-skill for maintainer pytest selection, CI invariants, no-inline-sampling lint, multiprocessing/hang debugging, versioning, Docker/PyInstaller release checks, and safe…

    328 GitHub stars~697 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed

More from samugit83/redamon

All 15 skills in this repo
  • Add Community Skill

    samugit83/redamon

    Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

    2.9k GitHub stars~775 tokensUpdated 2 days ago
    Auto-check passed
  • Add Partial Recon

    samugit83/redamon

    Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

    2.9k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Agentic Tool Integration

    samugit83/redamon

    Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…

    2.9k GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Builtin Agent Skill

    samugit83/redamon

    Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…

    2.9k GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Graph DB Writes

    samugit83/redamon

    Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

    2.9k GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • LLM Provider Integration

    samugit83/redamon

    Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.

    2.9k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed

Questions about Redamon Testing

What does Redamon Testing do?

How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie. Redamon Testing is an agent skill from samugit83/redamon. How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie.

When should I use Redamon Testing?

Redamon Testing fits situations like: tasks that involve Penetration testing; tasks that involve Unit testing; tasks that involve Containers.

How do I install Redamon Testing in Claude Code?

Run `npx skills add samugit83/redamon --skill redamon-testing -a claude-code`. Or copy the skill folder (skills/redamon-testing in samugit83/redamon) into .claude/skills/redamon-testing in your project. Claude Code loads it when a task matches its description.

How do I install Redamon Testing in Codex?

Run `npx skills add samugit83/redamon --skill redamon-testing -a codex`. Or copy the skill folder (skills/redamon-testing in samugit83/redamon) into .agents/skills/redamon-testing in your project. Codex loads it when a task matches its description.

Can I use Redamon Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add samugit83/redamon --skill redamon-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/redamon-testing, .gemini/skills/redamon-testing, .github/skills/redamon-testing and .opencode/skills/redamon-testing in your project.

What does Redamon Testing need to run?

SKILL.md names no scripts, command-line tools or credentials: Redamon Testing is instructions for the agent only. Our summary lists: Python 3; Docker.

Does Redamon Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Redamon Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Redamon Testing use?

Redamon Testing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Redamon Testing use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Redamon Testing?

Skills that share tags, products or a category with Redamon Testing: Slow Tests (UKGovernmentBEIS/inspect_ai, 2.9k stars), Code Patterns (Aedelon/claude-code-blueprint, 120 stars), Flowfile Debugging Playbook (Edwardvaneechoud/Flowfile, 370 stars) and Flowfile Testing And Validation (Edwardvaneechoud/Flowfile, 370 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Redamon Testing?

samugit83 (a GitHub user) maintains it in samugit83/redamon, which has 2,948 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 5, 2026.

Source: samugit83/redamon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.