Official agent skill

Mutation Check

by trailofbits in trailofbits/coop

Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized.

OfficialApache-2.0Auto-check passedDevelopment

Install Mutation Check

skills CLI
$ npx skills add trailofbits/coop --skill mutation-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/coop mutation-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/coop.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/mutation-check .claude/skills/mutation-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mutation-check
GitHub stars
762
Token cost
~389 tokens
SKILL.md length
177 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized.

  • Works in 5 steps: Inspect the diff before running. New… → Sanity-check changed exclusions with… → Run a full-file sweep for each touched… → …
  • Logic-dense modules change
  • Calls cargo
  • Before refactors

What it does

Mutation Check is an agent skill from trailofbits/coop, published by the product's own GitHub organization. Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized. Use when logic-dense modules change, before refactors, or when asked to verify mutation coverage.

Its SKILL.md is about 390 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Refactoring. The repository describes itself as: Isolated VM environment for running Claude Code and Codex. The licence is Apache-2.0.

When your agent uses it

  • Logic-dense modules change
  • Before refactors
  • Asked to verify mutation coverage

Example prompts

  • “/mutation-check”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Inspect the diff before running. New functions in logic modules that shell
  2. Sanity-check changed exclusions with cargo mutants --list -f .
  3. Run a full-file sweep for each touched scoped module and library tests only
  4. Triage mutants.out/missed.txt: add a discriminating test for real gaps,
  5. Report files swept, missed count before/after, every survivor's disposition,

What it can do on your machine

Read from SKILL.md and the folder at commit 0f1c4ef. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mutation Check loads about 389 tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 177 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~389

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/coop at commit 0f1c4ef, republished under its Apache-2.0 licence (© trailofbits). 177 words, ~389 tokens.

Download SKILL.mdSave it as .claude/skills/mutation-check/SKILL.md (or your agent's skills folder).
name
mutation-check
description
Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized. Use when logic-dense modules change, before refactors, or when asked to verify mutation coverage.

Mutation Check

Read docs/testing.md first.

  1. Inspect the diff before running. New functions in logic modules that shell out, drive &PlatformBackend, read a TTY, or write stdout must be excluded in .cargo/mutants.toml in the same PR. Extract and test their pure decision logic. Pure helpers remain in scope.
  2. Sanity-check changed exclusions with cargo mutants --list -f <file>.
  3. Run a full-file sweep for each touched scoped module and library tests only: cargo mutants -f src/<file>.rs -- --lib. Redirect output to a file; do not pipe a long run through head or grep.
  4. Triage mutants.out/missed.txt: add a discriminating test for real gaps, mark genuinely equivalent mutants with a narrow documented skip, and delete dead code. Confirm each new test by re-running the mutant or deliberately breaking the protected behavior.
  5. Report files swept, missed count before/after, every survivor's disposition, and whether .cargo/mutants.toml changed.

Do not spend a full mutation run on whole-module exclusions (backend.rs, lima.rs, setup.rs, update.rs, ssh.rs, vm.rs, network.rs, port_forward.rs, cmd.rs, prompt.rs, main.rs). Instead, identify the unit/integration blind spot explicitly and test extracted pure logic directly.

© trailofbits, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/mutation-check of trailofbits/coop.

Open the folder on GitHubat commit 0f1c4ef

Compare with similar skills

Mutation Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mutation Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mutation Check this skilltrailofbits/coop762—~389Automated safety check: PassApache-2.0
Guidelinesakash-network/node1.1k22 repos~577Automated safety check: PassMIT
Component Refactoringlangflow-ai/langflow156k—~3.5kAutomated safety check: PassMIT
Migrate Core Code to Submodulestinyhumansai/openhuman41k—~2.6kAutomated safety check: PassGPL-3.0
ast-grep Structural Searchcode-yeongyu/oh-my-openagent70k—~3.3kAutomated safety check: PassMIT
Systematic Code Refactoringluongnv89/claude-howto42k—~3kAutomated safety check: PassMIT

Similar skills

  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 22 repos~577 tokens
    DevelopmentAuto-check passed
  • Component Refactoring

    langflow-ai/langflow

    Refactor high-complexity React components in Langflow frontend.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    41k GitHub stars~2.6k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • ast-grep Structural Search

    code-yeongyu/oh-my-openagent

    Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script.

    70k GitHub stars~3.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Systematic Code Refactoring

    luongnv89/claude-howto

    Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.

    42k GitHub stars~3k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Codex

    skills-directory/skill-codex

    A skill your agent uses when the user asks to run Codex CLI (codex exec, codex resume) or references OpenAI Codex for code analysis, refactoring, or automated editing

    1.5k GitHub starsUsed in 3 repos~1.8k tokens
    DevelopmentAuto-check passed

More from trailofbits/coop

  • Closeout Review

    trailofbits/coop

    Official

    Run the final scope-controlled review before committing, pushing, or opening a PR.

    762 GitHub stars~700 tokensUpdated today
    Auto-check passed
  • Review

    trailofbits/coop

    Official

    Review a coop pull request or local diff with independent, self-validated correctness, design, convention, security, API, test, documentation, and comment lenses.

    762 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Babysit PR

    trailofbits/coop

    Official

    Shepherd the current user's open PR through base updates, CI failures, and review feedback without rewriting history or merging.

    762 GitHub stars~625 tokensUpdated today
    Auto-check passed
  • Babysit My PRs

    trailofbits/coop

    Official

    Triage and shepherd all open PRs owned by the current GitHub user, isolating each writable worker in its own worktree.

    762 GitHub stars~453 tokensUpdated today
    Auto-check passed
  • Integration

    trailofbits/coop

    Official

    Run and interpret coop's VM integration suite locally on Lima or remotely on Firecracker.

    762 GitHub stars~227 tokensUpdated today
    Auto-check passed

Categories

Questions about Mutation Check

What does Mutation Check do?

Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized. Mutation Check is an agent skill from trailofbits/coop, published by the product's own GitHub organization.toml synchronized.

When should I use Mutation Check?

Mutation Check fits situations like: logic-dense modules change; before refactors; asked to verify mutation coverage.

How do I install Mutation Check in Claude Code?

Run `npx skills add trailofbits/coop --skill mutation-check -a claude-code`. Or copy the skill folder (.agents/skills/mutation-check in trailofbits/coop) into .claude/skills/mutation-check in your project. Claude Code loads it when a task matches its description.

How do I install Mutation Check in Codex?

Run `npx skills add trailofbits/coop --skill mutation-check -a codex`. Or copy the skill folder (.agents/skills/mutation-check in trailofbits/coop) into .agents/skills/mutation-check in your project. Codex loads it when a task matches its description.

Can I use Mutation Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/coop --skill mutation-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mutation-check, .gemini/skills/mutation-check, .github/skills/mutation-check and .opencode/skills/mutation-check in your project.

What does Mutation Check need to run?

Going by SKILL.md and its folder, Mutation Check needs the command-line tools its instructions call (cargo).

Does Mutation Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mutation Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mutation Check use?

Mutation Check is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mutation Check use?

About 389 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mutation Check?

Skills that share tags, products or a category with Mutation Check: Guidelines (akash-network/node, 1.1k stars), Component Refactoring (langflow-ai/langflow, 156k stars), Migrate Core Code to Submodules (tinyhumansai/openhuman, 41k stars) and ast-grep Structural Search (code-yeongyu/oh-my-openagent, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mutation Check?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/coop, which has 762 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/coop on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.