Official agent skill

mewt and muton Mutation Testing

by trailofbits in trailofbits/skills

Routes mutation testing work with mewt or muton to the right workflow: configuring a campaign, hunting bugs in untested code, or reporting on surviving mutants.

OfficialCC-BY-SA-4.0Auto-check: notesTesting & QA

Install mewt and muton Mutation Testing

skills CLI
$ npx skills add trailofbits/skills --skill mutation-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills mutation-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/mutation-testing/skills/mutation-testing .claude/skills/mutation-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mutation-testing
GitHub stars
7.4k
Token cost
~1.5k tokens
SKILL.md length
559 words
Files
12 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Routes mutation testing work with mewt or muton to the right workflow: configuring a campaign, hunting bugs in untested code, or reporting on surviving mutants.

  • Setting up and scoping a mutation testing campaign with mewt or muton
  • SKILL.md covers When to Use, When NOT to Use, Routing and Essential Commands, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Making a slow campaign run faster

What it does

The skill acts as a router. It picks one of three workflows, setting up or speeding up a campaign, hunting for bugs after a campaign has finished, or turning results into a formal report, and loads only the reference files that workflow needs. mewt and muton share the same interface, so examples use mewt and muton projects swap in muton.toml and muton.sqlite.

Reference notes cover trimming long campaigns, a catalog of equivalent mutants and how to verify them, severity tiers, a report template, patterns for blockchain targets such as Solidity, Move, FunC and Cairo, and parsing anchors for output from slither-mutate, mull and dextool-mutate. Commands follow the mewt 4.x API, with mewt --help named as the authority. Questions about tests or line coverage with no mutation testing in play are out of scope.

When your agent uses it

  • Setting up and scoping a mutation testing campaign with mewt or muton
  • Making a slow campaign run faster
  • Analyzing surviving mutants and spotting equivalent ones
  • Using escaped mutants to find bugs in untested code

Example prompts

  • “Set up a mewt campaign for the src directory and trim it so it finishes sooner.”
  • “Our muton run finished. Which surviving mutants are equivalent and which hide real bugs?”
  • “Write a formal report from the mewt results, with severity ratings.”

Requirements

  • mewt or muton installed
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Grep

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

mewt and muton Mutation Testing loads about 1.5k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 559 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 559 words, ~1,549 tokens.

Download SKILL.mdSave it as .claude/skills/mutation-testing/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
mutation-testing
description
Configures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps. Use when setting up mutation testing, reviewing campaign results, identifying equivalent mutants, or finding bugs from surviving mutations.
allowed-tools
Read, Write, Bash, Grep

Mutation Testing (mewt/muton)

Routes to the right mutation testing workflow and loads the references that workflow needs.

Note: muton and mewt share identical interfaces. Examples use mewt; substitute muton and its file names (muton.toml, muton.sqlite) for muton projects.

mewt --help and mewt <subcommand> --help are the source of truth for command-line behavior. Examples below reflect the mewt 4.x API; run --help when a flag looks unfamiliar or a command fails.

When to Use

Use this skill when the user:

  • Mentions "mewt", "muton", or "mutation testing"
  • Wants to configure, scope, or speed up a mutation testing campaign
  • Wants to analyze mutation results — surviving/uncaught mutants, equivalent mutants, kill rate
  • Wants to use mutation results to find bugs in the source code

When NOT to Use

Do not use this skill when the user asks about tests or line coverage without any mutation testing context.


Routing

Pick the workflow, then load it together with the references listed for it. Workflows and references do not load each other — that decision belongs here.

Setting up, scoping, or speeding up a campaign → workflows/configuration.md → Also load references/optimization-strategies.md when the campaign estimate is long enough to need trimming, or the user asks to make it faster.

Campaign finished, hunting for bugs in untested code → workflows/bug-hunter.md

Turning results into a formal analysis report → workflows/analyzing-results.md, plus:

Anything else → run mewt --help or mewt <subcommand> --help, then assist directly.


Essential Commands

bash
# Set up and run
mewt init                    # Create config and database
mewt mutate [paths]          # Generate mutants without testing them
mewt run [paths]             # Generate mutants and run the campaign

# Read results
mewt status                  # Overview with per-file breakdown
mewt results                 # Uncaught mutants (default view)
mewt results --all           # Every outcome, not just uncaught
mewt results --format json   # json | sarif | ids | table

# Narrow down (these filters work on both `results` and `print mutants`)
mewt results --target 'src/auth/**'   # Quote globs so the shell does not expand them
mewt results --severity high,medium
mewt results --mutation-types ER,CR
mewt results --status Uncaught        # Uncaught | TestFail | Skipped | Timeout
mewt results --line 42

# Investigate and re-test
mewt print mutant --id [id]              # View the mutated code
mewt test --ids [ids]                    # Re-test specific mutants
mewt test --ids-file uncaught_ids.txt    # Re-test IDs from a file, or '-' for stdin

# Inspect configuration
mewt print config                        # Effective config
mewt print targets                       # Files actually mutated
mewt print mutations --language [lang]   # Mutations and severities for a language

Language labels are canonical family or family/dialect values in mewt 4.x — for example rust, javascript/ts, move/sui, move/iota.


What Results Mean

  • Caught/TestFail: tests detected the mutation (good)
  • Uncaught: tests did not detect the change. Inspect the code to distinguish a testing gap from an equivalent mutation.
  • Timeout: tests took too long — inconclusive, not evidence of coverage
  • Skipped: a less severe mutant was skipped because a more severe mutant on the same line was uncaught

Show full SKILL.md (206 more words)Show less

Interpreting Mutation Types

mewt print mutations --language [lang] lists every mutation slug, description, and severity for a language, and is authoritative — the operator set grows with each release. What that output does not tell you is what a survivor means, which is where prioritization comes from:

SeverityRepresentative slugsWhat an uncaught mutant tells you
HighER (Error Replacement)Tests tolerate the injected error. Investigate whether the path executes, whether error handling masks the change, and whether assertions check the outcome.
MediumCR (Comment Replacement)Removing the statement does not fail the tests. Check whether its effects matter and whether assertions observe them.
MediumIF/IT (If False/True), NR (Negation Removal)Tests do not distinguish the changed condition. Both constant replacements surviving can indicate an unexecuted condition or weak assertions on the branch outcomes.
LowOperator shuffles (AOS, COS, LOS, BOS, shift/assignment variants), BL, AS, LC, WFCheck boundary inputs, arithmetic assertions, and semantic equivalence. The mutation result alone does not establish whether the code executed.

Severity ranks the mutation, not the risk. A low-severity survivor in a fee calculation matters more than a high-severity survivor in a log line — weigh what the mutated code does. Filter with --severity to work through the results in priority order.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (references, assets) in plugins/mutation-testing/skills/mutation-testing of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/blockchain-patterns.md
  • references/equivalent-mutants.md
  • references/input-formats.md
  • references/optimization-strategies.md
  • references/report-template.md
  • references/severity-classification.md
  • workflows/analyzing-results.md
  • workflows/bug-hunter.md
  • workflows/configuration.md

Open the folder on GitHubat commit 82fe822

Compare with similar skills

mewt and muton Mutation Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

mewt and muton Mutation Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
mewt and muton Mutation Testing this skilltrailofbits/skills7.4k—~1.5kAutomated safety check: NotesCC-BY-SA-4.0
Senior QAnicepkg/auto-company1923 repos~1.1kAutomated safety check: NotesNone
Golang Testingantoniopaya22/go-rest-template1729 repos~4.2kAutomated safety check: PassNone
Test RoadmapOvid/paad131—~2.3kAutomated safety check: PassMIT
Designing TestsCloudAI-X/opencode-workflow275—~2.9kAutomated safety check: PassMIT
Next QA Ideabreaking-brake/cc-wf-studio5.4k—~1.7kAutomated safety check: PassCustom licence

Similar skills

  • Senior QA

    nicepkg/auto-company

    Comprehensive QA and testing skill for quality assurance, test automation, and testing strategies for ReactJS, NextJS, NodeJS applications.

    192 GitHub starsUsed in 3 repos~1.1k tokens
    Testing & QAAuto-check: notes
  • Golang Testing

    antoniopaya22/go-rest-template

    Go testing patterns including table-driven tests, subtests, benchmarks, fuzzing, and test coverage.

    172 GitHub starsUsed in 9 repos~4.2k tokens
    Testing & QAAuto-check passed
  • Test Roadmap

    Ovid/paad

    EXPERIMENTAL. An agent skill from Ovid/paad.

    131 GitHub stars~2.3k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Designing Tests

    CloudAI-X/opencode-workflow

    Guides test strategy, TDD/BDD approaches, test coverage planning, and testing best practices.

    275 GitHub stars~2.9k tokensUpdated 9 mo ago
    Testing & QAAuto-check passed
  • Next QA Idea

    breaking-brake/cc-wf-studio

    Runs one unattended ideation pass of a QA loop: finds the highest-value untested behavior and files a single locked qa issue describing the test to write, with no code.

    5.4k GitHub stars~1.7k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Go Testing

    Gentleman-Programming/gentle-ai

    Trigger: Go tests, go test coverage, Bubbletea teatest, golden files.

    7.6k GitHub stars~550 tokensUpdated today
    Testing & QAAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    Auto-check: notes
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes

Categories

Questions about mewt and muton Mutation Testing

What does mewt and muton Mutation Testing do?

Routes mutation testing work with mewt or muton to the right workflow: configuring a campaign, hunting bugs in untested code, or reporting on surviving mutants. The skill acts as a router. It picks one of three workflows, setting up or speeding up a campaign, hunting for bugs after a campaign has finished, or turning results into a formal report, and loads only the reference files that workflow needs.

When should I use mewt and muton Mutation Testing?

mewt and muton Mutation Testing fits situations like: setting up and scoping a mutation testing campaign with mewt or muton; making a slow campaign run faster; analyzing surviving mutants and spotting equivalent ones; using escaped mutants to find bugs in untested code.

How do I install mewt and muton Mutation Testing in Claude Code?

Run `npx skills add trailofbits/skills --skill mutation-testing -a claude-code`. Or copy the skill folder (plugins/mutation-testing/skills/mutation-testing in trailofbits/skills) into .claude/skills/mutation-testing in your project. Claude Code loads it when a task matches its description.

How do I install mewt and muton Mutation Testing in Codex?

Run `npx skills add trailofbits/skills --skill mutation-testing -a codex`. Or copy the skill folder (plugins/mutation-testing/skills/mutation-testing in trailofbits/skills) into .agents/skills/mutation-testing in your project. Codex loads it when a task matches its description.

Can I use mewt and muton Mutation Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill mutation-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mutation-testing, .gemini/skills/mutation-testing, .github/skills/mutation-testing and .opencode/skills/mutation-testing in your project.

What does mewt and muton Mutation Testing need to run?

SKILL.md names no scripts, command-line tools or credentials: mewt and muton Mutation Testing is instructions for the agent only. Our summary lists: mewt or muton installed. Its frontmatter pre-approves these tools: Read, Write, Bash, Grep.

Does mewt and muton Mutation Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is mewt and muton Mutation Testing safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does mewt and muton Mutation Testing use?

mewt and muton Mutation Testing is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does mewt and muton Mutation Testing use?

About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.5k tokens, read only when the agent opens those files.

What are the alternatives to mewt and muton Mutation Testing?

Skills that share tags, products or a category with mewt and muton Mutation Testing: Senior QA (nicepkg/auto-company, 192 stars), Golang Testing (antoniopaya22/go-rest-template, 172 stars), Test Roadmap (Ovid/paad, 131 stars) and Designing Tests (CloudAI-X/opencode-workflow, 275 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains mewt and muton Mutation Testing?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.