Skills tagged testing: 43 agent skills for Claude Code
ab-testing — When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program.
address-sanitizer — Builds and runs code under AddressSanitizer to catch buffer overflows, use-after-free, and other memory errors during fuzzing or tests.
aflpp — Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast.
angular-architect — Generates Angular 17+ standalone components, configures advanced routing with lazy loading and guards, implements NgRx state management, applies RxJS patterns.
app-platform-sandbox — Create and manage isolated container sandboxes for AI agent code execution.
atheris — Sets up and runs Atheris, the coverage-guided Python fuzzer built on libFuzzer.
audit-prep-assistant — Prepares codebases for security review using Trail of Bits' checklist.
aws-resilience-lifecycle — Guides the end-to-end AWS resilience lifecycle integrating Resilience Hub v2, Fault Injection Service, and Application Recovery Controller.
cargo-fuzz — Sets up and runs cargo-fuzz, the standard fuzzing tool for Cargo-based Rust projects. Covers cargo fuzz init, the nightly toolchain requirement, fuzz_target!
constant-time-testing — Measures timing side channels in cryptographic implementations by running them.
coverage-analysis — Measures and interprets what a fuzzing campaign actually reaches, using llvm-cov, lcov, or a fuzzer's own coverage output.
cro — When the user wants to optimize, improve, or increase conversions on any marketing page or form — including homepage, landing pages, pricing pages.
dev-browser — Browser automation with persistent named pages via the dev-browser CLI.
fuzzing-dictionary — Builds and applies fuzzing dictionaries so a fuzzer can produce the keywords, magic bytes, and tokens a target expects.
fuzzing-obstacles — Patches past the barriers that stop a fuzzer making progress — checksum and hash verification, magic-value validation, time-based seeds.
github-review-pr — Reviews or re-reviews one contributor pull request—including an explicitly named closed PR being reconsidered—or a bounded newest-to-oldest sweep of all open.
guidelines-advisor — Smart contract development advisor based on Trail of Bits' best practices.
harness-writing — Designs and improves fuzzing harnesses for C/C++ and Rust.
laravel-specialist — Build and configure Laravel 10+ applications, including creating Eloquent models and relationships, implementing Sanctum authentication.
libfuzzer — Sets up and runs libFuzzer, the coverage-guided fuzzer built into LLVM, on C/C++ code that compiles with Clang.
llm-eval-harness — Test/evaluate any LLM behind an OpenAI- or Anthropic-compatible endpoint: availability (max_tokens-aware).
mutation-testing — Configures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps.
nestjs-expert — Creates and configures NestJS modules, controllers, services, DTOs, guards, and interceptors for enterprise-grade TypeScript backend applications. ts files.
ossfuzz — Enrolls a project in OSS-Fuzz, Google's free continuous fuzzing service for open source, and drives it locally.
pentesting-with-aws-security-agent — Run an AWS Security Agent penetration test against a live web application — registers and verifies the target domain.
php-pro — 3+ features, Laravel, or Symfony frameworks. Invokes strict typing, PHPStan level 9, async patterns with Swoole, and PSR standards.
playwright-expert — Use when writing E2E tests with Playwright, setting up test infrastructure, or debugging flaky browser tests.
post-patch-validation — Validates security patches with reproducible baseline-versus-patched evidence, including original exploits, root-cause variants, behavior preservation.
promptfoo-evaluation — Configures and runs LLM evaluation using Promptfoo framework.
property-based-testing — Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants.
python-pro — 11+ applications requiring type safety, async programming, or robust error handling.
qa-expert — This skill should be used when establishing comprehensive QA testing processes for any software project.
rails-expert — Rails 7+ specialist that optimizes Active Record queries with includes/eager_load, implements Turbo Frames and Turbo Streams for partial page updates.
running-release-tests — Run automated release testing (UI or API) via the AWS DevOps Agent using a pre-configured test profile.
ruzzy — Sets up and runs Ruzzy, Trail of Bits' coverage-guided Ruby fuzzer and the only production-ready one for the language.
seo-unlighthouse — Multi-page Lighthouse audit via the MIT-licensed Unlighthouse CLI.
terraform-engineer — Use when implementing infrastructure as code with Terraform across AWS, Azure, or GCP.
test-master — Generates test files, creates mocking strategies, analyzes code coverage, designs test architectures.
vector-forge — Mutation-driven test vector generation.
wycheproof — Validates cryptographic implementations against Project Wycheproof's test vectors, which encode known attacks and edge cases across AES, RSA, ECDSA, ECDH.
yara-rule-authoring — Guides authoring of high-quality YARA-X detection rules for malware identification. Use when writing, reviewing, or optimizing YARA rules.