跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

测试 Skill

「测试」分类共 528 个 Skill,按仓库 star 排序。分类自动生成,仅供参考。

receiving-code-review
jnMetaCode/superpowers-zh8.3k

receiving-code-review

收到代码审查反馈后、实施建议之前使用,尤其当反馈不明确或技术上有疑问时——需要技术严谨性和验证,而非敷衍附和或盲目执行

requesting-code-review
jnMetaCode/superpowers-zh8.3k

requesting-code-review

完成任务、实现重要功能或合并前使用,用于验证工作成果是否符合要求

subagent-driven-development
jnMetaCode/superpowers-zh8.3k

subagent-driven-development

当在当前会话中执行包含独立任务的实现计划时使用

systematic-debugging
jnMetaCode/superpowers-zh8.3k

systematic-debugging

遇到任何 bug、测试失败或异常行为时使用,在提出修复方案之前执行

test-driven-development
jnMetaCode/superpowers-zh8.3k

test-driven-development

在实现任何功能或修复 bug 时使用,在编写实现代码之前

using-git-worktrees
jnMetaCode/superpowers-zh8.3k

using-git-worktrees

当需要开始与当前工作区隔离的功能开发,或在执行实现计划之前使用——通过原生工具或 git worktree 回退机制确保隔离工作区存在

using-superpowers
jnMetaCode/superpowers-zh8.3k

using-superpowers

在开始任何对话时使用——确立如何查找和使用技能,要求在任何响应(包括澄清性问题)之前调用 Skill 工具

verification-before-completion
jnMetaCode/superpowers-zh8.3k

verification-before-completion

在宣称工作完成、已修复或测试通过之前使用,在提交或创建 PR 之前——必须运行验证命令并确认输出后才能声称成功;始终用证据支撑断言

workflow-runner
jnMetaCode/superpowers-zh8.3k

workflow-runner

在 Claude Code / OpenClaw / Cursor 中直接运行 agency-orchestrator YAML 工作流——无需 API key,使用当前会话的 LLM 作为执行引擎。当用户提供 .yaml 工作流文件或要求多角色协作完成任务时触发。

writing-plans
jnMetaCode/superpowers-zh8.3k

writing-plans

当你有规格说明或需求用于多步骤任务时使用,在动手写代码之前

writing-skills
jnMetaCode/superpowers-zh8.3k

writing-skills

当创建新技能、编辑现有技能或在部署前验证技能是否有效时使用

gentle-ai-bench
Gentleman-Programming/gentle-ai7.6k

gentle-ai-bench

Trigger: bench, journey, journeys, driven mode, gentle-ai-bench, journey corpus, j-numbers, bench axis. Author and verify gentle-ai bench journeys; go test ./bench never proves driven execution.

gentle-ai-bench
Gentleman-Programming/gentle-ai7.6k

gentle-ai-bench

Trigger: bench, journey, journeys, driven mode, gentle-ai-bench, journey corpus, j-numbers, bench axis. Author and verify gentle-ai bench journeys; go test ./bench never proves driven execution.

go-testing
Gentleman-Programming/gentle-ai7.6k

go-testing

Trigger: Go tests, go test coverage, Bubbletea teatest, golden files. Apply focused Go testing patterns.

work-unit-commits
Gentleman-Programming/gentle-ai7.6k

work-unit-commits

Plan commits as reviewable work units. Trigger: implementation, commit splitting, chained PRs, or keeping tests and docs with code.

work-unit-commits
Gentleman-Programming/gentle-ai7.6k

work-unit-commits

Plan commits as reviewable work units. Trigger: implementation, commit splitting, chained PRs, or keeping tests and docs with code.

audit-prep-assistant
trailofbits/skills7.4k

audit-prep-assistant

Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments). Use when preparing your own codebase to be audited by someone else, getting a repository review-ready before an external security review, deciding what to fix before auditors start, or asking what assessors need from a project. For understanding unfamiliar code you are about to audit, use audit-context-building instead.

code-maturity-assessor
trailofbits/skills7.4k

code-maturity-assessor

Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls, complexity, decentralization, documentation, MEV risks, low-level code, and testing, then produces a scorecard with evidence-based ratings and a priority-ordered roadmap. Use when assessing or scoring the maturity of a smart contract or blockchain codebase, producing a maturity scorecard or evaluation, or judging how mature, well-tested, or well-documented such a project is against a rubric.

differential-review
trailofbits/skills7.4k

differential-review

Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and generates a markdown report. Use when reviewing a PR, commit, or diff for security vulnerabilities, checking whether a change re-introduces a previously fixed bug, asking what else a change could break, or finding which modified code has no test covering it.

firebase-apk-scanner
trailofbits/skills7.4k

firebase-apk-scanner

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK files for Firebase vulnerabilities, performing mobile app security audits, or testing Firebase endpoint security. For authorized security research only.

guidelines-advisor
trailofbits/skills7.4k

guidelines-advisor

Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Use when asking whether a smart contract project follows development best practices, reviewing on-chain/off-chain split, upgradeability, or delegatecall proxy patterns against guidelines, or seeking recommendations on contract design, inheritance, events, documentation, dependencies, or test strategy.

offensive-api-security
SnailSploit/Claude-Red7.4k

offensive-api-security

Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection. Addresses WebSocket vulnerabilities including origin bypass, message injection, and cross-site WebSocket hijacking. Provides tooling guidance for Burp Suite, Postman, grpcurl, websocat, and mitmproxy. Each technique includes detection signatures and defensive indicators so you understand what artifacts your testing leaves behind. Designed for authorized penetration testing engagements against API-driven architectures.

offensive-jwt
SnailSploit/Claude-Red7.4k

offensive-jwt

JWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), weak HMAC secret brute force, kid parameter injection (SQLi, path traversal), jku/x5u/jwk header injection, JWKS cache poisoning, JWS/JWE confusion, timing attacks, and mobile JWT storage extraction. Use when testing JWT-based authentication, hunting auth bypass via token manipulation, or evaluating JWT implementation security in web or mobile apps.

acquisition-channel-advisor
deanpeters/Product-Manager-Skills7.2k

acquisition-channel-advisor

Evaluate acquisition channels using unit economics, customer quality, and scalability. Use when deciding whether to scale, test, or kill a growth channel.