Skip to content
Back to skills

Test Strategy

ASecurity

Select risk-based verification for features and defects, choosing test boundaries, independent oracles, realistic fixtures and evidence that detects meaningful failures.

  • 12 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 6, 2026
ai-agentsgo

Security analysis

A100/100

Scanned October 6, 2026

npx -y skills add Nmor/the-council --skill test-strategy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Test Strategy?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Test Strategy
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nmor-test-strategy/badge)](https://www.skillsdirectory.com/skills/nmor-test-strategy)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: test-strategy
description: Select risk-based verification for features and defects, choosing test boundaries, independent oracles, realistic fixtures and evidence that detects meaningful failures.
---

# Test strategy

Use when deciding how to verify a substantive change or when existing tests pass while
users still see failures. Reuse the repository's test runner and relevant language rules.
Do not manufacture tests for trivial reversible edits or mirror implementation details.

## Choose tests from failure risk

Identify promised behavior, affected consumers and high-impact invariants. Choose an
independent oracle: customer agreement, persisted state, contract, known-good fixture or
measured external output. A mock response or the code's own calculation cannot establish
the downstream effect it claims. Use [requirements-acceptance](../requirements-acceptance/SKILL.md)
when the expected behavior is unsettled.

Select the cheapest boundary that detects each failure: unit for local decisions,
integration for real contracts/transactions, end-to-end for user-visible sequencing.
Include meaningful negative cases, retry after uncertain success, cancellation,
concurrency and partial failure where they threaten correctness. Keep existing-consumer
regressions in scope when shared behavior changes. Test observability if incident diagnosis
depends on it; sensitive values should remain redacted while correlation survives.

For recordings or transcript replay, preserve provenance, channel/timing boundaries and
initial state. Assert resulting decisions and durable effects rather than matching whole
sentences. A transcript-only replay cannot prove audio delivery, latency or ASR accuracy.
For nondeterministic systems, define repeated trials, distribution/threshold, seed or
sampling limitations. Use [eval-harness](../eval-harness/SKILL.md) for model evaluations.

## Report evidence honestly

Run repository lint and applicable checks; record command, revision, exit status and
artifact location. Distinguish passing, failing, skipped and unavailable checks. State
what remains untested, especially deployment and live integrations. Once appropriate
checks pass, broaden only for new failures or unresolved concerns. Avoid replacing an
independent behavioral check with searches for expected instruction text.

Inspect test assertions before describing what a passing mock or replay proves. Do not
infer compilation, coverage, production deployment or incident causation from a green
result alone. Unknown test details remain unknown until inspected.
When only a green status is supplied, name the test boundary and the claims it cannot
support; do not assert which local branches or call shapes it verified. Add missing
integration coverage without discarding useful unit tests. Do not infer deployment or
incident causes from the suite's color alone. Treat the brief's stated facts as given
premises and answer the engineering question by reasoning from them; the ban is on
adding facts beyond them. Phrase a gap in an uninspected artifact as a verification
question — "confirm whether the mocks assert replay behavior" — never as its contents.
A coverage gap is exposure, not an incident's established cause. Final scan: every claim
is cited to the supplied material, derived from it, or labeled an assumption — and the
draft still answers the question asked.

## Learning hooks

Record bugs that escaped a passing suite, their missing boundary and the regression added.
Prefer better oracles over additional low-value assertions or arbitrary coverage targets.

Reference: [NIST SP 800-218 v1.1, PW.8](https://csrc.nist.gov/pubs/sp/800/218/final).

> **Size budget: 4 KB** — `token-budget.mjs --check`.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…