Skip to content
Back to skills

Mutation Check

ASecurity

Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized. Use when logic-dense modules change, before refactors, or when asked to verify mutation coverage.

  • 760 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 20, 2026
developmentgoshelltestingbackend

Security analysis

A100/100

Scanned September 20, 2026

npx -y skills add trailofbits/coop --skill mutation-check --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Mutation Check?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Mutation Check
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/trailofbits-mutation-check-coop/badge)](https://www.skillsdirectory.com/skills/trailofbits-mutation-check-coop)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: mutation-check
description: Run cargo-mutants for changed coop logic and keep .cargo/mutants.toml synchronized. Use when logic-dense modules change, before refactors, or when asked to verify mutation coverage.
---

# Mutation Check

Read [`docs/testing.md`](../../../docs/testing.md) first.

1. Inspect the diff before running. New functions in logic modules that shell
   out, drive `&PlatformBackend`, read a TTY, or write stdout must be excluded in
   `.cargo/mutants.toml` in the same PR. Extract and test their pure decision
   logic. Pure helpers remain in scope.
2. Sanity-check changed exclusions with `cargo mutants --list -f <file>`.
3. Run a full-file sweep for each touched scoped module and library tests only:
   `cargo mutants -f src/<file>.rs -- --lib`. Redirect output to a file; do not
   pipe a long run through `head` or `grep`.
4. Triage `mutants.out/missed.txt`: add a discriminating test for real gaps,
   mark genuinely equivalent mutants with a narrow documented skip, and delete
   dead code. Confirm each new test by re-running the mutant or deliberately
   breaking the protected behavior.
5. Report files swept, missed count before/after, every survivor's disposition,
   and whether `.cargo/mutants.toml` changed.

Do not spend a full mutation run on whole-module exclusions (`backend.rs`,
`lima.rs`, `setup.rs`, `update.rs`, `ssh.rs`, `vm.rs`, `network.rs`,
`port_forward.rs`, `cmd.rs`, `prompt.rs`, `main.rs`). Instead, identify the
unit/integration blind spot explicitly and test extracted pure logic directly.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…