gjalla-code-review
78Review Code Changes Before Merge
Code changes can hide correctness, security, and maintainability issues before merge. This skill reviews diffs from relevant perspectives and returns prioritized, location-specific fixes.
Audit Test Suites for False Confidence
Weak tests can hide production bugs while inflating coverage metrics. This skill reviews test quality and identifies misleading, redundant, or excessively mocked tests.
Скопируйте этот запрос в своего Агента. Он содержит каноническую страницу Skill и манифест.
Review the Skillstore skill "gjalla-test-audit" from https://skillstore.io/skills/gjalla-gjalla-test-audit.md and its manifest at https://skillstore.io/api/skills/gjalla-gjalla-test-audit/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Ваш Агент по-прежнему должен показать план и запросить все подтверждения, требуемые политикой безопасности.
Используйте эти ссылки, когда AI-агенту, crawler или script нужен чистый контекст вместо полной страницы.
Использование «gjalla-test-audit». Audit the account service tests for tautological database mocks.
Ожидаемый результат:
Tier 2 finding: three tests return hardcoded database rows and assert those same values. Replace them with database-backed behavior tests.
Использование «gjalla-test-audit». Find tests that do not exercise production code.
Ожидаемый результат:
Использование «gjalla-test-audit». Review overlapping unit and integration tests.
Ожидаемый результат:
Tier 3 finding: the mocked unit test duplicates the stronger database-backed scenario. Keep unique edge cases and remove redundant coverage after approval.
All 15 static findings are false positives caused by Markdown inline-code formatting around test identifiers and examples. The source defines a review workflow and requires approval before cleanup actions. No prompt injection, data exfiltration, command execution, or network reconnaissance intent was found.
Делитесь версионным отчетом об оценке, нейтральным значком, встраиваемой карточкой и цитатами. Skillstore публикует доказательства, не решая, безопасен ли этот Skill.
https://skillstore.io/skills/gjalla-gjalla-test-audit/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/gjalla-gjalla-test-audit?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/gjalla-gjalla-test-audit?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/gjalla-gjalla-test-audit/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/gjalla-gjalla-test-audit.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>gjalla. (2026). gjalla-test-audit security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/gjalla-gjalla-test-audit/audits/1@techreport{gjalla-gjalla-gjalla-test-audit-2026,
author = {gjalla},
title = {gjalla-test-audit security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/gjalla-gjalla-test-audit/audits/1},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "gjalla-test-audit security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "gjalla"
date-released: "2026-08-11"
url: "https://skillstore.io/skills/gjalla-gjalla-test-audit/audits/1"
identifiers:
- type: other
value: "skillstore:gjalla-gjalla-test-audit:audit:1"
description: "Skillstore immutable audit report identifier"
Find tests that inflate confidence without protecting current production behavior.
Compare critical source paths with tests and identify missing realistic coverage.
Classify weak tests and create a prioritized remediation report for the team.
Audit the test suite in [directory]. Identify placeholder tests, tests without source imports, and obvious duplicated coverage. Report findings without changing files.
Review tests for [component]. Compare each test with its source code. Flag tautological mocks and explain which production defects each test cannot detect.
Audit tests covering [critical path]. Rank gaps by production impact, identify encoded bugs, and recommend realistic integration or round-trip tests.
Audit [test scope] across all test layers. Classify findings into deletion and replacement tiers. Estimate coverage impact and propose approved cleanup waves.
Автор
gjallaЛицензия
MIT
Ревизия Skillstore
r1
Примечание о версии
Автор не указал версию.
Репозиторий
https://github.com/gjalla/engineering/tree/774041e7ab8b8fde48418dd4cd41e417fb4d71d3/skills/gjalla-test-auditСсылка
c40485c25b35e0203cf615647a1fd81ad7a69ea8
Актуальность поддержки
12.08.2026
Использование
0 загрузок · 0 просмотров
Структура файлов
📄 SKILL.md
Review Code Changes Before Merge
Code changes can hide correctness, security, and maintainability issues before merge. This skill reviews diffs from relevant perspectives and returns prioritized, location-specific fixes.
Review Software Specifications Before Implementation
Ambiguous specifications create implementation gaps, security risks, and costly rework. This skill reviews plans through architecture, security, quality, user, and governance perspectives before engineers begin implementation.
Create Production-Ready Software Specifications
Complex features fail when requirements, architecture effects, and verification criteria remain unclear. This skill guides agents through research and produces an implementation-ready Gjalla specification.
Break Features Into Implementation Waves
Large feature specifications can be difficult to sequence and track. This skill creates dependency-ordered waves of small tasks with files and acceptance checks.
Анализ качества тестов в разных фреймворках
от C0ntr0lledCha0s
Слабые тесты скрывают дефекты, замедляют рефакторинг и делают показатели покрытия вводящими в заблуждение. Этот навык анализирует тестовые наборы и дает приоритетные рекомендации по надежности, сопровождаемости, покрытию и мутационному тестированию.
Планируйте надежные тесты во всей кодовой базе
от 0xDarkMatter
Этот skill помогает командам выбирать стратегии тестирования, моки, фикстуры данных, пороги покрытия и CI-паттерны, не смешивая уровни тестирования. Он дает Claude, Codex и Claude Code структурированные рекомендации для unit, integration, end-to-end, TDD и pipeline-тестирования.
Создание Rust-моков для тестов с помощью паттернов трейтов
от EmilLindfors
Тесты Rust часто становятся медленными или хрупкими, когда зависят от баз данных, HTTP-сервисов или реальной инфраструктуры. Этот навык помогает Claude, Codex и Claude Code проектировать моки на основе трейтов, управляемые сбои и вспомогательные функции для фикстур.
Постройте практическую стратегию тестирования
от Atman36
Команды часто добавляют тесты без четкого понимания области применения, инструментов или целей покрытия. Этот skill предоставляет практический план для тестирования с Vitest, Playwright и CI.
Пишите сфокусированные поведенческие тесты
от EIS-ITS
Команды часто добавляют хрупкие тесты, которые отражают детали реализации вместо поведения пользователя. Этот навык помогает Claude, Codex и Claude Code писать сфокусированные тесты для критически важных рабочих процессов.
Создание тестов Python с использованием паттернов Pytest
от sickn33
Командам Python нужны воспроизводимые паттерны для надежных тестов. Этот навык помогает с фикстурами pytest, моками, асинхронными тестами, покрытием и настройкой CI.