Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/icoretech/airbroke/testing-pr-securitygit clone --depth 1 https://github.com/icoretech/airbrokeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00438 |
| Opus 5 | $0.00000 | $0.00219 |
| Sonnet 5 | $0.00000 | $0.00088 |
| Haiku 4.5 | $0.00000 | $0.00044 |
Grade A, and why
testing-pr-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Testing, PRs, and Security
Testing Workflow
- Run tests from the
testservice, not fromweb - Use targeted runs first during iteration, then widen before closing the task
- Typical commands:
docker compose -f docker-compose.yml --profile test run --rm test yarn test --run
docker compose -f docker-compose.yml --profile test run --rm test \
yarn test --run __tests__/lib/projectActions.test.ts
docker compose exec web yarn typecheck
docker compose exec web yarn biome:lint
Vitest Contracts
- Default environment is
jsdom - Files that need server-only behavior should declare
// @vitest-environment node next/navigationis aliased to__tests__/helpers/nextNavigation.tsfor redirect and refresh assertions- Coverage includes
lib/**/*.ts,app/**/*.ts(x),components/**/*.tsx, andproxy.ts - Coverage excludes tests, generated code, and
lib/db.ts - Test sequencing runs with concurrency
1
What to Test
- Add or update tests in
__tests__/alongside the touched area - Prefer contract coverage around collector parsing, auth restrictions, server actions, and cache or redirect behavior
- Do not rely only on mocks when a narrow runtime-facing test is practical
Security-Sensitive Areas
- Treat
BETTER_AUTH_SECRET,AIRBROKE_MCP_API_KEY,repo_provider_api_key, andrepo_provider_api_secretas sensitive - Use redacted fixtures and env values in tests and docs
- When touching auth, MCP, or collector endpoints, cover both accepted and rejected flows
- Keep CORS and origin rules explicit when changing
/api/v3/*,/api/sentry/*, or/api/mcp
PR and Doc Hygiene
- Keep
README.md,.env.dist, deploy manifests, andUPGRADE.mdin sync when changing env vars, runtime commands, auth requirements, or deployment steps - Use release-please compatible commit semantics
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 51 lines · 0 tokens per session scan A b120dff90bf7
testing-pr-security is an agent published in the GitHub repository icoretech/airbroke (222 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 438 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
software-engineer
Implements Accepted specs end to end, fixes bugs, and refactors without changing behaviour. Use proactively for new features once the spec is Accepted, domain/Prisma/Server Action changes, and technical approach decisions. Do not use when the request is a problem without a spec — that is product-manager.
code-reviewer
Reviews a change against this repository's layer, tenancy, security and testing contracts. Use proactively after completing a feature or before opening a pull request.
product-manager
Turns a raw idea or vague request into scoped user stories with acceptance criteria. Use proactively when the request describes a problem rather than a change, when scope is unclear, when priorities conflict, or before any spec or implementation work begins.
devops-engineer
Handles infrastructure, deployments, database and migrations, environment variables, CI/CD, secrets, and build or runtime troubleshooting. Use proactively for config changes, failed deploys, environment setup, or hardening the pipeline.
domain-architect
Designs domain rules, invariants and pure function contracts before implementation. Use proactively for new features with non-trivial rules, ambiguous or conflicting requirements, calculations and state machines, inconsistencies between a spec and the code, or when deciding what belongs in domain versus services.
ui-ux-developer
Designs and builds product interfaces — screens, layouts, forms, sheets, tables, dashboards, empty and error states. Use proactively when creating or refining any user-facing surface, or auditing an existing one.