Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/TestAny-io/testany-agent-skillsnpx agentmods add commands/testany-io/testany-agent-skills/test-strategy-reviewerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/testany-io/testany-agent-skills/test-strategy-reviewer)<a href="https://agentmods.dev/commands/testany-io/testany-agent-skills/test-strategy-reviewer"><img src="https://agentmods.dev/badge/commands/testany-io/testany-agent-skills/test-strategy-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/testany-io/testany-agent-skills/test-strategy-reviewer"><img src="https://agentmods.dev/badge/commands/testany-io/testany-agent-skills/test-strategy-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00027 | $0.00461 |
| Opus 5 | $0.00014 | $0.00230 |
| Sonnet 5 | $0.00005 | $0.00092 |
| Haiku 4.5 | $0.00003 | $0.00046 |
Grade A, and why
test-strategy-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Test Strategy Reviewer
启动测试策略评审流程。作为进入 LLD 和详细测试规格前的门禁,检查测试策略是否完整、可执行、无关键遗漏。
使用方式
提供测试策略和上游基线路径:
$ARGUMENTS
在研发流程中的位置
Test Strategy → [Test Strategy Reviewer] → Test Strategy(准出)→ LLD → Test Spec
审查框架
采用四道门审查:
- Gate 1 - 基线与范围:版本、范围、must-not-regress、豁免
- Gate 2 - 风险覆盖与测试分层:高风险能力与分层合理性
- Gate 3 - 环境/数据/依赖:执行可行性
- Gate 4 - 门禁与自动化:入口/出口、回归与自动化策略
准出门槛
- P0 = 0
- P1 = 0
- P2 ≤ 2
必需产出
- 审查报告
- 准出证书(通过时)
强制脚本校验
在人工评审前必须先执行:
python3 plugins/testany-eng/scripts/trace_lint.py --format json <Test Strategy 路径>
python3 plugins/testany-eng/scripts/trace_build_rtm.py --format json <PRD 路径> <Test Strategy 路径>
trace-lint blocking issue 和 RTM001 / RTM002 / RTM003 / RTM004 都按 P0 处理。
请提供 Test Strategy 路径开始评审。建议同时提供 PRD、API Contract、HLD 与 Guardrails。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 54 lines · 27 tokens per session scan A 82a53db98cf0
test-strategy-reviewer is a command published in the GitHub repository TestAny-io/testany-agent-skills (82 stars, last pushed 3d ago), licensed MIT. It adds 27 tokens to every session and 461 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
prototype
You are building a proof-of-concept for the current Grainulator sprint. Read CLAUDE.md for sprint context and claims.json for existing research claims.
verify
Run repository verification using the verification-loop skill.
qa-changes
This skill should be used when the user asks to "QA a pull request", "test PR changes", "verify a PR works", "functionally test changes", or when an automated workflow triggers QA validation of code changes. Provides a structured methodology for setting up the environment, exercising changed behavior, and reporting…
test-coverage
Analyze test coverage and identify the highest-value gaps to fill.
tdd
A command that follows test-driven development (TDD), a method where you write tests before the code they check. It moves through writing a failing test, adding the smallest implementation, and then improving the code.
check-dev
Type-check a Z specification with fuzz.