test

A test-planning and test-writing workflow that examines existing tests, finds risky untested code, adds tests, and checks their quality with mutation testing, which deliberately introduces small code changes to see whether tests catch them.

In plain words
What is it for?
Use it to assess current tests and coverage, rank testing risks, add unit, integration, or end-to-end tests, and validate whether those tests detect faults.
Why use it?
It helps reveal where tests are missing or too weak, especially around important business rules and data changes.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/zevtos/agentpipe/test
Clone the repo
git clone --depth 1 https://github.com/zevtos/agentpipe
Per session 25 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 751 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00025 $0.00751
Opus 5 $0.00013 $0.00376
Sonnet 5 $0.00005 $0.00150
Haiku 4.5 $0.00003 $0.00075

Measured 2d ago against content hash 7f91417ee8fb, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

test scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/test.md · 87 lines

How it starts

The opening of the file, as written. The whole thing — 87 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are orchestrating comprehensive test coverage for the project. This goes beyond "write some unit tests" — it's a full test strategy with risk-based prioritization.

Context

@CLAUDE.md

Test Target

$ARGUMENTS

Pipeline

Step 1: Coverage Analysis

Before writing any tests:

  1. Identify the testing framework in use (check package.json, pyproject.toml, Cargo.toml, etc.)
  2. Run existing tests to establish baseline: what passes, what fails, what's slow
  3. If coverage tooling exists, run it to identify untested code paths
  4. Map critical code paths that MUST be tested (auth, payments, data mutations, business rules)
  5. Identify which test types already exist (unit, integration, e2e)

Present:

  • Current coverage: what's tested, what's not
  • Risk map: critical untested code paths ranked by risk
  • Test strategy: which types of tests to add and why

Step 2: Test Implementation (Tester Agent)

Run the tester agent: "Analyze the codebase and implement comprehensive tests. Target: $ARGUMENTS (if empty, focus on highest-risk uncovered code)

Current test coverage: [paste from Step 1]

Write tests in this priority order:

  1. Critical business logic — domain rules, calculations, state transitions
  2. API endpoints — request validation, response format, error handling, auth
  3. Data layer — queries return correct results, constraints enforced, migrations work
  4. Error paths — what happens when things fail (network, DB, invalid input)
  5. Edge cases — boundary values, empty inputs, concurrent access

For each test file:

  • Follow existing test patterns and conventions
  • Use real dependencies where possible (mock only external HTTP services)
  • Name tests descriptively: test_[scenario]_[expected_result]
  • Include setup/teardown for clean test isolation

Consider advanced strategies where they add value:

  • Property-based testing for serialization/deserialization round-trips
  • Property-based testing for algorithmic invariants
  • Contract tests if there are service-to-service APIs
  • Fuzzing for parsers or security-critical input processing"

Read the full file on GitHub · 87 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 87 lines · 25 tokens per session scan A 7f91417ee8fb

Subscribe to this mod's changes

test is a command published in the GitHub repository zevtos/agentpipe (11 stars, last pushed 2mo ago), licensed MIT. It adds 25 tokens to every session and 751 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.