Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add mblode/agent-skills --skill test-auditgit clone --depth 1 https://github.com/mblode/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/mblode/agent-skills/test-audit)<a href="https://agentmods.dev/skills/mblode/agent-skills/test-audit"><img src="https://agentmods.dev/badge/skills/mblode/agent-skills/test-audit/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/mblode/agent-skills/test-audit"><img src="https://agentmods.dev/badge/skills/mblode/agent-skills/test-audit.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00063 | $0.02047 |
| Opus 5.5 | $0.00025 | $0.00819 |
| Sonnet 5.5 | $0.00013 | $0.00409 |
| Haiku 4.5 | $0.00006 | $0.00205 |
Grade A, and why
test-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 123 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Test Audit
Tests earn their place by catching a credible regression that nothing else catches. Agents write a test for every small change, and most of those re-assert the source, replay a stronger test through a mock, or pin a private call shape. Coverage barely moves when they go; maintenance cost and suite time do.
- IS: sweeping a directory for low-value, misplaced, and skipped tests, and campaign-pruning a whole subsystem or repo to a measured target with coverage held, plus deleting the test-only production seams those tests kept alive.
- IS NOT: gating a test before it lands or reviewing a feature diff (
tidy), making CI faster by splitting or sharding (ci-speedup), or writing tests for untested code.
Pick a mode
| Mode | When | Done means |
|---|---|---|
| Audit | A focused sweep of named files or a directory | A handful of high-confidence candidates with full evidence, deleted in one coherent batch with validation green |
| Campaign | A subsystem's or repo's whole test surface, or any request with a target ("remove 20%") | The target is met or the ledger shows why it cannot be, coverage held within tolerance, and the preservation review passed. Read references/campaign.md first |
Set a target before starting
An open-ended "clean up the tests" stops after a few obvious deletions, because every remaining candidate looks defensible in isolation. Audit and Campaign need a number to work against. When the user gave one, use it. When they did not, propose one and proceed on it rather than waiting:
Remove the least useful 20% of test declarations in
<scope>, keeping line and branch coverage within 2 percentage points of the baseline and every retained test green.
Measure the baseline first (references/coverage.md), then keep deleting in order of lowest value until the target is met or the coverage budget is spent. Stopping short is a valid result only with a ledger showing that the remaining candidates each guard a named contract. The target is a floor on effort, not permission to cut uncertain tests: the retention bar below still wins over the number.
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +7 lines f3548ddd22bb
- 5d ago Changed · -49 tokens per session b86bfae2cd78
- 12d ago Changed · -10 lines · +18 tokens per session f887d32c9ce7
- 15d ago First seen · 126 lines · 94 tokens per session scan A 6076596823ee
test-audit is a skill published in the GitHub repository mblode/agent-skills (144 stars, last pushed yesterday), licensed MIT. It adds 63 tokens to every session and 2,047 once invoked, about $0.0003 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-25.
Other skills, from other repositories
handoff
Finish a vibe session in symphony-alpha and hand it to whoever picks it up next, usually design and then engineering. Through workers, completes internal scope and Storybook checks, writes focused tests at handoff, runs lint, typecheck and tests, reviews the integrated result and fixes confirmed findings. Asks who…
audit-harness
Use when auditing HARNESS.md, pre-commit hooks, pre-push hooks, architecture gates, or CI workflows for tunacode-cli. This skill treats any mismatch, skipped gate, or failing check as a critical failure and requires manual one-by-one execution rather than make targets, batch wrappers, or summary-only audits.
build-status-cache
Skip Phase 7 rebuild when no code changed since Phase 5 build passed. Compares git diff hash against stored hash from last successful build validation. Triggers on: entering Phase 7, checking build status, before final build validation. Returns BUILDCACHEHIT to skip or BUILDCACHEMISS to re-run build-validator.
auto-optimize
Autonomously optimize an existing skill's output quality by running it repeatedly, scoring against binary evals, mutating the prompt, and keeping improvements. Started only by the user, because it edits the skill in place and runs many paid model calls.
guided-manual-qa
Derive and run an interactive, evidence-recorded manual QA session for a code change, ticket, branch, or pull request. Use when a human should validate live behavior checkpoint by checkpoint after repository-aware setup; do not use as a substitute for automated tests or a read-only code review.
run-tests
Run tests matching a pattern. Use when user says "test", "run tests", or asks to verify changes.