Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add s977043/river-review --skill flaky-testgit clone --depth 1 https://github.com/s977043/river-reviewWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/s977043/river-review/flaky-test)<a href="https://agentmods.dev/skills/s977043/river-review/flaky-test"><img src="https://agentmods.dev/badge/skills/s977043/river-review/flaky-test.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00018 | $0.01056 |
| Opus 5 | $0.00009 | $0.00528 |
| Sonnet 5 | $0.00004 | $0.00211 |
| Haiku 4.5 | $0.00002 | $0.00106 |
Grade A, and why
Flaky Test Risk Check scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Pattern declaration
Primary pattern: Reviewer Secondary patterns: Inversion Why: Flakyテストリスク検出はチェックリスト型評価が主だが、テストファイルが差分に含まれない場合は実行を止める必要がある。
Rule / ルール
- テストを決定的にし、実行順や環境依存を避ける。
- タイミング依存(sleep/timeout)、乱数、時刻依存のまま放置しない。
- ネットワークや外部サービス呼び出しはモック/スタブに置き換える。
Heuristics / 判定の手がかり
setTimeout/sleep/waitForで待ち時間を固定している。Math.random()/Date.now()/new Date()をシード・固定値なしで使っている。- ネットワーク/DB/ファイル I/O への直接依存がある(モックが無い)。
- 並列実行で共有状態を操作している、またはテスト順序に依存している。
- 未
awaitの Promise が残っている、cleanup がafterEachで行われていない。
Good / Bad Examples
- Good:
vi.useFakeTimers(); jest.runAllTimers();でタイマーを制御。 - Good:
Math.random = () => 0.42;などで乱数を固定。 - Bad:
await sleep(1000);に依存するテスト。 - Bad: 実際の外部 API を呼ぶ統合テストをユニットテストに混在させる。
Actions / 改善案
- タイマー/日時/乱数をモックし、シードを固定する。
- ネットワーク・DB・外部サービスをモック/スタブ化し、リトライやバックオフをテストしない。
- 共有状態を隔離し、
beforeEach/afterEachでクリーンアップする。 - 並列実行に耐えるようテストデータを分離し、副作用を最小化する。
Non-goals / 扱わないこと
- E2E/負荷試験の設計や実行環境のチューニング。
- テストフレームワークの全面移行。
- 監視/アラートの設計。
Pre-execution Gate / 実行前ゲート
このスキルは以下の条件がすべて満たされない限りNO_REVIEWを返す。
- 差分にテストファイル(
*.test.*,*.spec.*,tests/**/*)の変更が含まれている - 差分にテストの実行内容に影響する変更がある(コメントや説明文のみの変更ではない)
- inputContextにdiffが含まれている
ゲート不成立時の出力: NO_REVIEW: flaky-test — Flakyテストリスク検出の対象となるテスト変更が検出されない
False-positive guards / 抑制条件
- テスト対象が純粋関数で、時間・乱数・外部I/Oを一切使っていない。
- すでにフェイクタイマー/固定シードが導入済みで、差分で逸脱がない。
評価指標(Evaluation)
- 合格基準: 指摘が差分に紐づき、根拠と次アクションが説明されている。
- 不合格基準: 差分と無関係な指摘、根拠のない断定、抑制条件の無視。
人間に返す条件(Human Handoff)
- 仕様や意図が不明確で解釈が分かれる場合は質問として返す。
- 影響範囲が広い設計判断やトレードオフは人間レビューへ返す。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 87 lines · 18 tokens per session scan A 819a73bda850
Flaky Test Risk Check is a skill published in the GitHub repository s977043/river-review (3 stars, last pushed today), licensed MIT. It adds 18 tokens to every session and 1,056 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
brooks-sweep
Full-sweep mode: runs a unified analysis across all quality dimensions — code decay, architecture, tech debt, and test quality — then applies fixes directly to the codebase. Safe changes are auto-applied; risky changes are confirmed before execution. Drawing on twelve classic engineering books. Triggers when: user…
brooks-test
Test quality review drawing on twelve classic engineering books — with primary focus on xUnit Test Patterns, The Art of Unit Testing, How Google Tests Software, and Working Effectively with Legacy Code — that diagnoses structural problems in an existing test suite: brittleness, mock abuse, coverage illusions, slow…
pre-pr-audit
Pre-PR confidence audit with 5-dimension scoring. Use when: final check before commit/push/PR, evaluating PR readiness, assessing test quality + risk + coverage holistically. Triggers: pre-pr, readiness check, confidence audit, final verification, ready to PR, how confident. Not for: code review (use…
spike-consumer-adversarial
OI-3 spike harness — heavy consumer, ADVERSARIAL arm. Worst-case early-exit test: the mid-workflow Skill call has no continuation guardrail and the guidance skill ends with a final-sounding anchor. Use only when explicitly invoked by the spike harness with a TRIALID and data path.
testing-strategy
Design test strategies and test plans with coverage targets. Complements /draft:coverage which measures what this skill plans. Auto-loaded by /draft:implement before TDD.
code-standards
Apply a disciplined engineering workflow to any code change. Use whenever implementing a feature, fixing a bug, or refactoring — before writing code, not after. Walks orient → baseline → smallest change → test → verify → self-review, and enforces language-agnostic hard gates (don't mass-reformat, keep the linter and…