Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/shopwarelabs/ai-coding-tools/phpunit-unit-test-reviewingnpx skills add shopwareLabs/ai-coding-tools --skill phpunit-unit-test-reviewinggit clone --depth 1 https://github.com/shopwareLabs/ai-coding-toolsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/shopwarelabs/ai-coding-tools/phpunit-unit-test-reviewing)<a href="https://agentmods.dev/skills/shopwarelabs/ai-coding-tools/phpunit-unit-test-reviewing"><img src="https://agentmods.dev/badge/skills/shopwarelabs/ai-coding-tools/phpunit-unit-test-reviewing.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00031 | $0.04335 |
| Opus 5 | $0.00015 | $0.02167 |
| Sonnet 5 | $0.00006 | $0.00867 |
| Haiku 4.5 | $0.00003 | $0.00434 |
Grade A, and why
phpunit-unit-test-reviewing scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 248 lines — stays where its author put it; the contents beside it link to each section on GitHub.
PHPUnit Unit Test Review
Review a Shopware PHPUnit unit test for compliance with testing guidelines and best practices.
Input
{test_path}(required unless{digest}is set, which supplies the class shape instead) — Path to the test file{methods}(optional) — List of test method names to scope the review to. When omitted, the full class is reviewed.{review_unit}(optional) —method,class-structure,class-bodies, or a list of these. When set, only rules whose minimal evaluation unit matches load. When omitted, all rules load. Orthogonal to{methods}: both may be set (e.g.methods=[...]+review_unit=method).{digest}(optional) — a pre-extracted, body-free structural digest of the test class. When set, review this text and skip reading the test file. Forcesclass-structurerules only. See Digest Mode.{rules}(optional) — the pre-rendered rule catalog as text, provided in your prompt. When set, enter Inline-Rules Mode: select rules from this text instead of callingget_rules. When omitted, rules load viaget_rules. See Inline-Rules Mode.{baseline}(optional) —pass,fail, orunavailable: this file's test state before the review, supplied by the caller. Defaults tounavailablewhen omitted. Record and report it; this skill never executes tests to obtain it.
Workflow
digraph unit_review {
"Review request" [shape=doublecircle];
"digest set?" [shape=diamond];
"Digest Mode: judge the digest text alone; force class-structure rules; read nothing from disk" [shape=box];
"Phase 1: locate the file, verify tests/unit/, check CoversClass, detect category A-E, verify class structure and base class, count test methods, read the source class" [shape=box];
"a unit test class in tests/unit/?" [shape=diamond];
"STOP: FAILED - not a unit test, or not a test class" [shape=octagon, style=filled, fillcolor=red];
"unit and integration patterns mixed in one class?" [shape=diamond];
"STOP: abort - Mixed test types detected, review unit test portions only" [shape=octagon, style=filled, fillcolor=red];
"named methods resolve?" [shape=diamond];
"STOP: FAILED - No matching methods found" [shape=octagon, style=filled, fillcolor=red];
"Phase 2: build the rule filters - test_type=unit, test_category, scoped_review, review_unit" [shape=box];
"rules set?" [shape=diamond];
"Inline-Rules Mode: select from the inline catalog by the filter predicate; open no rule file" [shape=box];
"Call get_rules per group with the filters this mode sets" [shape=box];
"get_rules available?" [shape=diamond];
"STOP: FAILED - test-rules MCP server not available; never fall back to hardcoded checks" [shape=octagon, style=filled, fillcolor=red];
"Phases 3-7: per group, apply each rule's detection algorithm against the scoped code, record violations, write suggested fixes" [shape=box];
"Phase 8: apply the baseline - fail forces ISSUES_FOUND" [shape=box];
"Emit the report per references/output-format.md" [shape=doublecircle];
"Review request" -> "digest set?";
"digest set?" -> "Digest Mode: judge the digest text alone; force class-structure rules; read nothing from disk" [label="yes"];
"digest set?" -> "Phase 1: locate the file, verify tests/unit/, check CoversClass, detect category A-E, verify class structure and base class, count test methods, read the source class" [label="no"];
"Digest Mode: judge the digest text alone; force class-structure rules; read nothing from disk" -> "rules set?";
"Phase 1: locate the file, verify tests/unit/, check CoversClass, detect category A-E, verify class structure and base class, count test methods, read the source class" -> "a unit test class in tests/unit/?";
"a unit test class in tests/unit/?" -> "STOP: FAILED - not a unit test, or not a test class" [label="no"];
"a unit test class in tests/unit/?" -> "unit and integration patterns mixed in one class?" [label="yes"];
"unit and integration patterns mixed in one class?" -> "STOP: abort - Mixed test types detected, review unit test portions only" [label="yes"];
"unit and integration patterns mixed in one class?" -> "named methods resolve?" [label="no"];
"named methods resolve?" -> "STOP: FAILED - No matching methods found" [label="none match"];
"named methods resolve?" -> "Phase 2: build the rule filters - test_type=unit, test_category, scoped_review, review_unit" [label="some or all match, or methods unset - each unmatched name is a warning"];
"Phase 2: build the rule filters - test_type=unit, test_category, scoped_review, review_unit" -> "rules set?";
"rules set?" -> "Inline-Rules Mode: select from the inline catalog by the filter predicate; open no rule file" [label="yes"];
"rules set?" -> "Call get_rules per group with the filters this mode sets" [label="no"];
"Inline-Rules Mode: select from the inline catalog by the filter predicate; open no rule file" -> "Phases 3-7: per group, apply each rule's detection algorithm against the scoped code, record violations, write suggested fixes";
"Call get_rules per group with the filters this mode sets" -> "get_rules available?";
"get_rules available?" -> "STOP: FAILED - test-rules MCP server not available; never fall back to hardcoded checks" [label="no"];
"get_rules available?" -> "Phases 3-7: per group, apply each rule's detection algorithm against the scoped code, record violations, write suggested fixes";
"Phases 3-7: per group, apply each rule's detection algorithm against the scoped code, record violations, write suggested fixes" -> "Phase 8: apply the baseline - fail forces ISSUES_FOUND";
"Phase 8: apply the baseline - fail forces ISSUES_FOUND" -> "Emit the report per references/output-format.md";
}
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago Changed · +64 lines b76a03b4e58a
- 4d ago First seen · 184 lines · 31 tokens per session scan A fd4a91f2b970
phpunit-unit-test-reviewing is a skill published in the GitHub repository shopwareLabs/ai-coding-tools (43 stars, last pushed today), licensed MIT. It adds 31 tokens to every session and 4,335 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
batch-simplify
Batch-run simplification across changed files, or across an entire repository, grouped by ecosystem and dependency order. Use when: 'batch simplify', 'simplify recent changes', 'simplify everything', 'forgot to run simplify', 'catch up on simplify', 'simplify my branch changes', 'simplify the whole repo', 'simplify…
audit-permission-state
Report the Claude Code permission state actually in effect. Discovers every settings scope (managed policy, user-global, project, local, and the pre-v2.1.211 start-directory copy), merges them into the effective allow/ask/deny set with each rule's source and precedence mechanic named, and classifies which allow rules…
audit-install-state
Read-only audit of a Claude Code INSTALLATION directory, the machine-scope /.claude tree plus /.claude.json. Inventorying every file, separating what the product's own retention sweep already manages from what nothing manages, resolving what each number in a filename actually means before any process-liveness check…
audit-native-overlap
Map native Claude Code surfaces (built-in CLI commands, bundled skills, plugin-backed built-ins, session-provided skills) against the current repo's plugin skills and agents, so a custom component never silently duplicates what Claude Code itself now ships. Bare invocation is a READ-ONLY report: overlap candidates…
audit-performance
Read-only slowness-diagnostic capture for a Claude Code installation. Run it AT THE MOMENT the machine or a session feels slow, before restarting or deleting anything. One timed engine pass captures the four suspects: CLI version (regression), retention-sweep health including the silent unparsable-settings pause…
audit-prompting-postures
Audit locally-owned instruction components (skill bodies, agent definitions, hook instruction text, output styles, CLAUDE.md and rules) for MISSING posture guidance the official prompting guide says their purpose needs: delegation criteria and caps, minimal-scope and anti-test-gaming guardrails…