Install
$ agentstack add skill-jartan-llc-grimoire-testing-patterns ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Testing Philosophy
Integration Tests Verify Behavior, Not Internals
Integration tests must verify observable behavior through endpoints, not implementation details.
Good integration tests:
- Drive endpoints with an HTTP client
- Assert status codes and response bodies
- Verify side effects (emails sent, database rows created, audit entries logged)
- Test cross-cutting concerns (middleware, auth, rate limiting)
Bad integration tests:
- Calling internal service functions for behavior already observable via HTTP
- Using DB queries as the primary assertion surface (DB is for post-assertion verification)
- Testing internal query functions or utility functions -- those belong in unit tests
- Duplicating coverage already exercised by another test
Prefer Fixture Composition
If a test starts with boilerplate setup (register a user, log in, configure a setting), that belongs in a fixture. Test bodies should stay focused on what they're actually testing.
Build fixture stacks: user -> logged_in_user -> admin_user. Each level adds one concern. Tests request the level they need.
Canary Markers for Library Internals
When code depends on a library's private or poorly-documented internals, add a canary test that asserts the internal's shape directly -- don't rewrite production code to avoid the dependency when doing so would cost real accuracy or capability.
The canary turns an upstream rename or shape change into a loud test failure instead of a silent runtime bug.
Canary practices:
- Assert the specific attribute/method and the shape of its return value -- not just "no exception raised"
- Name the test so the failure message makes the breakage obvious (e.g.,
test_library_rate_limit_contract), since it'll likely be read by whoever just bumped a dep - Place it close to the module that uses the internal
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Jartan-LLC
- Source: Jartan-LLC/grimoire
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.