Install
$ agentstack add skill-jovd83-restassured-skill-core ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Rest Assured Core
1. Preflight
- Inspect the build file, Java version, test engine, and module boundaries.
- Inspect API documentation, existing contracts, auth flow, and environment variables.
- Read [preflight.md](references/preflight.md) before major changes.
2. Choose the Test Shape
- Use [service-test-types.md](references/service-test-types.md) to classify the test as smoke, regression, contract, integration, negative, or workflow.
- Read [project-structure.md](references/project-structure.md) before creating new packages.
- Use JUnit 5 patterns from [junit5-patterns.md](references/junit5-patterns.md).
- Use build guidance from [maven-and-gradle.md](references/maven-and-gradle.md).
- Decide whether the suite is
runtime-aligned,contract-enforcement, ormixedbefore writing assertions.
3. Implement the Backbone
- Build shared request and response specs from [request-response-specs.md](references/request-response-specs.md).
- Centralize auth logic with [authentication.md](references/authentication.md).
- Add semantic assertions using [validation-and-assertions.md](references/validation-and-assertions.md).
- Add schema or contract checks only when they increase signal; use [schema-and-contract-validation.md](references/schema-and-contract-validation.md).
- Build deterministic test data with [test-data-management.md](references/test-data-management.md).
- In
runtime-alignedmode, assert the live behavior in executable tests and route discrepancies to../documentation/contract-mismatches/SKILL.md. - In
contract-enforcementmode, keep assertions aligned to the specification and tag the tests so drift is visible as an explicit contract failure. - In
mixedmode, keep runtime-aligned regression tests separate from contract-enforcement checks by tag, package, or class naming.
4. Add Service-Test Details
- Read [testcontainers-and-wiremock.md](references/testcontainers-and-wiremock.md) before introducing containers or stubs.
- Read [observability-and-redaction.md](references/observability-and-redaction.md) before enabling request or response logging.
- Read [security-negative-testing.md](references/security-negative-testing.md) for authz, authn, and abuse cases.
- Read [graphql-and-file-upload.md](references/graphql-and-file-upload.md) for GraphQL or multipart endpoints.
- Read [xml-and-soap-payloads.md](references/xml-and-soap-payloads.md) for XML or SOAP payload handling.
- Read the framework recipe that matches the repo: [framework-spring-boot.md](references/framework-spring-boot.md), [framework-quarkus.md](references/framework-quarkus.md), or [framework-micronaut.md](references/framework-micronaut.md).
5. Run and Debug
- Run the narrowest relevant test first.
- Use [debugging.md](references/debugging.md) for triage.
- Use [error-index.md](references/error-index.md) when a common failure pattern appears.
- If a failure reveals contract drift, capture the raw request, raw response metadata, and affected contract path before changing assertions.
- When a contract-enforcement test fails because the runtime drift is already known, preserve the failing evidence and link it to the mismatch artifact instead of muting the test silently.
6. Examples
- Input:
Implement POST /orders negative tests from the approved coverage plan.
Output: Add OrdersApiTest, shared specs, data builders, and explicit 400, 401, 403, 409, and 422 assertions.
- Input:
Refactor these duplicated given/when/then chains.
Output: Extract request and response specs plus auth support before changing test intent.
- Input:
The OpenAPI says JSON but the live 404 returns XML.
Output: Keep the executable test aligned to the live XML response, then document the contract mismatch separately.
- Input:
Keep strict contract checks, but do not break the main regression suite.
Output: Put the contract-enforcement assertions in a separate tagged slice and keep the runtime-aligned suite stable.
7. Troubleshooting
- Problem: The suite uses static
RestAssured.baseURIeverywhere.
Fix: Move configuration into request specs or JUnit lifecycle setup.
- Problem: Tests pass only when run in order.
Fix: Isolate data setup and cleanup per test or per fixture.
- Problem: Logs expose secrets.
Fix: Add redaction filters and restrict full logging to failures.
- Problem: The contract and runtime disagree on status, content type, or payload shape.
Fix: Treat the live runtime as the source for executable assertions, then create a mismatch record instead of forcing the test to match the contract.
- Problem: The user needs both regression stability and strict spec conformance.
Fix: Split the suite into runtime-aligned and contract-enforcement slices instead of forcing one assertion mode to do both jobs.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: jovd83
- Source: jovd83/restassured-skill
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.