github.com/santosomar/general-secure-coding-agent-skills
| Skill | Added | Review |
|---|---|---|
test-driven-generation skills/testing/test-driven-generation/SKILL.md Generates code test-first — writes a failing test from a requirement, then generates the minimal code to pass it, then refactors, in strict red-green-refactor cycles. Use when building new features where the spec is clear, when the design is uncertain and you want tests to drive it, or when you need high confidence in coverage from the start. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
test-guided-bug-detector skills/debugging/test-guided-bug-detector/SKILL.md Uses failing test results as signals to guide bug search and narrow down candidate fault locations. Use when one or more tests are failing and the user wants to understand what's broken, when CI reports failures, or when triaging a batch of test failures after a change. | 74 74 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
test-guided-migration-assistant skills/code-analysis/test-guided-migration-assistant/SKILL.md Uses an existing test suite as the behavioral oracle during a migration, tracking which tests pass at each step and localizing regressions to specific migration changes. Use when porting or refactoring code that has tests, when the user wants to migrate incrementally with a safety net, or when a migration broke something and you need to find which step did it. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
test-oracle-generator skills/testing/test-oracle-generator/SKILL.md Generates test oracles — the "expected output" part of a test — by choosing among reference implementations, invariants, inverse functions, or differential comparison when the correct answer isn't obvious. Use when the hard part of testing is knowing what the right answer is, not generating inputs. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
test-suite-prioritizer skills/testing/test-suite-prioritizer/SKILL.md Orders tests so failures surface earliest — runs tests covering changed code first, historically flaky/failing tests early, and slow low-value tests last. Use when the suite is too slow to run in full on every change, when CI feedback takes too long, or when deciding what to run in a smoke-test tier. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
tlaplus-guided-code-repair skills/verification/tlaplus-guided-code-repair/SKILL.md TLA+-specific instance of model-guided repair — reads a TLC error trace, identifies the enabling condition that should have been false, strengthens the corresponding action, and maps the fix to source code. Use when TLC reports an invariant violation or deadlock and you have the code-to-TLA+ mapping from extraction. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
tlaplus-model-reduction skills/verification/tlaplus-model-reduction/SKILL.md Reduces a TLA+ model so TLC can actually check it — shrinks constants, adds state constraints, abstracts data, or applies symmetry — when the state space is too large to enumerate. Use when TLC runs out of memory, when checking takes hours, or when a spec works at N=2 and you need confidence at larger scale. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
tlaplus-spec-generator skills/verification/tlaplus-spec-generator/SKILL.md Translates natural-language or pseudocode descriptions of concurrent and distributed systems into TLA+ specifications ready for the TLC model checker. Identifies state variables, actions, type invariants, safety properties, and liveness properties from the description. Use when formalizing a protocol, when the user describes a distributed algorithm to verify, when designing a consensus or locking scheme, or when starting formal verification of a concurrent system. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
traceability-matrix-generator skills/requirements/traceability-matrix-generator/SKILL.md Builds a bidirectional traceability matrix linking requirements to design elements, code, and tests — so every requirement traces forward to its implementation and every test traces back to its justification. Use for compliance audits, when answering why a piece of code exists, or when checking that nothing was built without a reason. | 80 80 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
unit-test-generator skills/testing/unit-test-generator/SKILL.md Generates unit tests for a function or class by analyzing branches, boundaries, and error paths — then emits test code in the project's existing framework and style. Covers happy path, edge cases, and failure modes with mocks for external dependencies. Use when writing tests for new code, when backfilling coverage on untested functions, when the user asks to generate tests, or when a coverage report shows specific gaps. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
verified-pseudocode-extractor skills/verification/verified-pseudocode-extractor/SKILL.md Extracts human-readable pseudocode from a verified formal artifact (Dafny, Lean, TLA+) while preserving the verified properties as annotations, so the proof-carrying logic can be reimplemented in a production language. Use when porting verified code to an unverified target, when documenting what a formal spec actually does, or when handing a verified algorithm to an implementer. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 47d56bb | |
vulnerability-pattern-matcher skills/security/vulnerability-pattern-matcher/SKILL.md Matches code against Project CodeGuard's catalog of known-dangerous patterns — banned C functions, weak crypto primitives, hardcoded credentials, deprecated APIs. Use when grepping for low-hanging security fruit, when enforcing a ban-list in CI, or when the user asks to check for known-bad patterns. | 71 71 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 47d56bb |