本文へ移動
cccskills
無料GitHub で公開

boundary-negative-testing

Use when building cases for any input, form, endpoint or state change - boundary values, invalid and hostile data, authz and concurrency cases with a worked example

インストール方法を見る

含まれるファイル(1)

  • SKILL.md1.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Boundary and Negative Testing

Data catalogue

  • Strings: empty, whitespace-only, 1 char, max, max+1, 10x max, leading/trailing spaces, emoji/ZWJ, RTL text, combining marks, <b>x</b> and <img src=x onerror=alert(1)> (must render as inert text, never execute), ' OR 1=1 -- (as literal data), ../../etc/passwd in a filename-ish field.
  • Numbers: −1, 0, 1, max, max+1, a decimal where an integer is expected, 1e309, NaN.
  • Dates: leap day, a DST transition, a timezone boundary, past/future limits the domain implies.
  • Files: 0 bytes, just over the size limit, wrong MIME type with a correct-looking extension.
  • Collections: 0 items, 1 item, exactly the page size, page size + 1.
  • Concurrency: double submit, two sessions editing the same record.
  • Dependency down: the stubbed dependency returns 5xx/timeout (test-data-and-stubs), or route "**/api/<dep>/**" --status=500 for a UI-only case.

Flow-level cases

Unauthorized access, missing resources (404 paths), concurrent/duplicate submission, partial failure of a dependency.

Recording

Record every boundary you probed as its own test case on the task, passing ones included — absence of evidence is not evidence of absence, and a boundary nobody can see you tried is one the next reader has to try again. A boundary that cannot exist here (the field is an enum, the endpoint is internal-only) is a case too: record it invalid with that reason.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Use when writing acceptance criteria for a task - express each as an observable Given/When/Then that QA can execute, including negative cases

日本語の概要は準備中です。原文の説明を表示しています。

makifbaysal/tasktrooper1122026年10月10日 更新

Use when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level authorization, mass assignment and tenant scoping

日本語の概要は準備中です。原文の説明を表示しています。

makifbaysal/tasktrooper1122026年10月10日 更新

Use on every UI change - semantic HTML, labels for controls, keyboard-navigable dialogs/menus, visible focus, and never color as the only signal

日本語の概要は準備中です。原文の説明を表示しています。

makifbaysal/tasktrooper1122026年10月10日 更新

Use when a task changes any screen, form, dialog, menu or control - Lighthouse/axe scan of the changed screens, a keyboard walk, and the thresholds that fail a task

日本語の概要は準備中です。原文の説明を表示しています。

makifbaysal/tasktrooper1122026年10月10日 更新

How to work a task returned with review, QA or UAT findings. Use when a task is in need_revision or PR review comments are in your context.

日本語の概要は準備中です。原文の説明を表示しています。

makifbaysal/tasktrooper1122026年10月10日 更新

Use when deciding whether a request needs an analiz task before implementation - the conditions that require the architect's analysis versus going straight to implementation

日本語の概要は準備中です。原文の説明を表示しています。

makifbaysal/tasktrooper1122026年10月10日 更新

makifbaysal のスキルをすべて見る

このスキルの問題を報告する