target-tests — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited target-tests (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Identify the highest-value targets for additional test coverage by combining risk, complexity, and behavioral signals.
Omen CLI must be installed and available in PATH.
Run the defect prediction analysis:
omen -f json defectFiles with high defect probability are statistically likely to contain bugs.
Run the hotspot analysis:
omen -f json hotspotHigh-churn + high-complexity code needs regression protection.
Run the complexity analysis:
omen -f json complexityComplex functions have many code paths that need coverage.
Run the ownership analysis:
omen -f json ownershipSingle-owner code needs tests as documentation for when others maintain it.
Prioritize based on combined signals:
| Priority | Signals | Why Test |
|---|---|---|
| Critical | High risk + High complexity + High churn | Bugs likely, changes often, hard to verify |
| High | High complexity + Single owner | Many paths, tests = documentation |
| Medium | High churn + Moderate complexity | Changes often, needs regression protection |
| Lower | Low complexity + Low churn | Stable, simple code |
Use cyclomatic complexity to estimate test cases needed:
| Cyclomatic Complexity | Minimum Test Cases |
|---|---|
| 1-5 | 2-5 tests |
| 6-10 | 6-15 tests |
| 11-20 | 16-40 tests |
| 21+ | Consider refactoring first |
Generate a test targeting report:
# Test Targeting Report
## Critical Coverage Gaps
### `src/payment/processor.go:processPayment`
- **Defect probability**: 0.82
- **Cyclomatic complexity**: 18
- **Current coverage**: Unknown/Low
- **Estimated tests needed**: 25-35 test cases
- **Why**: High-risk financial logic, frequently modified
### `src/auth/validator.go:validateToken`
- **Defect probability**: 0.75
- **Cyclomatic complexity**: 12
- **Bus factor**: 1 (alice)
- **Estimated tests needed**: 15-20 test cases
- **Why**: Security-critical, single owner, needs documentation
## High-Churn Files (Regression Priority)
| File | Churn (30d) | Complexity | Priority |
|------|-------------|------------|----------|
| api/handlers.go | 45 changes | 24 | High |
| core/engine.go | 32 changes | 31 | High |
| utils/helpers.go | 28 changes | 8 | Medium |
## Knowledge Silo Files
Files where tests serve as critical documentation:
1. `legacy/importer.go` - Only bob has touched this
- Add characterization tests before bob leaves
- Focus on capturing current behavior
2. `integration/sync.go` - Single contributor, complex
- Tests document the sync protocol
- Critical for future maintainers
## Testing Strategy by Area
### Unit Tests Needed
- `processor.go` - All code paths in processPayment
- `validator.go` - All validation rules
- Edge cases in complex conditionals
### Integration Tests Needed
- `api/handlers.go` - Request/response flows
- `storage/repository.go` - Database interactions
### Characterization Tests Needed
- `legacy/` - Capture current behavior before refactoring
## Suggested Order
1. **Week 1**: Critical coverage gaps (highest risk reduction)
2. **Week 2**: High-churn regression tests
3. **Week 3**: Knowledge silo characterization tests
4. **Ongoing**: Maintain coverage on new codeFocus on tests that provide the most value:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.