ai-regression-testing-1ce690 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ai-regression-testing-1ce690 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
When an agent writes code and then reviews it, it carries the same assumptions into both steps. Automated tests break this cycle.
/bug-check after a change sessionAgent writes fix → Agent reviews fix → Agent says "looks correct" → Bug still presentThe most common blind spot: an agent fixes the production path but leaves the sandbox/mock path unchanged, or vice versa.
Run in order. Do not skip to agent review if automated steps fail.
npm test # or: pytest, cargo test, go test ./...
npm run build # TypeScript build / type checkWith tests passing, do a focused review for patterns agents commonly miss:
For every bug found and fixed, add a test immediately:
Bug: <description>
File: <path>
Regression test: <test name and what it asserts>If you cannot write a test, document why:
Bug: <description>
Regression test: DEFERRED — <reason> (e.g., requires E2E harness not yet in place)Do not silently skip. Every real bug should either have a test or an explicit deferral note.
Test the contract, not the implementation:
// Test what the consumer receives, not how it's computed
const REQUIRED_RESPONSE_FIELDS = ["id", "email", "settings", "created_at"];
it("profile endpoint returns all required fields", async () => {
const res = await GET(createRequest("/api/user/profile"));
const json = await res.json();
for (const field of REQUIRED_RESPONSE_FIELDS) {
expect(json.data).toHaveProperty(field);
}
});Name tests after the bug category, not the fix:
it("sandbox path returns same field set as production path (BUG-CLASS: path-parity)")
it("notification_settings is not undefined after SELECT * removal (regression)")| Pattern | Check | Priority |
|---|---|---|
| Execution path parity | Same response shape across all paths | High |
| Query field omission | All response fields present in DB query | High |
| Error state leakage | State cleared before error is returned | Medium |
| Missing rollback | Previous state restored on API failure | Medium |
Do not aim for coverage percentage. Write tests only for bugs that were found. Bug clusters naturally: if three bugs appeared in /api/user/profile, that endpoint needs tests. An endpoint that has never had a bug does not need tests yet.
Tests added this way grow organically with the bug history and cannot be gamed by coverage metrics.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.