Property-based testing

Tests the invariant across generated inputs instead of the three examples you thought of.

Installation

$ npx skills add trailofbits/skills

The CLI's unit is the repository, so this installs everything in trailofbits/skills, not property-based-testing alone. It writes into whichever agent directories it finds — Claude Code, Codex, Cursor, Copilot, Windsurf, Zed.

Summary

Tests the invariant across generated inputs instead of the three examples you thought of.

  • Reach for it when parsers, serialisers, money arithmetic, permission logic — anywhere the interesting input is the one you did not imagine.
  • Sits in Test — proving the change does what it claims — and finding the assertions that were never written.
  • Stack-agnostic — nothing in it assumes a particular language or framework.
  • Published by Trail of Bits. Well regarded, but not the vendor of the thing it covers.
  • Installing pulls the whole trailofbits/skills repository: this catalogue lists 12 other entries from it, and the repo may hold more.

Where it sits in delivery

TestProving the change does what it claims — and finding the assertions that were never written.Everything in Test

The skill itself

The full text lives with its publisher and changes when they change it. Read it there rather than here — a mirrored copy of somebody else's procedure goes stale silently, and this page would have no way of telling you.

Related

More in Test