SkillAgentSearch skills...

property-based-testing

Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants

Install / Use

npx skills add trailofbits/skills --skill property-based-testing

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

83/100

Category

Legal

Supported Platforms

Universal

Our assessment of property-based-testing

property-based-testing scores 83/100 on our quality scale, 67th of 103 Legal skills we index.

Its SKILL.md is 4.2 KB long, split into 5 sections and no code examples: a solid amount of guidance for an agent.

With 7,225 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
11/20
Description
15/15
Adoption
16/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 4 days ago, so property-based-testing is actively maintained.
  • It is released under the CC-BY-SA-4.0 license; check its terms before commercial use.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

property-based-testing compared with similar skills

All 4 of these similar skills score higher than property-based-testing; compare them before choosing.

SkillScoreStarsUpdatedFormat
property-based-testing (this skill)by trailofbits837.2k4d agoSKILL.md
Agent-Reachby Panniantong10085.8k12d agoCLAUDE.md
headroomby headroomlabs-ai10074.0k1d agoCLAUDE.md
crawl4aiby unclecode10084.4k3d agoMCP Server
Scraplingby D4Vinci10084.1ktodayMCP Server

Frequently asked questions

How do I install property-based-testing?
Run npx skills add trailofbits/skills --skill property-based-testing. The install tabs above show the steps for each supported agent.
Which AI agents does property-based-testing work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is property-based-testing safe to use?
It is CC-BY-SA-4.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is property-based-testing still maintained?
The repository was last updated 4 days ago, so property-based-testing is actively maintained.

name: property-based-testing effort: low description: "Writes, reviews, and debugs property-based tests — Hypothesis, fast-check, proptest, jqwik, rapid, and Echidna or Medusa for Solidity invariants. Use whenever tests should cover a whole input domain instead of a hand-picked list of examples: encode/decode and serialize/deserialize pairs, parsers, canonicalizers and normalizers, validators, numeric and Decimal types, comparators and sort order, data structures, and smart-contract state invariants. Also use when adding cases to an existing @given, fast-check, or proptest suite, when judging whether existing property tests assert anything real, and when a generator has shrunk a counterexample and you need to tell a wrong property from a genuine bug. Not for coverage-guided binary fuzzing (libFuzzer, AFL), mutation-testing campaigns, static analysis, benchmarking, or end-to-end UI tests."

Property-Based Testing

An example test asserts one point. A property asserts a rule over the whole input domain and lets the generator hunt for the counterexample. That trade is worth making when the code has an algebraic shape — an inverse, an invariant, an oracle — and not otherwise. Code with no such shape gets example tests; saying so is a valid outcome.

Check first whether the shape is missing or merely buried. A calculation wrapped in I/O, a string built by concatenation, an in-place mutation — each has a property and no seam to assert it through. See references/refactoring.md before concluding there is nothing to assert.

Property catalog

| Property | Formula | Where it applies | |---|---|---| | Roundtrip | decode(encode(x)) == x | Serialization, conversion pairs | | Inverse | f(g(x)) == x | encrypt/decrypt, compress/decompress | | Oracle | new(x) == reference(x) | Optimization, refactoring, reimplementation | | Idempotence | f(f(x)) == f(x) | Normalization, formatting, sorting | | Invariant | Holds before and after | Any transformation, contract state | | Easy to verify | is_sorted(sort(x)) | Complex algorithms with cheap checkers | | Commutativity | f(a, b) == f(b, a) | Binary and set operations | | Associativity | f(f(a,b), c) == f(a, f(b,c)) | Combining operations | | Identity | f(x, e) == x | Operations with a neutral element |

Strength ordering, weakest to strongest: no crash → type preservation → invariant → idempotence → roundtrip / oracle.

Assert the strongest property the code supports. "No crash" alone rarely justifies the dependency — if that is all you can find, either a small rearrangement exposes something stronger, or the honest report is that this code is a poor PBT candidate. Rule out the first before settling for the second.

The two ways a property test asserts nothing

  • Tautology. assert add(a, b) == a + b restates the implementation; no bug they share can fail it. Pick a property that constrains the function without recomputing it. Note the exception: f(x) == f(x) is a genuine determinism property when f is not obviously pure — serializers over dicts or sets, hashing, anything reading the clock.
  • Vacuity. assume() that filters out nearly every input passes without exercising anything, and self-contradictory assume() passes having run zero cases. Push constraints into the strategy so the generator produces valid inputs directly.

Where to look next

Load the one that matches the task in front of you:

| Task | File | |---|---| | Writing new tests, designing strategies | references/generating.md | | The code has no property to assert yet | references/refactoring.md | | Reviewing existing property tests | references/reviewing.md | | A property test just failed | references/interpreting-failures.md | | Library choice, Echidna and Medusa | references/libraries.md |

Introducing PBT to a project that lacks it

If the project already uses a PBT library, just write the tests in it. If it does not, adding one is a dependency decision that belongs to the user — offer it once with the specific property you would write, and take the answer either way.

Related Skills

View on GitHub
GitHub Stars7.2k
CategoryLegal
Updated4d ago
Forks615

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions