skills/test-strategy-doc/SKILL.md
Write a test strategy document from a feature spec, PRD, or system description. Use when asked to create a test plan, write a test strategy, define QA approach, or plan testing for a feature or release. Produces a complete test strategy with scope, risk assessment, test types, coverage targets, and a prioritised test case outline.
npx skillsauth add mohitagw15856/pm-claude-skills test-strategy-docInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces a complete test strategy from a feature spec, PRD, or system description — covering scope, test types, risk areas, coverage requirements, and a prioritised test case outline.
Ask for these if not provided:
In scope:
Out of scope:
Assumptions:
Identify the highest-risk areas first — these drive depth and coverage:
| Area | Risk Level | Why | Test Priority | |---|---|---|---| | [e.g. Payment processing] | High | Money movement, regulatory | P0 — exhaustive | | [e.g. User authentication] | High | Security boundary | P0 — exhaustive | | [e.g. Email notifications] | Medium | External dependency | P1 — happy path + key failures | | [e.g. UI copy changes] | Low | Visual only, reversible | P2 — smoke only |
Unit Tests
Integration Tests
End-to-End Tests
Performance Tests (include if any row in the Risk Assessment table has performance as a risk factor, regardless of overall risk level)
Security Tests (include only if risk is high+)
Priority-ordered list of specific test cases:
P0 — Must pass before merge: | Test Case | Type | Expected Outcome | |---|---|---| | [e.g. User can log in with valid credentials] | E2E | [Redirect to dashboard, session created] | | [e.g. Invalid login returns 401] | Integration | [Error message displayed, no session] | | [e.g. Password is never stored in plain text] | Unit | [bcrypt hash in DB] |
P1 — Must pass before release: | Test Case | Type | Expected Outcome | |---|---|---| | [e.g. Login fails gracefully when DB is down] | Integration | [User sees friendly error, 503] | | [e.g. Rate limiting blocks after 5 failed attempts] | Integration | [429 returned, account flagged] |
P2 — Should pass, can ship with known issues tracked: | Test Case | Type | Expected Outcome | |---|---|---| | [e.g. Login page renders correctly on mobile] | E2E | [Layout matches design] |
Testing is complete when:
business
Analyze why deals are won and lost and turn it into an action plan. Use when asked to run a win/loss analysis, review closed-won and closed-lost deals, understand why the team is losing to a competitor, or summarize sales feedback into patterns. Produces a structured win/loss report with themes, win/loss rates by segment and competitor, representative quotes, and prioritized actions for product, marketing, and sales.
development
Route a fuzzy request to the right skill in this library. Use when the user is unsure which skill fits, asks 'which skill should I use for X', describes a task without naming a skill, or when a request could plausibly match several skills. Produces a best-fit recommendation with the inputs to gather, a runner-up with the tie-breaker, and a workflow recipe when the job spans multiple skills.
testing
Triage a vulnerability or scanner finding — assess real severity, exploitability, and how urgently to fix. Use when asked to triage a CVE, prioritize scanner/pentest findings, assess a vuln's risk, or decide what to patch first. Produces a triage verdict: CVSS-informed severity adjusted for your context, exploitability, real risk, a fix/mitigation, and an SLA — so you fix what matters, not just what's red.
development
Stand up a Voice of Customer (VoC) program that turns feedback into action. Use when asked to build a VoC program, design a customer feedback loop, consolidate feedback sources, or set up a closed-loop feedback process. Produces a VoC program design — objectives, feedback sources and channels, a taxonomy, collection and analysis cadence, closed-loop routing, ownership, and success metrics.