More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Shift Left

    2

    Risk analysis reporting and software test prioritisation

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    shift-left

    shift-left

    Example session with this skill installed

    /shift-left create plans

    • Read your context and instructions
    • Compiled the shift-left
    • Generated the document

    I have enough to assess and ask the scope question. Here's what I found.

    Quality Maturity Assessment

    Current Level: 3 -- Workflow-Centric

    Evidence

    • Three test tiers in place: tests/unit/, tests/integration/, tests/functional/
    • pytest + pytest-django + pytest-xdist; coverage.py uploaded to Codecov
    • GitHub Actions matrix: 5 Python versions x 3 Django versions, PostgreSQL service
    • Key e-commerce workflows covered: payment (bankcard, models), checkout (calculators,
      session, surcharges, views), order (creator, event_handler, processing, reports),
      basket, offer, customer, dashboard, partner, shipping
    • Python linting (flake8, isort, pylint, black) and JS linting (eslint) in CI
    • Functional tests use django-webtest (HTTP-level, not browser)

    Strengths

    • Unusually thorough integration test coverage for a library -- most e-commerce modules
      have meaningful tests at the right layer
    • CI version matrix is a genuine strength; regressions across Django/Python versions
      are caught before release
    • Codecov tracks coverage at patch level

    Gaps

    • CodeQL runs on a weekly schedule only -- not gated on PRs; a vulnerability introduced
      in payment or checkout code can merge before the next scan
    • No dependency vulnerability scanning (no pip-audit, Safety, or Bandit)
    • No browser-based E2E (functional tests use WebTest -- no JS execution, no real
      browser rendering)
    • No accessibility testing despite a customer-facing storefront surface in the sandbox
    • No coverage threshold enforced; CI never blocks on coverage regression
      Archetype: Django Oscar is a Library/SDK with a customer-facing storefront + admin dashboard delivered via a sandbox. Risk is concentrated in the e-commerce domain -- payment, checkout, offer calculation, order processing, and the customer auth backend.

    Likely relevant plans

    Plan Rationale
    Quality risk strategy Always
    Unit Existing suite; strengthen offer/voucher calculation and checkout pipeline edge cases
    Integration Existing suite; strengthen payment seams and order event handling
    Security High priority -- CodeQL weekly gap, no SAST, payment + auth + admin
    E2E Sandbox has real customer + admin UI; WebTest covers logic but not JS or real browser rendering
    Accessibility Lightweight -- customer-facing storefront; no current tooling
    Not recommended: Performance (no runtime load concern for a library), Contract (no HTTP API surface; Oscar's extension points are covered by integration tests and semantic versioning).

    Would you like

    All relevant plans -- quality risk strategy + unit + integration + security + E2E + accessibility (recommended)
    Only the umbrella quality risk strategy
    A custom subset

    All plans written and dashboard generated. Here's the summary:

    Do first (in this order):

    CodeQL on PRs -- 3-line YAML edit to .github/workflows/codeql-analysis.yml. Closes the biggest gap immediately; a vulnerability introduced in checkout or auth code currently survives until the next weekly scan.
    pip-audit in CI -- run it locally first to get a clean baseline, then add a security job to test.yml. ~15 lines.
    Offer/voucher boundary unit tests -- benefit cap when discount exceeds line total, per-customer voucher reuse, exclusive voucher blocking.
    Order event handler failure test -- verify test_event_handler.py covers the dispatch-failure path explicitly.

    Defer for now

    Playwright E2E -- valuable, but start it after security CI is stable
    Accessibility -- add axe-playwright alongside Playwright once that suite is running
    Performance and contract -- not applicable at the library layer
    Deliverables written to django-oscar/quality/:

    File
    1-quality-risk-strategy.md Risk table, Mermaid diagrams, coverage summary, top 10 test cases
    1-quality-risk-strategy-dashboard.html Stakeholder-ready visual
    2-unit-test-plan.md Offer/voucher/checkout priority cases
    3-integration-test-plan.md Checkout seam, payment, order event handler
    4-security-test-plan.md CodeQL gate + pip-audit -- exact YAML included
    5-e2e-test-plan.md 5 Playwright journeys against the sandbox
    6-accessibility-test-plan.md axe-playwright on 4 key pages, keyboard baseline
    README.md Entry point with plan table and do-first summary

    shift-left.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Create a repo-specific quality roadmap based on current technical debt.Generate targeted test cases for a specific feature or archetype.Review existing automated tests for brittle logic or coverage gaps.Perform a scoped bug hunt to find regressions in a specific branch.Assess quality maturity to select the right testing tools and layers.

    About this skill

    What it does

    Shift Left transforms your AI agent into a Senior QA and Test Automation Engineer. Instead of generating generic testing advice, it performs deep, repo-specific inspections to create risk-based quality strategies, test plans, and actionable test cases that actually match your codebase and tech stack.

    Why use this skill

    Most AI agents provide "textbook" QA answers that don't scale. Shift Left is designed for developer-first testing: it respects token limits by lazily loading resources, identifies your project archetype (SaaS, CLI, Mobile, etc.), and refuses to "hallucinate" tools you haven't installed. It bridges the gap between raw code and a professional quality roadmap, ensuring your testing effort is prioritized based on actual technical risk.

    Supported Deliverables

    • Quality Risk Strategies: High-level risk analysis reports focused on where your app is most likely to break.
    • Deep-Dive Test Plans: Specific guides for Unit, Integration, API, E2E, and Performance layers.
    • Targeted Bug Hunting: Context-aware exploration for regressions in specific commits or branches.
    • Automation Reviews: Audits of existing test suites for maintainability and coverage gaps.
    • Technical Templates: Professional bug reports and quality dashboards generated as clean HTML or Markdown.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 4 months ago

    • Passed all security checks, Safe to install

    Listed4 months ago

    What's inside

    Frequently Asked Questions