mutation-testing
Mutation testing
mutation-testing is Trail of Bits' agent skill for configuring mutation testing campaigns with its mewt or muton tools, reading surviving mutants, telling equivalent mutants from real test gaps, and hunting bugs they expose.
Install Mutation testing
Install this skill with the skills CLI
npx skills add trailofbits/skills --skill mutation-testingOr, in Claude Code, add Trail of Bits' plugin marketplace
/plugin marketplace add trailofbits/skillsOr, in Codex, add the same marketplace from your terminal
codex plugin marketplace add trailofbits/skillsThen install the mutation-testing plugin in Codex
codex plugin add mutation-testing@trailofbitsIn Claude Code, open /plugin menu after adding the marketplace and install the mutation-testing plugin. For a ChatGPT workspace, Trail of Bits' README says to import the repository's .claude-plugin/marketplace.json.
Or paste this into your coding agent: Install the agent skill mutation-testing from github.com/trailofbits/skills.
A skill can include scripts that run on your computer, so read its source first.
What Mutation testing does
mutation-testing is an agent skill from security firm Trail of Bits for mutation testing: making small deliberate changes to source code and checking whether the test suite notices. It works with Trail of Bits' own tools, mewt and muton, which share one interface, and follows the mewt 4.x commands, while telling the agent to trust the installed tool's help output over its examples.
The mutation-testing skill routes each request to one of three workflows. Configuration sets up a campaign, picks targets, measures test time and trims a campaign that would take too long. Analysis reads each surviving mutant, separates equivalent changes from real testing gaps and recommends specific assertions or inputs in a report. Bug hunting uses survivors to point at untested code and requires a reproduced proof before calling anything a bug.
The skill explains what each mutation type means when it survives and warns that a severity label describes the mutation and not the danger to you: a surviving low-severity mutant in fee logic can outweigh a high-severity one in a log line. Analysis also accepts results from slither-mutate, mull and dextool-mutate, and has notes for Solidity, Move, Cairo and Solana code.
When to use Mutation testing
- Your line coverage is high but you doubt your tests would catch real bugs.
- You want mewt or muton set up for a Rust, TypeScript or smart contract project.
- Your mutation campaign would take days and you want it scoped down.
- You have a list of surviving mutants and want to know which ones matter.
When to pick something else
- Plain test or line coverage questions with no mutation testing involved: the skill itself says not to load for those.
What Mutation testing needs
- mewt or muton plus a runnable test suite for running campaigns; analyzing saved results needs neither tool
Which agents Mutation testing works in
Trail of Bits documents Mutation testing for Claude Code, Codex, ChatGPT workspace marketplace. The open skills CLI also installs it into 78 agents, including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode (we listed it with the CLI on October 1, 2026). See where each agent looks for skills.
Mutation testing license
Mutation testing is published under CC-BY-SA-4.0. CC-BY-SA-4.0 is a share-alike license. You can copy the skill into a project and change it, even for commercial work, if you credit Trail of Bits, link the license and say what you changed. If you share a changed version, for example in a public repository, it must stay under CC-BY-SA-4.0. It is a content license, not a software license, so ask your legal team before bundling it inside a closed product.
Questions people ask
Can I copy Trail of Bits' mutation-testing skill into my own repository?
Yes, with conditions. The skills are CC-BY-SA-4.0. You may copy and adapt them, even commercially, if you credit Trail of Bits, link the license and note your changes. Any changed version you share must carry the same CC-BY-SA-4.0 license. Using the skill unchanged in your own work does not put your code under that license.
Does the mutation-testing skill work with tools other than mewt and muton?
Partly. Campaign setup is written for mewt and muton only. The analysis workflow also reads results from slither-mutate, mull and dextool-mutate, and saved results can be analyzed without any mutation tool installed.
Related skills for testing and debugging
- Playwright CLI: playwright-cli is Microsoft's agent skill for driving a real browser from the terminal: open pages, click and fill by element reference, take snapshots and screenshots, mock requests and generate Playwright tests.
- Systematic Debugging: Systematic Debugging is an agent skill from Superpowers that makes your agent find the root cause of a bug or failing test before it proposes any fix, instead of guessing.
- TDD: tdd is Matt Pocock's agent skill for test-driven development: the agent agrees which public interfaces to test with you, then works one failing test and one minimal fix at a time.
- Test-Driven Development: Test-Driven Development is an agent skill from Superpowers: your agent writes a failing test first, watches it fail, then writes only the code needed to make it pass.
More from Trail of Bits
- Differential review: differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report.
- Semgrep rule creator: semgrep-rule-creator is Trail of Bits' agent skill for writing custom Semgrep rules that detect vulnerabilities and bug patterns, test-first, with taint mode preferred and every test required to pass.
- Supply chain risk auditor: supply-chain-risk-auditor is Trail of Bits' agent skill for auditing a project's npm, PyPI and Go dependencies for known advisories, abandoned upstreams, publisher concentration and install scripts, measured by bundled scripts.