Problem
Only the pure parseGitHubUrl from src/lib/skill/marketplace.ts has tests. Untested but load-bearing:
discoverSkills tree filtering (marketplace.ts:253) — path-prefix logic over untrusted GitHub tree responses.
importSkillDir's MAX_EXTRA_FILES / MAX_FILE_BYTES caps — the guards themselves are unverified.
src/lib/contributors.ts — sizedAvatar (pure) and the bot-filtering in fetchContributors.
src/lib/use-local-storage.ts / src/lib/use-debounced-value.ts — JSON-parse fallbacks and timer logic.
This is exactly the kind of code that regresses silently.
Implementation notes
- Marketplace + contributors are node-testable today with a mocked
fetch — see the existing tests in src/lib/skill/__tests__/ for the house style.
- The two hooks need the jsdom setup tracked separately — fine to leave them for a follow-up PR.
Good first issue because… these are functions with clear inputs and outputs, and the existing lib tests show exactly what a good test file here looks like.
Problem
Only the pure
parseGitHubUrlfromsrc/lib/skill/marketplace.tshas tests. Untested but load-bearing:discoverSkillstree filtering (marketplace.ts:253) — path-prefix logic over untrusted GitHub tree responses.importSkillDir'sMAX_EXTRA_FILES/MAX_FILE_BYTEScaps — the guards themselves are unverified.src/lib/contributors.ts—sizedAvatar(pure) and the bot-filtering infetchContributors.src/lib/use-local-storage.ts/src/lib/use-debounced-value.ts— JSON-parse fallbacks and timer logic.This is exactly the kind of code that regresses silently.
Implementation notes
fetch— see the existing tests insrc/lib/skill/__tests__/for the house style.Good first issue because… these are functions with clear inputs and outputs, and the existing lib tests show exactly what a good test file here looks like.