Mutation Testing
Configures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps. Use when setting up mutation testing, reviewing campaign results, identifying equivalent mutants, or finding bugs from surviving mutations.
- Type
- Plugin
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Version
- 1.9.2
- Author
- Trail of Bits
What Mutation Testing is
Mutation Testing is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Mutation Testing adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Mutation Testing
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
- Install the plugin: claude plugin install mutation-testing@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
- Find Mutation Testing in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/mutation-testing/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
Configure mutation testing campaigns, explain what surviving mutations reveal about tests, and investigate potential bugs in the affected code.
The plugin ships one skill, mutation-testing. Invoke it with /mutation-testing:mutation-testing or ask for help with a mutation testing campaign or its results.
Workflows
A surviving mutation means the tests did not detect a deliberate change. It can reveal a testing gap or an equivalent implementation. It does not by itself establish a bug in the original code. The analysis workflow recommends test improvements without implementing them.
Prerequisites
Campaign setup uses mewt or muton, plus a runnable test suite. Examples follow the mewt 4.x API. Check the installed tool's --help for supported flags and language labels. For muton projects, substitute muton, muton.toml, and muton.sqlite in the examples.
Analyzing saved results does not require either tool to be installed. Supply the campaign output, the source at the mutation sites, and the relevant tests. The analysis workflow also accepts results from other mutation testing tools.
Examples
- "Help me set up mewt for this Rust project."
- "Configure muton for this FunC codebase."
- "My mutation campaign would take 30 hours. Help me reduce its scope."
- "Which of these surviving mutants are equivalent, and what tests are missing?"
- "Investigate the original code around these surviving authorization mutations."
Validation
The bundled eval uses a captured campaign against a deliberately weak Rust test suite. It requires the agent to distinguish balance > 0 from two mutations: balance != 0 is equivalent for u64, while balance >= 0 differs at zero. It also checks authorization, balance-accounting, and logging gaps. The fixture can be analyzed without cargo or mewt.
Run the report-validator tests from the repository root:
uv run --no-project --with pytest python -m pytest plugins/mutation-testing/tests -q --import-mode=importlib
DETERMINISTIC_ONLY=1 uv run --no-project bash plugins/mutation-testing/tests/smoke-test.shThe deterministic checks accept a correct report and reject reports that misclassify either comparison. They test the grader, not the skill's effectiveness. The optional model eval checks the agent's report against the same validator:
# Requires Claude Code with plugin eval support and ANTHROPIC_API_KEY.
uv run --no-project bash plugins/mutation-testing/tests/smoke-test.shThe model eval retains reports locally and makes API calls. Its model, judge, run count, and cost ceiling can be set with MODEL, JUDGE_MODEL, RUNS, and MAX_COST_USD. A passing fixture does not establish improvement over an agent without the skill.
To reproduce the captured campaign, work on a separate copy:
mutation_fixture_dir="$(mktemp -d)/vault"
cp -R plugins/mutation-testing/evals/weak-suite-analysis/fixture "$mutation_fixture_dir"
cd "$mutation_fixture_dir"
cargo test
mewt mutate
mewt run
mewt resultsReferences
- mewt
- muton
- Use mutation testing to find the bugs your tests don't catch
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Mutation Testing?
Mutation Testing is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Configures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps. Use when setting up mutation testing, reviewing campaign results, identifying equivalent mutants, or finding bugs from surviving mutations.
How do I install Mutation Testing in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install mutation-testing@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Mutation Testing in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Mutation Testing in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Mutation Testing safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- C Review Comprehensive C/C++ security code review, with coverage verified against a parse of the source Plugin · trailofbits/skills
- C Review Fp Judge Second-stage judge in the c-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors)… Subagent · trailofbits/skills
- 6 Test Generator Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test execution. Subagent · trailofbits/skills
- C Review Worker Runs one c-review producing task — a location slice, the class sweep, the invariant audit or the dedup pass — reading source and writing exactly one part file. Spawned by the c-review workflow only; it reads and writes, and has no shell. Subagent · trailofbits/skills
- Property Based Testing Write, review, and triage property-based tests — Hypothesis, fast-check, proptest, and Echidna or Medusa for Solidity invariants Plugin · trailofbits/skills
- Modern Python Modern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools. Plugin · trailofbits/skills
- Rust Review Comprehensive Rust security code review with specialized bug-finding agents covering the safe/unsafe boundary, memory safety in unsafe blocks, concurrency, panic-induced DoS, recursion-induced stack overflow, FFI, and async runtime hazards Plugin · trailofbits/skills
- Let Fate Decide Draws the 12 Houses of the Zodiac Tarot spread using cryptographic randomness to add 100+ bits of entropy to vague or underspecified planning. Interprets the spread to guide next steps. Use when feeling lucky, invoking heart-of-the-cards energy, or when prompts are ambiguous. Plugin · trailofbits/skills