{"slug":"test-strategy","title":"test-strategy","summary":"回答\"这个功能应该怎么测\"时使用——风险评级挂证据（Risk Map），翻译成功能域+类型域两域范围与深度：类型域十轴全轴必答（脚本扫描信号+预填修订），include挂信号、exclude挂理由、full有预算上限。不用于：已有策略直接写用例（test-case-writing）、需求建模（requirement-analysis）、端到端流水线（qa）。","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-02T16:13:16.824958Z","repo":{"url":"https://github.com/fishzjp/qa-skills","stars":36,"forks":7,"license":"MIT","updatedAt":"2026-09-20T13:45:21Z"},"bodyHtml":"<hr>\n<h2>name: test-strategy\nslug: test-strategy\ndisplayName: 测试策略\nversion: 0.7.0\ndescription: 回答\"这个功能应该怎么测\"时使用——风险评级挂证据（Risk Map），翻译成功能域+类型域两域范围与深度：类型域十轴全轴必答（脚本扫描信号+预填修订），include挂信号、exclude挂理由、full有预算上限。不用于：已有策略直接写用例（test-case-writing）、需求建模（requirement-analysis）、端到端流水线（qa）。</h2>\n<h1>测试策略（test-strategy）</h1>\n<p>回答\"<strong>这个功能应该怎么测</strong>\"——把风险翻译成<strong>两域测试范围与深度</strong>。策略位于\"需求 → 风险分析 → <strong>策略</strong> → 测试设计 → 用例\"链路中，跳过策略直接写用例是本框架明确反对的。</p>\n<ul>\n<li><strong>输入</strong>：需求模型（<code>需求模型.md</code>；没有则内联轻量研读需求源）、代码仓库、系统架构、历史 Bug</li>\n<li><strong>输出（落盘）</strong>：<code>{项目}/测试策略.md</code>（Risk Map + 两域 scope + depth_budget）；有 handoff / blocked / 外部执行器轴时另产 <code>{项目}/专项移交_{轴}_{日期}.yaml</code></li>\n<li><strong>边界</strong>：不写具体用例（→ <code>test-case-writing</code>）；不代替用户裁决（自动化提案、预算裁决均 ⏸ 等确认）；覆盖范围限于<strong>系统级黑盒</strong>（UI / API / 手动 / 专项移交）——单元/集成测试是开发侧职责，本策略的风险评级与\"已覆盖\"结论均以<strong>该层已有保障为假设前提</strong>（假设未验证时在测试报告标注，防\"系统级全过 = 质量有保障\"的误读）</li>\n</ul>\n<h2>When to Use</h2>\n<ul>\n<li>\"这个功能应该怎么测\"——需要范围 / 类型 / 深度 / 优先级的策略决策与理由</li>\n<li>需要识别风险并评级（Risk Map），作为用例优先级与回归锚点的依据</li>\n<li>需要决定测试类型取舍（性能 / 安全 / 可靠 / 兼容等哪些测、测多深、哪些明确不测）并留痕</li>\n<li>需要制定自动化计划提案与长期回归策略</li>\n</ul>\n<h2>When NOT to Use</h2>\n<ul>\n<li>端到端测试整个需求 → <code>qa</code> 编排</li>\n<li>需要系统性需求建模 → <code>requirement-analysis</code></li>\n<li>已有策略、直接写用例 → <code>test-case-writing</code></li>\n<li>代码变更后判断回归范围 → <code>regression-testing</code>（本 skill 的 regression_plan 是长期回归策略，不是某次 diff 的范围选择）</li>\n</ul>\n<h2>测试策略 Schema（产出结构）</h2>\n<pre><code>test_strategy:\n  feature:\n  functional_scope:            # 功能域：范围+深度+理由（含 state / data_consistency 两轴）\n    functional:        { include: true, depth: full,     rationale: \"核心资损路径\", risk_refs: [R3] }\n    boundary:          { include: true, depth: standard }\n    permission:        { include: true, depth: full,     rationale: \"越权高危\", risk_refs: [R2] }\n    state:             { include: true, depth: standard }\n    data_consistency:  { include: true, depth: standard }\n    regression:        { include: true, depth: standard }\n  type_scope:                  # 类型域：十轴全轴必答，每轴单行 flow 风格（校验器按行解析）\n    performance:        { decision: include, depth: full,     signals: [\"PRD-4.2 SLA\", \"order_service.go:88\"], risk_refs: [R3], executor: k6, execution_status: blocked, todo: \"向运维索取独立压测环境\", handoff_ref: \"专项移交_performance_{日期}.yaml\" }\n    security_business:  { decision: include, depth: standard, signals: [\"多角色\", \"内部信号:permission≥standard\"] }\n    reliability:        { decision: include, depth: standard, signals: [\"retry: pay_service.go:41\"] }\n    concurrency:        { decision: include, depth: standard, signals: [\"库存扣减\", \"S级复核: check-then-write 命中 cart_service.go:41\"] }\n    compatibility:      { decision: include, depth: light,    signals: [\"有前端\"] }\n    accessibility:      { decision: include, depth: light,    signals: [\"有前端\"] }\n    visual:             { decision: include, depth: light,    signals: [\"有前端\"] }\n    i18n:               { decision: exclude,  rationale: \"需求信号（海外/多语言/RTL）未命中；无代码仓库\", scanned: [\"需求信号(G)\"] }\n    migration:          { decision: include, depth: standard, signals: [\"migrations/2026-08-x.sql\"] }\n    contract_integration: { decision: include, depth: standard, signals: [\"外部风控依赖\"] }\n  depth_budget:                # full ≤3（两域合并计）；被裁 Critical 轴走预算裁决\n    full_axes: [functional, permission, performance]\n    ranking_rationale: \"R3(资损 Critical) &gt; R2(越权 High) &gt; ...\"\n  automation_plan:            # 哪些用例自动化、用什么框架（提案，⏸ 等用户确认）\n  regression_plan:            # 回归策略（锚点用例、回归节奏）\n  risk_map_ref:               # 指向 Risk Map（本文档内嵌，每条风险含证据）\n</code></pre>\n<p>字段口径：<code>signals</code> 引用需求章节 / <code>文件:行</code> / 矩阵内部信号；<code>scanned</code> 为 exclude 的 G+S 双清单（项尾标 (G)/(S)）；<code>executor</code> 缺省视为 agent，非 agent（k6 / locust 等）必须带 <code>handoff_ref</code>；<code>execution_status</code> ∈ ready / blocked / done，exclude 轴省略。深度档位<strong>只取三值</strong>：full（逐格全覆盖）/ standard（主干+重点异常）/ light（抽样+冒烟）——\"不测\"不是深度而是范围决策：功能域写 <code>include: false</code>（挂 rationale），类型域写 <code>decision: exclude</code> 或 <code>handoff</code>，均须挂理由（校验器会拒绝 depth 里出现其他值）。</p>\n<blockquote>\n<p><strong>格式硬约束（防弱模型格式漂移）</strong>：type_scope <strong>每轴必须写成一行</strong> flow 风格，形如 <code>performance: { decision: include, depth: standard, signals: [\"...\"] }</code>——<strong>禁止</strong>把一个轴拆成 decision / depth / signals 多行块式（校验器按行解析，块式 = 校验失败 = 该轴视同未决策）。写之前先照抄上一行的形状。依据：弱模型实测近半数样本出现块式漂移致解析失败，决策内容本身无恙——纯格式损耗。</p>\n</blockquote>\n<h2>工作流</h2>\n<h3>1. 输入研读</h3>\n<ul>\n<li>读需求模型（无则读原始需求源做轻量研读）；有代码 → 索取仓库（路径/分支/diff），确认实现形态（有无 UI、接口面、数据流）</li>\n<li>收集历史 Bug（同功能区/同模块），历史缺陷密度是 Likelihood 的估计输入与升降档 R3 的触发输入</li>\n</ul>\n<h3>2. 风险识别与评级（此时加载 <code>../core/risk-model.md</code>）</h3>\n<ul>\n<li>按<strong>维度</strong>扫风险：功能域维度（权限 / 数据一致性 / 边界 / 状态流转 / 资损——五维与第 3 步 scope 六轴的对应关系见 <code>../core/risk-model.md</code> 的 dimension 注释）+ 类型域轴名（并发 / 可靠 / 安全 / 性能 / 兼容 / 迁移 / 契约——与矩阵轴同源）</li>\n<li>每条风险（R1、R2…）按模型评级：<strong>Impact × Likelihood（各 1–5）→ Critical/High/Medium/Low</strong>，每条强制带 evidence——<strong>没有证据的风险评级视为无效评级</strong></li>\n<li>方法选择参考 <code>../core/testing-principles.md</code> 第 2 节（按功能特征选设计方法，决定功能域各轴的深度理由）</li>\n</ul>\n<h3>3. 功能域范围决策</h3>\n<p>逐轴决定 include / depth / rationale（functional / boundary / permission / state / data_consistency / regression）：</p>\n<ul>\n<li>风险等级 → 用例优先级映射按 <code>../core/risk-model.md</code> 第 3 节执行（Critical 必有 P0 且为回归锚点……），偏离显式说明理由</li>\n<li><strong>不测的也要写理由</strong>——\"为什么不测\"与\"为什么测\"同等重要</li>\n<li>permission 高深度（≥standard）同时是轴 2 业务安全的内部纳入信号（裁决见矩阵第 2 节）</li>\n</ul>\n<h3>4. 类型域全轴扫描（此时<strong>按组加载</strong> <code>../core/test-type-matrix.md</code> 对应小节）</h3>\n<p><strong>分轴组推进</strong>（A 资金与正确性 → B 依赖与变更 → C 前端体验；每组只加载矩阵中本组轴的小节，不整文件加载）：</p>\n<ol>\n<li><strong>G 级扫描</strong>（有代码仓库时，开工跑一次三组共用）：<code>python3 ../core/scripts/scan_signals.py &lt;仓库路径&gt;</code> → 每轴 G 级信号 + 预填表</li>\n<li><strong>逐轴决策（受限选择，从预填表修订，不空白生成）</strong>：需求信号 → G 级核对 → <strong>S 级照单复核</strong>（矩阵各轴标〔S〕的项逐项读代码确认）→ decision → depth</li>\n<li><strong>防橡皮图章</strong>：exclude 永不预填——exclude 必须完成 S 级复核并把 G+S 双清单写进 <code>scanned</code>；\"脚本无命中\"单独不构成 exclude 理由</li>\n<li><strong>组内交付核对</strong>：本组全轴有决策再进下一组；十轴完成进入第 5 步</li>\n</ol>\n<p>无代码仓库：跳过 G/S 级，仅需求信号决策；exclude 的 rationale 注明\"无代码仓库\"（校验器按此豁免 S 级要求）。</p>\n<h3>5. 深度校准与预算排序（此时执行矩阵第 13 节 R1–R6）</h3>\n<ul>\n<li>升降档按 R1–R6（风险升档 / 双源信号 / 历史缺陷 / 无信号降档 / 成本门 / 预算约束）</li>\n<li><strong>R6 &gt; R1</strong>：full（两域合并）&gt; 3 时按风险排序裁剪；被裁剪的 Critical 轴触发 <strong>⏸ 预算裁决检查点</strong>——呈现排序与裁剪影响，用户可扩预算（扩预算时 depth_budget 记 <code>budget_review: {approved_by: 用户}</code>）</li>\n<li><strong>depth 与 execution_status 分离</strong>：环境 / 数据 / 工具缺位 → depth 不降，记 <code>blocked</code> + <code>todo</code>（向谁索取什么）——\"做不了\"不得冒充\"不用测\"</li>\n</ul>\n<h3>6. 自动化计划提案（⏸ 提案，不裁决）</h3>\n<ul>\n<li>按用例特征提案：有 UI 主流程 → Playwright（<code>automated-e2e-testing</code>）；接口级校验/幂等/并发 → API 脚本（<code>api-testing</code>）；脚本型轴的执行物（性能/视觉、无障碍的 axe 扫描任务）→ 专项脚本 / 扫描任务；探索性/一次性 → 手动</li>\n<li>automation_plan 是<strong>提案</strong>：列出建议清单 + 框架 + 不自动化清单 + 理由，交用户确认（qa 流水线中为执行策略检查点）；确认前不启动执行类 skill</li>\n</ul>\n<h3>7. 回归策略</h3>\n<ul>\n<li>从 Critical/High 风险与 P0 用例中指定<strong>回归锚点</strong>（每次必跑）</li>\n<li>regression_plan：锚点集 + 按变更类型的扩展规则（接口变更 → 接口用例全量；UI 变更 → 主流程 E2E……）</li>\n</ul>\n<h3>8. 落盘与交付</h3>\n<ol>\n<li>写 <code>{项目}/测试策略.md</code>（Schema 结构 + Risk Map 内嵌；type_scope 每轴单行 flow 风格 + 足够性声明：逐轴档位动作清单与完成状态；开头一段<strong>范围假设声明</strong>：本策略限于系统级黑盒，单元/集成测试为开发侧职责，结论以此为前提）</li>\n<li>handoff 轴 / include+外部执行器 / blocked 轴 → 生成 <code>{项目}/专项移交_{轴}_{日期}.yaml</code> 移交包（目标、场景参数、阈值/验收口径）</li>\n<li><strong>校验后交付</strong>：<code>python3 ../core/scripts/validate_schema.py {项目}/测试策略.md</code>（V1–V5；有代码仓库时叠加 <code>--repo-root {仓库根}</code> 抽查各轴 signals 指涉真实性），错误清零再交付。注意：include 且挂 Critical 风险的轴若最终维持 full 以下档位，校验器要求该轴名出现在 budget_review 文本中——降档裁量必须留一行依据，不许无声消失</li>\n<li>交付索引给下游（<code>test-case-writing</code>）：策略路径 + include 轴清单（用例型轴的 type/标签要求见矩阵第 12 节）+ 优先级映射要求</li>\n</ol>\n<h2>Common Mistakes</h2>\n<table>\n<thead>\n<tr>\n<th>错误</th>\n<th>后果</th>\n<th>正确做法</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>风险评级无证据（拍脑袋 High）</td>\n<td>评级不可复核，策略失去推导链</td>\n<td>每条风险挂 evidence（<code>../core/risk-model.md</code>）</td>\n</tr>\n<tr>\n<td>类型轴静默缺失（漏轴）</td>\n<td>类型盲区被藏成\"没想过\"，无从挑战</td>\n<td>十轴必答（V1），exclude 也要留痕</td>\n</tr>\n<tr>\n<td>include 无信号 / exclude 无理由</td>\n<td>过测 / 漏测</td>\n<td>signals 挂证据；rationale + scanned 双清单（V2/V3）</td>\n</tr>\n<tr>\n<td>脚本无命中直接 exclude</td>\n<td>脚本盲区被制度化为漏测</td>\n<td>S 级复核后才可 exclude（G+S 双确认）</td>\n</tr>\n<tr>\n<td>full 满天飞</td>\n<td>资源稀释在长尾，无重点</td>\n<td>full ≤3 + 挂风险编号（V4）；冲突时 R6&gt;R1 + 预算裁决</td>\n</tr>\n<tr>\n<td>环境缺位记成 exclude</td>\n<td>\"做不了\"冒充\"不用测\"</td>\n<td>depth/execution 分离，blocked + todo（R5/V5）</td>\n</tr>\n<tr>\n<td>scope 只写布尔开关</td>\n<td>\"测多深\"丢失，执行时各自理解</td>\n<td>范围 + 深度 + 理由三件套</td>\n</tr>\n<tr>\n<td>把用例写进策略</td>\n<td>越界（那是 test-case-writing 的产出）</td>\n<td>策略到\"范围/深度/优先级要求\"为止</td>\n</tr>\n<tr>\n<td>automation_plan 直接执行不等确认</td>\n<td>剥夺用户执行策略裁决权</td>\n<td>提案 → ⏸ 用户确认 → 才启动执行</td>\n</tr>\n<tr>\n<td>风险等级沿用 P0/P1 命名</td>\n<td>与用例优先级同名歧义</td>\n<td>风险用 Critical/High/Medium/Low（<code>../core/risk-model.md</code>）</td>\n</tr>\n</tbody>\n</table>\n","files":[{"path":"SKILL.md","sizeBytes":13280,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-27T19:48:43.031026Z","sha256":"57E43E756715BA0DE0701E9F948856AE75C2635B5D9BC3BA8B1F8FF780167BD0","sizeBytes":6655},"review":null,"source":{"repositoryUrl":"https://github.com/fishzjp/qa-skills","path":"skills/test-strategy","license":"MIT","commit":"ac89a31391fe85c99a6303772aa197e552ed415e","subtreeSha":"D1D7D27EE4E31F49ED342418C4D23339164BF888752F9B32A4AA5E7E95DB1DE4","lastSyncedAt":"2026-09-27T19:48:09.379129Z"},"reviewedAt":"2026-09-27T19:49:21.196843Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/fishzjp/qa-skills/tree/main/skills/test-strategy"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install fishzjp-qa-skills@llmmart"},{"target":"git","command":"git clone https://github.com/fishzjp/qa-skills.git"}]}