qa-test-data
Test data engineering: 17 skills (bogus-data, boundary-value-generator, e2e-test-narrative-builder, factory-bot-data, faker-data, golden-file-conventions, malicious-payload-bank, mimesis-data, mountebank-imposters, msw-handlers, negative-test-generator, pairwise-test-case-generator, seed-data-curator, synthetic-data-tool-selector, synthetic-pii-generator, test-data-patterns, wiremock-stubs) and 3 agents (golden-file-manager, mock-server-composer, test-data-setup-agent).
Install this plugin
/plugin install qa-test-data@testland-qaPart of role bundles: qa-starter, qa-role-manual-tester, qa-role-automation-engineer, qa-role-sdet
qa-test-data
Test data engineering: Faker as the default generator plus the synthetic-data-toolkit umbrella (FactoryBot / mimesis / Bogus); WireMock (with Mountebank multi-protocol reference) and MSW mock servers; golden-file conventions + manager; seed-data curator; parameterized / boundary / negative test case generators; synthetic PII; malicious payload bank.
Components
| Type | Name | Description |
|---|---|---|
| Skill | faker-data | Faker (Python faker / JS @faker-js/faker / Ruby faker-ruby) - fields, locales, deterministic seeding. The family default. |
| Skill | synthetic-data-toolkit | Umbrella for the generators beyond Faker: dispatch by language + job; side-by-side patterns; full FactoryBot (Ruby), mimesis (Python), and Bogus (.NET) workflows in references/. |
| Skill | wiremock-stubs | JVM HTTP mock server: stubFor matchers + willReturn + verify() + dynamic ports + scenarios; Mountebank multi-protocol workflow in references/. |
| Skill | msw-handlers | JS / TS HTTP mocking via Mock Service Worker: http.get / HttpResponse.json handlers; browser + Node setup. |
| Skill | golden-file-conventions | Reference: snapshot/golden file naming, layout, sanitization, severity tiering, update-vs-fix decision tree. |
| Skill | seed-data-curator | Build a reproducible E2E seed dataset; coverage matrix; persistence formats; intentional refresh cadence. |
| Skill | pairwise-test-case-generator | All-pairs / pairwise combinatorial generation from a multi-input spec; constraints; coverage report. |
| Skill | boundary-value-generator | Six-point boundary cases per typed input field (numeric / string-length / collection-count / enum / nullable). |
| Skill | synthetic-pii-generator | Realistic-but-fake PII using safe-by-construction values (RFC 2606 domains, IRS test SSN range, Stripe test cards). |
| Skill | malicious-payload-bank | Reference catalog of adversarial payloads (SQLi / XSS / SSRF / path traversal / XXE / prototype pollution / ReDoS / Unicode / CRLF). |
| Skill | test-data-patterns | Architecture-tier reference: Test Data Builder (Pryce), Factory (with traits), Object Mother (Fowler), Fixture composition (Meszaros four-phase + Fresh-vs-Shared), Snapshot (defers to golden-file-conventions), Production-Data Anonymisation. |
| Skill | negative-test-generator | Generate rejection-path tests mirroring happy-path: schema / auth / authz / rate / conflict / adversarial / server-error categories. |
| Agent | golden-file-manager | Active maintenance: add / update / prune snapshot baselines; refuse updates whose diff doesn't match PR intent. |
| Agent | test-data-setup-agent | Stands up a full test-data setup for a feature: fixtures + seed data, composing the plugin's generators. |
Choosing WireMock vs MSW vs Mountebank
| Project shape | Mock server |
|---|---|
| JVM (Java / Kotlin / Scala), HTTP dependencies | wiremock-stubs - in-process @WireMockTest, typed DSL |
| JS / TS (browser or Node), HTTP dependencies | msw-handlers - one handler set shared across Vitest / Jest / Cypress / Playwright |
| Any stack with non-HTTP dependencies (TCP, SMTP, LDAP, gRPC, WebSockets) | Mountebank - see wiremock-stubs references/mountebank.md |
Pick one per project; add Mountebank only when a dependency genuinely isn't HTTP.
Install
/plugin marketplace add testland/qa
/plugin install qa-test-data@testland-qaSkills
boundary-value-generator
Generates boundary-value test cases from typed input specifications - for each input field, produces the canonical 6-point set (one below, at, and above the lower bound; one below, at, and above the upper bound) plus equivalence-class representatives. Emits cases as parameterized test inputs (pytest @parametrize / Jest test.each / xUnit InlineData / etc.). Use when a function or endpoint has numeric / string-length / collection-size constraints and the team needs systematic edge-case coverage.
faker-data
Fixes test data that breaks tests - factory values in a shape the code under test rejects (a phone number that is not E.164), fixtures that only pass when the whole suite runs in order, and random values that make an assertion pass or fail depending on the run. Authors test-data factories with Faker: the Python `faker` library, the `@faker-js/faker` JS port, and the `faker-ruby` gem - install per language, the provider catalogue (person / internet / location / date / finance / lorem), locale selection and multi-locale mode, and seed-based determinism for reproducible runs. Scope is generating fresh values for tests that start from nothing, not replacing values inside a dataset that already holds real records - that goes to pii-masking-pipeline-builder. Use when fixtures need realistic values, a stable shape, or a fixed seed.
golden-file-conventions
Reference catalog for snapshot / golden file management - naming conventions, directory layout, when to add / update / remove a baseline, sanitization (timestamps, IDs, PII), per-OS / per-runtime variant strategy, and review workflow for snapshot diffs in PRs. Use when designing a snapshot-testing convention or auditing an existing one for drift.
malicious-payload-bank
Reference catalog of curated adversarial input payloads keyed by attack class - SQL injection, XSS, SSRF, path traversal, command injection, XXE, prototype pollution, regex DoS, Unicode confusables, header injection - plus per-context guidance for which payloads apply (URL parameter / form input / JSON body / file upload). Use when authoring negative-test cases for input validation, fuzz targets, or a security-focused test suite that needs to exercise the OWASP Top 10 attack surface.
msw-handlers
Authors Mock Service Worker (MSW) request handlers for both browser and Node.js test environments using the `http.get` / `http.post` / `HttpResponse.json` API, wires them via `setupWorker` (browser) or `setupServer` (Node), and manages the test lifecycle (`server.listen` / `resetHandlers` / `close`). Use when the project uses JavaScript / TypeScript and needs to mock fetch / XHR at the network layer for both Vitest / Jest unit tests and Cypress / Playwright integration tests.
negative-test-generator
Covers the refusal paths a handler already implements but nothing tests - a batch endpoint that must apply all rows or none, optimistic-concurrency version conflicts between two editors, or a delete that deliberately separates who you are from what you may do from the state the record is in. For each happy-path test, produces companions exercising input validation rejection, missing required fields, type mismatches, authorization failures, rate-limit errors, and adversarial payloads from the malicious-payload-bank, emitted as parameterized tests in the project's runner format. Use when code has deliberate error paths and the suite only proves the success case.
pairwise-test-case-generator
Generates parameterized test inputs combining boundary-value, equivalence-class, and pairwise-combinatorial cases from a typed multi-input specification - produces the cross-product of cases up to a configurable strength (1-wise / 2-wise / N-wise) using all-pairs reduction so the test surface stays tractable. Emits cases in the project's test-runner-native parametrize format. Use when a function or endpoint takes 3+ inputs whose interactions matter and full Cartesian product would explode.
seed-data-curator
Builds a reproducible E2E seed dataset for the project's test environments - picks a representative user / org / data-product cross-section, generates the rows via the project's chosen factory library (FactoryBot / mimesis / Bogus / Faker + factory_boy), persists the dataset as a checked-in fixture (SQL dump / JSON / per-engine seed file), and wires it into the test bootstrap. Use when starting E2E coverage on a project that has no seed strategy, or when an existing seed has drifted.
synthetic-data-toolkit
Umbrella for the synthetic test data generators beyond plain Faker - FactoryBot (Ruby factories with traits, associations, and build / create / build_stubbed strategies), Mimesis (fast type-hinted Python generator with the Schema/Field bulk pattern and 46 locales), and Bogus (.NET typed `Faker<T>` builders with `.RuleFor` / `StrictMode` / `UseSeed`). Picks the right generator by language and job, shows side-by-side equivalents of the same fixture across all four ecosystems, and carries each tool's full workflow in references/ (factory-bot.md, mimesis.md, bogus.md). faker-data stays the default for plain field values in Python / JS / Ruby; use this skill when the project needs typed factory orchestration, .NET fixtures, or a documented "which tool should I use" decision.
synthetic-pii-generator
Generates realistic-but-fake personally identifiable information (PII) - emails, phone numbers, SSNs / national IDs, addresses, names, credit-card numbers (test BIN ranges), date-of-birth - for non-production environments. Wraps Faker / mimesis with PII-aware constraints so generated values match real format expectations (Luhn-valid card numbers, region-valid phone formats, ITIN/SSN format) without ever generating real-person data. Use when seeding test environments, building demo data, or replacing real PII in copied datasets.
test-data-patterns
Pure reference catalog of the cross-language object-construction patterns for test data - Test Data Builder (Pryce/Freeman), Factory (with traits and associations), Object Mother, Fixture composition (per-test / per-describe / shared), Snapshot (defers to `golden-file-conventions` for the operational details), and Production-Data Anonymisation. Distinct from the per-language tool skills (`faker-data` and the `synthetic-data-toolkit` umbrella covering FactoryBot / mimesis / Bogus) which document tool-specific configuration; this catalog is the architecture-tier reference for choosing **which pattern** before reaching for the tool. Use when choosing a test-data construction pattern for a new suite, or auditing an existing suite whose fixtures have drifted into shared mutable state.
wiremock-stubs
Authors WireMock stub mappings for HTTP service mocking - `stubFor` with verb/path/header matchers + `willReturn` response shaping, lifecycle via `WireMockServer` (start / stop) or JUnit `WireMockExtension`, request verification via `verify()`, and dynamic-port allocation for parallel tests. Also carries the Mountebank multi-protocol workflow (TCP / SMTP / LDAP / gRPC imposters, record-playback proxying) in references/mountebank.md. Use when the project is JVM-based and tests need to mock HTTP dependencies (third-party APIs, internal microservices) at the network layer, or when mocking must go beyond HTTP.
Agents
golden-file-manager
Action-taking agent that maintains snapshot / golden file health across a project - adds new baselines for previously-uncovered tests, updates baselines after intentional changes (refusing to update if the diff doesn't match the PR's stated intent), prunes orphaned baselines whose tests no longer exist, and applies sanitization rules from the golden-file-conventions catalog. Use as a periodic maintenance pass or after a refactor that touches many snapshot tests.
test-data-setup-agent
Action-taking agent that sets up a complete test-data layer for a single feature - detects the project language and stack, generates per-test fixture factories (via faker-data or synthetic-data-toolkit), and builds a reproducible E2E seed dataset (via seed-data-curator), wiring both into the test bootstrap. Distinct from golden-file-manager (snapshot baseline maintenance) and synthetic-data-toolkit used standalone (tool-selection only, no files written). Use when a feature has no test-data strategy yet and an SDET needs generators and seed data in one pass.