QaCAUTION
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Overview
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
d90170da4369OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: qa description: "Systematic QA testing of a web application: diff-aware, tiered, with fix-and-verify loop" argument-hint: "[path] [--thorough]" effort: high disable-model-invocation: true --- # QA: Web application testing Systematically test a web application for bugs, then fix and verify each issue found. Three tiers of thoroughness. Diff-aware scoping tests what actually changed. ## Instructions ### Step 1: Scope detection Determine which pages and features to test. **Diff-aware mode (default):** Identify affected routes from the current branch changes. ```bash # Files changed in this branch git diff --name-only origin/main...HEAD 2>/dev/null || git diff --name-only HEAD~5 # Identify affected routes from changed files # e.g., changes in src/pages/dashboard/ → test /dashboard # changes in api/payments/ → test payment flows ``` **Full mode** (`/qa --full`): Test the entire application, starting with critical paths. **Explicit scope** (`/qa /dashboard /settings`): Test specified pages only. --- ### Step 2: Tier selection | Tier | Flag | Scope | Use when | |------|------|-------|----------| | Quick | `--quick` | Critical + High severity only | Pre-commit fast check | | Standard | *(default)* | + Medium severity | Pre-PR review | | Exhaustive | `--exhaustive` | + Low + cosmetic | Release candidate | --- ### Step 3: Clean working tree Before testing, ensure you can commit fixes atomically. ```bash git status --short ``` If there are uncommitted changes: stash them first (`git stash`), or commit them. Testing on a dirty tree makes it impossible to isolate fix commits. --- ### Step 4: Testing For each page in scope, systematically check all categories relevant to the selected tier. #### How to test Use whatever browser tooling is available: - **MCP browser tools** (if configured): automated navigation and screenshots - **Playwright/Puppeteer** (if in the project): scripted test runs - **Manual testing**: navigate to the URL, document findings systematically For each page, cover: ``` 1. Load the page: does it render without errors? 2. Check console: any uncaught errors, failed requests, warnings? 3. Test primary user action: the core thing this page is for 4. Test empty state: what shows when there's no data? 5. Test error state: what happens when an action fails? 6. Test on narrow viewport: does it break below 375px? ``` #### Issue taxonomy **Visual** (layout, spacing, typography, colors, responsiveness) **Functional** (broken interactions, missing features, wrong behavior) **UX** (confusing flows, missing feedback, poor error messages) **Content** (typos, wrong copy, placeholder text in production) **Performance** (slow page loads, layout shifts, unoptimized images) **Console** (JavaScript errors, failed network requests, deprecation warnings) **Accessibility** (missing alt text, keyboard traps, missing labels, contrast) #### Severity levels | Severity | Criteria | Examples | |----------|----------|---------| | **Critical** | Feature completely broken or data loss risk | 500 error, blank page, form that loses data | | **High** | Major feature degraded, significant UX harm | Wrong data shown, broken primary CTA, mobile layout broken | | **Medium** | Minor feature issue, noticeable but workaround exists | Visual glitch, confusing empty state, slow load | | **Low** | Cosmetic, barely noticeable | Minor spacing, minor copy issue, low-severity console warning | **Quick tier**: Critical + High only **Standard tier**: Critical + High + Medium **Exhaustive tier**: All severities --- ### Step 5: Document findings Track each issue with a unique ID. ``` ISSUE-001 Severity: [Critical / High / Medium / Low] Category: [Visual / Functional / UX / Content / Performance / Console / Accessibility] Page: [URL or route] Finding: [What is wrong, specific not vague] Steps: [How to reproduce] Expected: [What should happen] Evidence: [Screenshot path or console output] ``` --- ### Step 6: Fix and verify loop For each Critical and High issue (and Medium/Low in Standard/Exhaustive tiers): 1. **Fix the issue** in source code 2. **Commit atomically**: one commit per fix ```bash git add <changed-files> git commit -m "fix: <brief description of what was fixed>" ``` 3. **Re-verify**: navigate to the same page and confirm the issue is resolved 4. **Update the issue status** to FIXED with the commit hash Do not batch multiple fixes in one commit. Each fix must be individually revertable. --- ## Output format ``` QA REPORT ════════════════════════════════════════ Branch: [current branch] Scope: [pages tested] Tier: [Quick / Standard / Exhaustive] Duration: [time taken] HEALTH SCORES ───────────────────────────────────────── Visual [PASS / WARN / FAIL] [N issues] Functional [PASS / WARN / FAIL] [N issues] UX [PASS / WARN / FAIL] [N issues] Content [PASS / WARN / FAIL] [N issues] Performance [PASS / WARN / FAIL] [N issues] Console [PASS / WARN / FAIL] [N issues] Accessibility [PASS / WARN / FAIL] [N issues] ISSUES FOUND: N (X critical, Y high, Z medium, W low) ISSUES FIXED: N ISSUES REMAINING: N ───────────────────────────────────────── ISSUE-001 [FIXED | OPEN] Severity: High Category: Functional Page: /dashboard Finding: Save button does nothing when form has validation errors, no feedback shown Fix: Added error toast notification (commit abc1234) ISSUE-002 [OPEN] Severity: Medium Category: Visual Page: /settings Finding: Input fields overflow container below 375px viewport ... ───────────────────────────────────────── SHIP READINESS Critical issues: [0 remaining / N remaining (BLOCKER)] High issues: [0 remaining / N remaining (CONCERN)] VERDICT: [READY TO SHIP / NOT READY: address critical and high issues first] ════════════════════════════════════════ ``` ## Usage ``` /qa # Standard tier,
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
whitepapers/recap-cards/en/_extensions
whitepapers/recap-cards/fr/_extensions
Gates applied: no_behavioural_pass.
d90170da4369full audit observations/trust-audit/skill/florianbruniaux__qa.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d90170da4369 | CAUTION | B | 89 | first audit |
Questions
What does the Qa skill do?
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Is Qa safe to install?
With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.
What can Qa access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (d90170da4369), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.