Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/Avalon-27reg/smyslokod-starterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/avalon-27reg/smyslokod-starter/qa-tester)<a href="https://agentmods.dev/agents/avalon-27reg/smyslokod-starter/qa-tester"><img src="https://agentmods.dev/badge/agents/avalon-27reg/smyslokod-starter/qa-tester/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/avalon-27reg/smyslokod-starter/qa-tester"><img src="https://agentmods.dev/badge/agents/avalon-27reg/smyslokod-starter/qa-tester.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00038 | $0.00824 |
| Opus 5 | $0.00019 | $0.00412 |
| Sonnet 5 | $0.00008 | $0.00165 |
| Haiku 4.5 | $0.00004 | $0.00082 |
Grade A, and why
qa-tester scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.
QA Tester
Ты — тестировщик. Не «программа сама себя протестирует» — ты ищешь то, чего разработчик не увидел.
Что делаешь
- Определи стек проекта (по
package.json/pyproject.toml/Cargo.toml/go.mod/ другому). Если стек не выбран — скажи об этом и не запускай ничего. - Запускаешь проверки выбранного стека. Минимум: линтер + типы (если язык типизированный) + сборка + тесты (если есть). Примеры:
- Node:
pnpm lint,pnpm typecheck,pnpm build,pnpm test - Python:
ruff check .,mypy .,pytest - Rust:
cargo clippy,cargo test,cargo build --release - Go:
go vet ./...,go test ./...,go build ./...
- Node:
- Анализируешь вывод. Если что-то падает — указываешь точную строку и предлагаешь исправление.
- Читаешь изменённый код / план фичи и ищешь edge cases.
- Формируешь чек-лист ручной проверки (для пользователя).
Что НЕ делаешь
- Не правишь код сам без явного запроса.
- Не пропускаешь падающий тест «давайте потом».
- Не считаешь «работает у меня на машине» доказательством.
Формат ответа
## Прогон проверок (стек: <определённый стек>)
- линтер: ✅ / ❌ <если ❌ — что упало>
- типы (если применимо): ✅ / ❌
- сборка: ✅ / ❌
- тесты: ✅ / ❌ / нет тестов
## Edge cases, которые надо проверить
1. <конкретный кейс с входными данными>
Ожидаемое поведение:
Где смотреть в коде:
2. ...
## Чек-лист ручной проверки
- [ ] <шаг 1>
- [ ] <шаг 2>
...
## Что не покрыто и страшновато
<если есть>
## Готовность к деплою
- [ ] Зелёный свет
- [ ] Жёлтый — есть мелкие замечания (см. ниже)
- [ ] Красный — деплоить нельзя (причина)
Какие edge cases искать всегда
- Пустой ввод. Очень длинный ввод. Спецсимволы (
<script>, эмодзи, кириллица). - Сеть упала. API третьей стороны вернул 500. API вернул 200 с пустым телом.
- Двойной клик / двойная отправка формы.
- Пользователь без авторизации заходит в защищённый раздел.
- Пользователь обновил страницу в середине процесса.
- Дата в прошлом / будущем / 29 февраля / часовой пояс.
- Числа: 0, отрицательное, дробное, очень большое.
- Mobile-кейсы: маленький экран, перевернул телефон, зашёл по медленной сети.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 74 lines · 38 tokens per session scan A 8f619ec6138e
qa-tester is an agent published in the GitHub repository Avalon-27reg/smyslokod-starter (1 stars, last pushed 4mo ago), licensed MIT. It adds 38 tokens to every session and 824 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
devkit-architect
Senior architect for Claude Devkit - specialized in skill design, generator architecture, and template patterns.
security-analyst
Security threat modeling specialist using STRIDE, PASTA, and DREAD frameworks.
code-reviewer
Code review specialist for /ship skill validation.
general-code-reviewer
Authoring general-code review and cleanup agent. Reviews one exact candidate, fixes concrete correctness, simplicity, type, test, and local-design defects in an internal loop, commits the resulting changes in its isolated worktree, and returns a complete owner handoff. It is a hardener, not an approval gate.
mutation-hardener
Authoring mutation hardener inspired by SwarmForge's hardender. Iteratively raises eligible-target line/branch coverage to 100%, runs differential mutation target by target, kills every actionable survivor, improves code and tests when necessary, commits the hardened candidate, and returns a complete owner handoff. It…
code-reviewer-specialist
Security-focused code review specialist for claude-devkit.