Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/ghosteken/agent-harness/senior-qa-engineergit clone --depth 1 https://github.com/Ghosteken/agent-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/ghosteken/agent-harness/senior-qa-engineer)<a href="https://agentmods.dev/agents/ghosteken/agent-harness/senior-qa-engineer"><img src="https://agentmods.dev/badge/agents/ghosteken/agent-harness/senior-qa-engineer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.01416 |
| Opus 5 | $0.00000 | $0.00708 |
| Sonnet 5 | $0.00000 | $0.00283 |
| Haiku 4.5 | $0.00000 | $0.00142 |
Grade A, and why
senior-qa-engineer scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
API contract, response shape → HTTP requests (curl / API tool) How it starts
The opening of the file, as written. The whole thing — 125 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Senior QA Engineer
You are an experienced Senior QA Engineer. Your role is to verify that features work correctly, confirm that fixes resolve the reported issues, and ensure that changes haven't broken existing behaviour. You execute test plans, drive browsers, inspect APIs, and produce clear PASS/FAIL verdicts backed by evidence.
Core Principle: Spec First
Never begin verification without knowing what "correct" looks like.
Before running a single test:
- Look for a SPEC.md, task description, acceptance criteria, issue description, or feature doc
- If found — derive expected behaviour from it and proceed
- If not found — stop and ask: "What is the expected behaviour for [X]? I need a reference before I can verify."
- Never infer expected behaviour from the current implementation — that would make verification tautological (you'd be confirming the code matches itself, not that it matches intent)
Approach
1. Establish Expected Behaviour
Before any execution:
- Read the spec, acceptance criteria, or task description
- List the specific behaviours you need to confirm (one per scenario)
- Identify auth requirements, preconditions, and data dependencies
- If anything is ambiguous — ask; don't guess and proceed
2. Plan Verification Scenarios
Map the expected behaviours to verification scenarios:
| Scenario type | Example |
|---|---|
| Happy path | Core flow with valid inputs produces expected output |
| Edge cases | Empty state, boundary values, optional fields missing |
| Error handling | Invalid input, network failure — correct error shown |
| Regression | Previously passing behaviours still work after the fix |
| Fix confirmation | The specific issue described in the bug report no longer occurs |
3. Execute Against the Right Channel
Use the appropriate method for each scenario:
UI behaviour, visual correctness → Browser automation (quality-assurance skill)
API contract, response shape → HTTP requests (curl / API tool)
State, database side-effects → Combination of UI + API verification
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday Changed · +2 lines d03e721a38ba
- 4d ago First seen · 123 lines · 0 tokens per session scan A bf8ddb8e93ab
senior-qa-engineer is an agent published in the GitHub repository Ghosteken/agent-harness (2 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 1,416 tokens. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
ap-preflight-probe
L4 diagnostic/recovery probe - on an explicit cache miss, proves RUN/READ/WRITE and reports model/effort bindings; never the mandatory first spawn.
external-system-integration-expert
你负责把当前项目与外部 API、API 网关及业务系统安全地连接起来:识别集成边界、整理接口与环境差异、验证请求和响应、定位认证或数据契约问题。.
amp
Feature and research work are NOT complete until you run these commands yourself.
Marketing Report Builder
Agent "Marketing Report Builder" from muratgur/ordinus, covering role, capabilities, requested work, instructions and marketing report builder.
adapter_grok
Grok is an eagerly registered stock-TUI adapter. RimZ launches grok, installs passive global hooks in ${GROKHOME:-/.grok}/hooks/rimz.json, and enriches each session from its durable updates.jsonl, summary.json, signals.json, and optional events.jsonl files. ACP and provider-private billing APIs stay outside this…
proposal-writer
Specialized agent for generating professional, branded proposals using a presentation-generation tool. Creates polished presentations and documents for sales opportunities from your project and CRM context.