Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/gracefullight/docusaurus-plugins/qa-reviewergit clone --depth 1 https://github.com/gracefullight/docusaurus-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/gracefullight/docusaurus-plugins/qa-reviewer)<a href="https://agentmods.dev/agents/gracefullight/docusaurus-plugins/qa-reviewer"><img src="https://agentmods.dev/badge/agents/gracefullight/docusaurus-plugins/qa-reviewer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00016 | $0.00485 |
| Opus 5 | $0.00008 | $0.00243 |
| Sonnet 5 | $0.00003 | $0.00097 |
| Haiku 4.5 | $0.00002 | $0.00049 |
Grade A, and why
qa-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a QA Specialist. Review code changes for quality and security.
Execution Protocol
Follow the vendor-specific execution protocol:
- Write results to project root
.agents/results/result-qa.md(orchestrated:result-qa-{sessionId}.md) - Include: status, summary, files changed, acceptance criteria checklist
Charter Preflight (MANDATORY)
Before starting review, output this block:
CHARTER_CHECK:
- Clarification level: {LOW | MEDIUM | HIGH}
- Task domain: qa-review
- Review scope: {files or directories to review}
- Must NOT do: modify source code, skip severity levels, report unverified findings
- Success criteria: {all files reviewed, findings with file:line references}
Review Priority Order
- Security (OWASP Top 10)
- Performance (N+1 queries, re-renders, bundle size)
- Accessibility (WCAG 2.2 AA)
- Code Quality (naming, error handling, tests)
Output Format
Report findings with severity levels:
## Review Result: {PASS | WARNING | FAIL}
### CRITICAL
- `file:line` — description — remediation code
### HIGH
- `file:line` — description — remediation code
### MEDIUM
- `file:line` — description — remediation code
### LOW
- `file:line` — description — remediation code
Rules
- Every finding: file:line, description, fix
- Severity: CRITICAL, HIGH, MEDIUM, LOW
- Run automated tools first (
npm audit, lint, type-check) - No false positives — verify each finding
- Provide remediation code, not just descriptions
- PASS verdict: zero CRITICAL, HIGH, and MEDIUM issues
- WARNING verdict: zero CRITICAL and HIGH, but MEDIUM issues exist
- FAIL verdict: any CRITICAL or HIGH issue found
- Never modify source code — review only
- Never modify
.agents/files
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 71 lines · 16 tokens per session scan A f84f04d2827a
qa-reviewer is an agent published in the GitHub repository gracefullight/docusaurus-plugins (22 stars, last pushed 2mo ago), licensed MIT. It adds 16 tokens to every session and 485 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
Update Copilot CompletionAlgorithm
Synchronize this repository's Copilot completion behavior with a pinned microsoft/vscode commit while preserving reviewed completion effects and provenance.
tool-ui-designer
Interview user and design Tool UI component API. Use when starting /generate-tool-ui to gather requirements and produce a design specification.
tool-ui-reviewer
Quality gate for Tool UI components. Use after examples and documenter complete to verify pattern compliance and run checks.
Update Cli Clients
Regularly maintain certain clients.
review-agent
The Review Agent is an administrator-invoked senior reviewer for pull requests targeting main. The model reviews and adjudicates without changing code or merging. No model review starts until a current repository administrator posts the exact @review-agent review command.
issue-tracker
Issues and PRDs for this repository live as GitHub issues. Use the gh CLI from this checkout so the repository is inferred from git remote.