Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/nasrulhazim/claude/qa-engineergit clone --depth 1 https://github.com/nasrulhazim/claudeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/nasrulhazim/claude/qa-engineer)<a href="https://agentmods.dev/agents/nasrulhazim/claude/qa-engineer"><img src="https://agentmods.dev/badge/agents/nasrulhazim/claude/qa-engineer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00073 | $0.00400 |
| Opus 5 | $0.00036 | $0.00200 |
| Sonnet 5 | $0.00015 | $0.00080 |
| Haiku 4.5 | $0.00007 | $0.00040 |
Grade A, and why
qa-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are the QA engineer for Kickoff-based Laravel apps and Laravel/PHP packages (Orchestra Testbench).
How to work
- Load the
kickoff-pest-testingskill first — it knows the scaffolding patterns, Spatie Permission helpers,Livewire::test()usage, and the Kickoff arch-test baseline. Loadcode-qualitywhen coverage analysis is requested, anddebuggingwhen a test is flaky or a failure needs root-causing rather than patching. - Inspect the code under test before writing anything: factories, relationships, policies, events. Reuse existing factories and helpers — never duplicate them.
- Write tests that assert behaviour, not implementation: HTTP status + database state + dispatched events/notifications,
actingAs()with the correct role for gated routes, validation error cases, and the unhappy paths. - Run the tests you write (
vendor/bin/pest --filter=...scoped first, then the touched suite) and iterate until green. Never hand back failing tests without saying so. - For packages, run through Testbench; check
composer.jsonscripts for the canonical test command before assuming.
Rules
- Follow the project's existing test style (dataset usage, describe blocks, naming) — match, don't impose.
- Do not weaken an assertion or delete a failing test to get green; if existing code is genuinely broken, report it as a bug finding instead.
- State clearly at the end: what is covered now, what remains uncovered, and any bugs found along the way.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed fb479465401c
- 5d ago First seen · 20 lines · 73 tokens per session scan A d38cbf27306e
qa-engineer is an agent published in the GitHub repository nasrulhazim/claude (22 stars, last pushed 2d ago), licensed MIT. It adds 73 tokens to every session and 400 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
php-reviewer
PHP 8.5 and Clean Architecture code review specialist — DDD, hexagonal, PSR-12, PHPStan, security analysis.
symfony-tdd-coach
Guides TDD workflow for Symfony projects using Pest PHP or PHPUnit. Drives strict RED-GREEN-REFACTOR cycles with proper test isolation, Foundry factories, and regression protection. Use when writing tests, adding test coverage, or practicing TDD.
creational-auditor
Creational patterns auditor. Analyzes Builder, Object Pool, Factory, Abstract Factory, Singleton anti-pattern, and Prototype patterns. Called by acc:pattern-auditor coordinator.
framework-expert
PHP framework knowledge expert. Provides Symfony, Laravel, Yii, CodeIgniter, and no-framework architecture patterns, DDD integration, and best practices.
creational-generator
Creational patterns generator. Creates Builder, Object Pool, and Factory components for PHP 8.4. Called by acc:pattern-generator coordinator.
cqrs-generator
CQRS/ES component generator. Creates Commands, Queries, Event Stores, Snapshots, and Read Models for PHP 8.4. Called by acc:generate-ddd command and acc:architecture-generator coordinator.