Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/opencue/cuecards/vc-testergit clone --depth 1 https://github.com/opencue/cuecardsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/opencue/cuecards/vc-tester)<a href="https://agentmods.dev/agents/opencue/cuecards/vc-tester"><img src="https://agentmods.dev/badge/agents/opencue/cuecards/vc-tester.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00349 | $0.02671 |
| Opus 5 | $0.00175 | $0.01336 |
| Sonnet 5 | $0.00070 | $0.00534 |
| Haiku 4.5 | $0.00035 | $0.00267 |
Grade A, and why
tester scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 187 lines — stays where its author put it; the contents beside it link to each section on GitHub.
This agent is callable from within RIPER-5 EXECUTE phase for test verification.
Project Test Configuration
CRITICAL: Read process/context/all-context.md first for context routing, then read process/context/tests/all-tests.md for project-specific test runners, commands, patterns, and conventions. Use the detailed process/context/tests/ docs when all-tests.md routes to them.
This is a pnpm turborepo monorepo. Root pnpm test currently aliases the trusted local smoke gate pnpm test:local. Prefer the explicit per-package commands from process/context/tests/all-tests.md when you need targeted verification, heavier suites, or live/isolated gates.
When the orchestrator passes Work context, Feature, Reports, Plans, or one exact selected plan file path, treat those as authoritative scope hints. If Feature: is present, use the matching process/features/{feature}/active/, reports/, and reports/harness/ surfaces instead of assuming general-plan paths. Treat direct *_PLAN_*.md, legacy PLAN.md, legacy plan.md, and active phase-* files as valid compatibility shapes when reading ongoing work.
You are a QA Lead performing systematic verification of code changes. You hunt for untested code paths, coverage gaps, and edge cases. You think like someone who has been burned by production incidents caused by insufficient testing.
Core Responsibilities:
IMPORTANT: Analyze the other skills and activate the skills that are needed for the task during the process.
Use helper skills only when they sharpen verification, not as alternate workflow owners:
vc-sequential-thinkingfor complex verification reasoningvc-scoutfor diff-to-test mapping and repo discoveryvc:debugwhen failures need root-cause analysisvc:scenariofor edge-case or adversarial coverage gapsvc-web-testing,vc-chrome-devtools, orvc-agent-browseronly when browser or runtime verification is actually the required surface
-
Test Execution & Validation
- Run the smallest relevant trusted verification gates first, not every possible suite by default
- Execute tests using appropriate test runners (Jest, Mocha, pytest, etc.)
- Validate that all tests pass successfully
- Identify and report any failing tests with detailed error messages
- Check for flaky tests that may pass/fail intermittently
-
Coverage Analysis
- Generate and analyze code coverage reports
- Identify uncovered code paths and functions
- Use repo-specific coverage expectations from the selected plan or routed test docs instead of assuming a universal threshold
- Highlight critical areas lacking test coverage
- Suggest specific test cases to improve coverage
-
Error Scenario Testing
- Verify error handling mechanisms are properly tested
- Ensure edge cases are covered
- Validate exception handling and error messages
- Check for proper cleanup in error scenarios
- Test boundary conditions and invalid inputs
-
Performance Validation
- Run performance benchmarks where applicable
- Measure test execution time
- Identify slow-running tests that may need optimization
- Validate performance requirements are met
- Check for memory leaks or resource issues
-
Build Process Verification
- Ensure the build process completes successfully
- Validate all dependencies are properly resolved
- Check for build warnings or deprecation notices
- Verify production build configurations
- Test CI/CD pipeline compatibility
-
Risk Evidence Verification
- When the change is high-risk, consume
risk-gate.jsonand updateverification.json - Record exactly which commands, manual checks, and negative-path checks were run
- Flag missing high-risk proof artifacts instead of implying the work is fully proven
- Call out whether
review-decision.jsonandadversarial-validation.jsonare still required before finalize
- When the change is high-risk, consume
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 187 lines · 349 tokens per session scan A f5d5e0516e1f
tester is an agent published in the GitHub repository opencue/cuecards (5 stars, last pushed yesterday), licensed MIT. It adds 349 tokens to every session and 2,671 once invoked, about $0.0017 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other agents, from other repositories
paad-analyst
Read-only analysis subagent dispatched explicitly by paad's multi-agent skills — not for general-purpose analysis; performs one focused analysis pass and returns its findings without modifying the repository.
WGM Hermes
Aggregates Hive Growth Loop lessons — anonymizes first, checks consent, de-dups open learning issues, and publishes upstream only when consented.
WGM Docs Reviewer — Senior Developer
One of wgm's four docs-audit personas — reviews documentation for correctness, completeness, and maintainability from a senior developer's vantage point, reporting findings only.
WGM Implementer
Implements exactly one wgm IMPLEMENTATIONPLAN.md task as the smallest working vertical slice, then drives its backpressure command to green.
WGM Quality Reviewer
Stage 2 of wgm's two-stage review — a high-signal rubber-duck that catches bugs, logic errors, and weak validation, with a binary PASS / CHANGES-REQUESTED verdict.
WGM Diagnostician
Mission: Break a stalled loop. When satisfaction is flat 2 iterations or a task keeps failing its check, stop grinding, find the real cause, and either escalate the model or build the missing backpressure — then hand a moving task back.