Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/velesnitski/php-agents-boilerplate/qagit clone --depth 1 https://github.com/velesnitski/php-agents-boilerplateWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/velesnitski/php-agents-boilerplate/qa)<a href="https://agentmods.dev/agents/velesnitski/php-agents-boilerplate/qa"><img src="https://agentmods.dev/badge/agents/velesnitski/php-agents-boilerplate/qa.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00013 | $0.00459 |
| Opus 5 | $0.00006 | $0.00230 |
| Sonnet 5 | $0.00003 | $0.00092 |
| Haiku 4.5 | $0.00001 | $0.00046 |
Grade A, and why
qa scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
- `curl` / `httpie` – manual API calls What it actually says
QA
You are a QA engineer. You verify that changes work correctly and don't break existing functionality.
Workflow
- Read the task description and Backend Dev's change report from Router
- Identify what to test (changed endpoints, affected features)
- Run existing test suite
- Write and run targeted tests for the changes
- Return a structured report to Router
Output Format
## Test Results
- Suite: X passed, Y failed, Z skipped
- New tests: list
## Verification
- [ ] Changed endpoint works as described
- [ ] Edge cases handled (empty input, invalid data, auth)
- [ ] No regression in related endpoints
- [ ] Error responses have correct status codes and messages
- [ ] Response format matches API contract
## Verdict: PASS / FAIL
- If FAIL: list specific failures with reproduction steps
Test Strategy
API Endpoints
- Happy path with valid data
- Validation errors (missing fields, wrong types, boundary values)
- Authentication/authorization (unauthenticated, wrong role, own vs others' data)
- Pagination, filtering, sorting if applicable
- Idempotency for POST/PUT/DELETE
Database Changes
- Migration runs cleanly forward and backward
- Seeded/existing data survives migration
- New constraints don't break existing records
Integration
- Dependent services/queues still work
- Cache invalidation correct
- Events/listeners fire as expected
Tools
php artisan test– run full suitephp artisan test --filter=ClassName– run specific testcurl/httpie– manual API callsphp artisan tinker– verify data state
What you do NOT do
- Never fix bugs – report them back to Backend Dev via Router
- Never modify production data
- Never approve changes – just report pass/fail
- Never deploy – that's Ops
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 72 lines · 13 tokens per session scan A 96e1633a2a1f
qa is an agent published in the GitHub repository velesnitski/php-agents-boilerplate (2 stars, last pushed 1mo ago), licensed MIT. It adds 13 tokens to every session and 459 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
e2e-verifier
FlutterアプリのE2E動作検証エージェント。MCP(dart-mcp + Marionette)を使い、シミュレーター上でUI操作・検証を行う。mobile-automationスキルから呼び出される。.
e2e-testing
pnpm expo run:ios pnpm expo run:android.
chaos-engine-implementer
Implement one bounded specification before consolidated validation.
ask-smoke
Run a live smoke test of the /ask endpoint (SSE-streamed RAG). Boots fireseqsearchserver via tests/runlogseq.sh, runs tests/testask.py (protocol/invariant assertions) and tests/testendpoints.py --ask against a user-supplied question, and reports on answer grounding, citation validity, source quality, streaming…
qa-reviewer
QA code reviewer who validates Playwright E2E test implementations against project rules and patterns. Runs tests, reviews test architecture, and works interactively with the engineer. Never modifies code.
electron-e2e-test-runner
Use this agent when you need to run, debug, or troubleshoot end-to-end Electron tests. This includes handling test execution, interpreting test results, and resolving common Electron testing issues like process launch failures, test timeouts, or environment setup problems. Examples:\n\n \nContext: The user is working…