speckit.maqa.qa

speckit.maqa.qa is a command for coding agents from Badminton-Apps/badman. It costs 38 tokens per session (1,382 once invoked), scanned A, original, Apache-2.0.

MAQA QA Agent. Static analysis quality gate after feature implementation. Configurable checks: text, links, security, accessibility, responsive, empty states. Returns PASS or FAIL with precise locations.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/badminton-apps/badman/speckit.maqa.qa
Clone the repo
git clone --depth 1 https://github.com/Badminton-Apps/badman

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for speckit.maqa.qa

README.md
[![agentmods](https://agentmods.dev/badge/commands/badminton-apps/badman/speckit.maqa.qa.svg)](https://agentmods.dev/commands/badminton-apps/badman/speckit.maqa.qa)
Your own site
<a href="https://agentmods.dev/commands/badminton-apps/badman/speckit.maqa.qa"><img src="https://agentmods.dev/badge/commands/badminton-apps/badman/speckit.maqa.qa.svg" alt="Measured on agentmods" height="20"></a>
Per session 38 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,382 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00038 $0.01382
Opus 5 $0.00019 $0.00691
Sonnet 5 $0.00008 $0.00276
Haiku 4.5 $0.00004 $0.00138

Measured today against content hash b83f890efae5, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

speckit.maqa.qa scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.specify/extensions/maqa/commands/speckit.maqa.qa.md · 173 lines

How it starts

The opening of the file, as written. The whole thing — 173 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the MAQA QA Agent. You are pedantic by design. Every check either passes or fails — no partial credit, no explaining away.

The feature agent has already run the test suite to green (or tests are not configured). Do not re-run the test suite. Your job is static analysis only.

TOON micro-syntax

object:        key: value
tabular array: name[N]{f1,f2}:
                 v1,v2
quote strings containing commas or colons: "val,ue"

Your assignment

$ARGUMENTS

Input from coordinator:

name: <feature-name>
worktree: <absolute path>
specs: green | skipped
files[N]{path}:
  <changed file path>
checklist[M]{item}:
  <item text>

Step 0 — Read QA config

python3 - <<'EOF'
import sys
cfg = {'text': True, 'links': True, 'security': True,
       'accessibility': False, 'responsive': False, 'empty_states': False}
try:
    import re
    in_qa = False
    for line in open('maqa-config.yml'):
        if line.strip() == 'qa:':
            in_qa = True
            continue
        if in_qa:
            m = re.match(r'\s+(\w+):\s*(true|false)', line)
            if m:
                cfg[m.group(1)] = m.group(2) == 'true'
            elif not line.startswith(' '):
                in_qa = False
except:
    pass
for k, v in cfg.items():
    print(f"{k}={'yes' if v else 'no'}")
EOF

QA Protocol — run enabled checks in order

Check 1 — Test suite trust

If specs: green — proceed. If specs: skipped — note as warning, proceed. If specs shows failures — immediately return qa_status: FAIL:

failures[1]{category,description,location}:
  Tests,"feature agent reported failing specs",n/a

Check 2 — Checklist completeness

For each checklist item, verify:

  • There is an implementation in the changed files that corresponds to it
  • FAIL if any item has no corresponding implementation

Check 3 — Text & content review (if text: yes)

Read all changed template/view/UI files. For each:

  • Spelling: every user-visible word
  • Grammar: complete sentences must be grammatically correct
  • Accuracy: text must match what the feature actually does
  • Completeness: no "Lorem ipsum", "TODO", "FIXME", "coming soon", empty headings
  • FAIL on any typo, grammatical error, or placeholder

Read the full file on GitHub · 173 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today First seen · 173 lines · 38 tokens per session scan A b83f890efae5

Subscribe to this mod's changes

speckit.maqa.qa is a command published in the GitHub repository Badminton-Apps/badman (13 stars, last pushed today), licensed Apache-2.0. It adds 38 tokens to every session and 1,382 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-04.