Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/Lykhoyda/rn-dev-agentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/lykhoyda/rn-dev-agent/qa-pr)<a href="https://agentmods.dev/commands/lykhoyda/rn-dev-agent/qa-pr"><img src="https://agentmods.dev/badge/commands/lykhoyda/rn-dev-agent/qa-pr/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/lykhoyda/rn-dev-agent/qa-pr"><img src="https://agentmods.dev/badge/commands/lykhoyda/rn-dev-agent/qa-pr.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00040 | $0.00874 |
| Opus 5 | $0.00020 | $0.00437 |
| Sonnet 5 | $0.00008 | $0.00175 |
| Haiku 4.5 | $0.00004 | $0.00087 |
Grade A, and why
qa-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 70 lines — stays where its author put it; the contents beside it link to each section on GitHub.
QA this React Native pull request: $ARGUMENTS
Run the rn-pr-qa protocol INLINE (parent session)
Important (GH #31): Do NOT spawn the
rn-pr-qaagent via the Task tool. MCP tools (rn_session,cdp_*,device_*) are not available in spawned subagents. Execute the protocol in this parent session.
Load rn-workflow, rn-testing, rn-device-control, and
capturing-proof. Follow agents/rn-pr-qa.md in this session. Summary:
- Parse
$ARGUMENTS. Require a GitHub PR URL,owner/repo#n, or number. Optional--platform ios|android|device|all(defaultall). If the PR identity is missing, ask once and stop. - Fetch with
gh pr view. Stop on auth or lookup failure. - Classify the changed files. Docs-only → SKIP device, report files. Plugin MCP/device changes → exercise the workspace test-app (or the declared candidate app), never Metro-bind the plugin checkout.
- Pin the head in a disposable git worktree. Do not mutate the primary checkout.
- Inventory with
rn-workflowsteps 0–2, thenrn_session(action="status").device_listdiagnoses; it does not choose. Missing requested hardware is SKIP with the exact setup gap. - Per selected target:
bind_device(exact id) →preview_integration→apply_integration confirmed=true→ run the rewritten<pm> run ios|androidfrom the app root → poll untilmetroBoundandinstallBound→pin_dev_client→ exercise the PR change (artifact-first;cdp_login_prologuefor auth). - Cleanup reverse-order: runner close →
stop_metro→restore_integration→release. Remove only the worktree you added. - Report on the PR with
gh pr comment --body-fileplus--attachfor every screenshot and video (GitHub CLI attaching-files flow). Then rewrite screenshot markdown to<img src="…" alt="…" width="720">via--edit-last. In-session, print the verdict table and the comment URL. Never leave unhosted/tmppaths as the reviewer-visible proof.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 70 lines · 40 tokens per session scan A 2c5eb5c86133
qa-pr is a command published in the GitHub repository Lykhoyda/rn-dev-agent (11 stars, last pushed yesterday), licensed MIT. It adds 40 tokens to every session and 874 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-12.
Other commands, from other repositories
dashboard-list-models
List reachable models from the dashboard registry. Usage /dashboard:list-models [annotated].
dashboard-session-abort-all
Abort multiple running sessions (asks which). Usage /dashboard:session-abort-all.
dashboard-session-diff
Show file changes (git diff) for a session by id-prefix. Usage /dashboard:session-diff . Runs locally, no LLM.
dashboard-flow-auto
Toggle autonomous mode for a session's flow. Usage /dashboard:flow-auto.
dashboard-server-tunnel-off
Disconnect the public tunnel. Usage /dashboard:server-tunnel-off.
dashboard-session-rename
Rename a session. Usage /dashboard:session-rename.