Borrowing it
Nothing to install: this file belongs to TheAstrelo/Claude-Pipeline. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/TheAstrelo/Claude-Pipeline/main/.claude/commands/qd.mdgit clone --depth 1 https://github.com/TheAstrelo/Claude-PipelineWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/theastrelo/claude-pipeline/qd)<a href="https://agentmods.dev/commands/theastrelo/claude-pipeline/qd"><img src="https://agentmods.dev/badge/commands/theastrelo/claude-pipeline/qd/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/theastrelo/claude-pipeline/qd"><img src="https://agentmods.dev/badge/commands/theastrelo/claude-pipeline/qd.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00471 |
| Opus 5 | $0.00000 | $0.00235 |
| Sonnet 5 | $0.00000 | $0.00094 |
| Haiku 4.5 | $0.00000 | $0.00047 |
Grade A, and why
qd scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Documentation check - verify Swagger, JSDoc, and API documentation.
Purpose
Verify that new/modified code has appropriate documentation:
- API routes have Swagger docs (REQUIRED)
- Public functions have JSDoc (RECOMMENDED)
- Complex types have descriptions (RECOMMENDED)
Execution
Use the quality-docs agent.
Input: Read build-report.md to identify changed files.
Process:
-
Check API routes for Swagger:
@swaggerblock present- Has summary, tags, security
- Has parameters and responses
-
Check exported functions for JSDoc:
- Has description
- Has @param tags
- Has @returns tag
-
Check types for documentation:
- Complex interfaces have descriptions
- Enum values documented if non-obvious
-
Append results to
qa-report.md
Documentation Requirements
| Item | Requirement |
|---|---|
| API Routes | REQUIRED - must have Swagger |
| Service Functions | RECOMMENDED - should have JSDoc |
| Utility Functions | Optional - if non-obvious |
| Types | RECOMMENDED - if complex |
Swagger Checklist
For each API route:
- Has
@swaggerblock - Has
summary - Has
tags - Has
security(BearerAuth, CookieAuth) - Has
parameters(if applicable) - Has
responses(200, 400, 401, 500)
Output
After check, report:
## Quality Docs Complete
**Verdict:** [PASS | FAIL | WARN]
### API Documentation
- Routes checked: [N]
- Fully documented: [N]
- Missing Swagger: [List]
### Function Documentation
- Functions checked: [N]
- With JSDoc: [N]
- Missing JSDoc: [List]
### Required Additions
[If FAIL, specific docs needed]
### Next Step
Run `/security-review` for security audit.
Gate
This command is part of the QA pipeline.
Order: /denoise → /qf → /qb → /qd → /security-review
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 95 lines · 0 tokens per session scan A 67bc3c6c299d
qd is a command published in the GitHub repository TheAstrelo/Claude-Pipeline (45 stars, last pushed 4d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 471 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
eval
Manage eval-driven development workflow (define, check, report, list).
tdd
A command for test-driven development, a method where you write a failing test first, then code to pass it, and finally improve the code.
test-coverage
Analyze test coverage and generate missing tests to reach 80%+ coverage.
test-suite
Run comprehensive test suite with coverage analysis.
health-check
Perform a comprehensive, read-only end-to-end review of any portfolio app across three layers — Frontend (E2E), Database integrity, and Audit Log & User Activity — and produce a structured, observations-only report. Optionally, on explicit opt-in, generate (never apply) the infrastructure provisions needed so future…
gba-test
$ARGUMENTS: test mode — game profile defines available modes (e.g., smoke, gameplay, save, stress, full, ai, battle, nav, custom ).