Borrowing it
Nothing to install: this file belongs to TheAstrelo/Claude-Pipeline. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/TheAstrelo/Claude-Pipeline/main/.claude/commands/qf.mdgit clone --depth 1 https://github.com/TheAstrelo/Claude-PipelineWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/theastrelo/claude-pipeline/qf)<a href="https://agentmods.dev/commands/theastrelo/claude-pipeline/qf"><img src="https://agentmods.dev/badge/commands/theastrelo/claude-pipeline/qf.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00000 | $0.00440 |
| Opus 5 | $0.00000 | $0.00220 |
| Sonnet 5 | $0.00000 | $0.00088 |
| Haiku 4.5 | $0.00000 | $0.00044 |
Grade A, and why
qf scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Code quality check - verify types, lint, and project conventions.
Purpose
Verify that implemented code fits RDO project quality standards:
- TypeScript types are correct
- ESLint rules pass
- Project conventions followed
Execution
Use the quality-fit agent.
Input: Read build-report.md to identify changed files.
Process:
-
Run automated checks:
npx tsc --noEmit— Type checkingnpx eslint [files]— Lint checking
-
Check RDO conventions:
- Database:
import pool from '@infrastructure/database/connection' - Auth:
requireAuth+AuthenticatedRequest+req.userId! - API: Swagger docs, method checks, error handling
- Frontend: MUI Grid v2 syntax, theme tokens, React Query
- Database:
-
Append results to
qa-report.md
Convention Checklist
| Convention | Check |
|---|---|
| Database import | @infrastructure/database/connection |
| Parameterized queries | No string interpolation in SQL |
No do alias |
Use d instead |
| Auth middleware | requireAuth or requireAdmin |
| MUI Grid v2 | size={{ xs: 12 }} not item xs={12} |
| Theme tokens | No hardcoded hex colors |
| React Query | Not SWR |
Output
After check, report:
## Quality Fit Complete
**Verdict:** [PASS | FAIL]
### Automated Checks
- TypeScript: [PASS | FAIL]
- ESLint: [PASS | FAIL]
### Convention Compliance
[Table of conventions and status]
### Issues Found
[List of specific issues with file:line references]
### Required Fixes
[If FAIL, specific fixes needed]
### Next Step
Run `/qb` for behavior validation.
Gate
This command is part of the QA pipeline.
Order: /denoise → /qf → /qb → /qd → /security-review
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 82 lines · 0 tokens per session scan A 07b999c6165e
qf is a command published in the GitHub repository TheAstrelo/Claude-Pipeline (44 stars, last pushed 4d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 440 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
assemble-team
Assemble a pre-built agent team for parallel work - review, feature, debug, cross-platform, full-stack, or research.
react-patterns
Review React code for performance and composition patterns — 50+ rules ranked by impact.
review-branch
Review an existing branch holistically before merging — blast radius, conventions, security, and spec compliance.
review-csk
Review pass — review + security + quality gates.
code-review
Review staged git changes for bugs, security issues, and style violations.
review
Run only the Hydraia double code-review + security gate on the current branch.