Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add Anasss/qa-orchestranpx agentmods add plugins/anasss/qa-orchestra/qa-orchestragit clone --depth 1 https://github.com/Anasss/qa-orchestraGrade A, and why
qa-orchestra scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "qa-orchestra",
"version": "1.1.0",
"description": "10 coordinated QA agents for Claude Code: chains diff analysis, AC compliance, test scenarios, browser validation, bug reports, and automation code generation.",
"author": {
"name": "Anass R.",
"url": "https://github.com/Anasss"
},
"homepage": "https://qa-orchestra.com",
"repository": "https://github.com/Anasss/qa-orchestra",
"license": "MIT",
"keywords": [
"qa",
"testing",
"agents",
"orchestrator",
"browser-validation",
"functional-review",
"test-scenarios",
"bug-reports",
"acceptance-criteria",
"diff-analysis",
"playwright",
"claude-code-plugin"
],
"screenshots": [
"docs/images/qa-orchestra-detective.webp"
],
"agents": "./.claude/agents/"
}
What it installs
The manifest is a name and a version. 10 agents travel with it, and installing the plugin installs all of them — 264 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Agent environment-manager A 20 tokens
- Agent orchestrator A 23 tokens
- Agent automation-writer A 21 tokens
- Agent browser-validator A 26 tokens
- Agent bug-reporter A 58 tokens
- Agent release-analyzer A 25 tokens
- Agent smart-test-selector A 26 tokens
- Agent test-scenario-designer A 25 tokens
- Agent functional-reviewer A 23 tokens
- Agent manual-validator A 17 tokens
What ships with it
1 file beside plugin.json in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 31 lines scan A be399225e8af
qa-orchestra is a plugin published in the GitHub repository Anasss/qa-orchestra (11 stars, last pushed 4mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
claude-code-skills marketplace
348 production-ready skill packages for Claude AI across 18 domains: engineering advanced (78, incl. v2.9.0 workflow-builder for Claude Code Workflow-tool authoring), engineering core (51), marketing (46 — incl. AEO/Answer Engine Optimization), c-level advisory (66), product (17), regulatory/QMS (18), compliance-os…
maestro-mobile-validator
iOS and Android mobile app validation via Maestro flows with simulator management and CI patterns.
swarm-skill
Multi-agent codebase audit skill for Claude Code — spawns parallel subagents (security, performance, tests, architecture, dead-code) and synthesizes their findings into a prioritized action plan.
browser-tools
Chrome automation tools for agent-assisted web testing and interaction using Chrome DevTools Protocol.
self-review
Review every code change before the turn ends: fresh-context reviewer agents, a verified finding standard, honest convergence, and a measured token budget — enforced by a Stop hook, graph-aware when you have a code graph, zero-cost when you don't.
o11y-analysis-tools marketplace
PromQL-Cody: Agent Skills for the o11y-analysis-tools PromQL/Alertmanager CLIs (promql-fmt, label-check, autogen-promql-tests, e2e-alertmanager-test, alert-hysteresis, stale-alerts-analyzer).