Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/chrono-meta/forge-harnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/chrono-meta/forge-harness/fh-qp)<a href="https://agentmods.dev/plugins/chrono-meta/forge-harness/fh-qp"><img src="https://agentmods.dev/badge/plugins/chrono-meta/forge-harness/fh-qp.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
fh-qp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "fh-qp",
"version": "3.1.4",
"engines": {
"claudeCode": ">=1.0.0"
},
"description": "QP (Quality Platform) — 4 skills (qp · qp-plan · qp-run · qp-regress). Plan→Automation→Regression loop for web and desktop apps with zero domain constants. Calls a registered qasp typed capability when one is present (strictest-wins); otherwise drives the target through the session's Playwright MCP (web) or computer-use MCP (desktop). Mobile deferred.",
"author": {
"name": "chrono-meta",
"email": "[email protected]"
},
"keywords": [
"qa",
"quality-platform",
"test-planning",
"e2e",
"regression",
"surface-reach",
"mtm",
"domain-agnostic"
]
}
What it installs
The manifest is a name and a version. 4 skills travel with it, and installing the plugin installs all of them — 505 tokens a session between them. Each is measured on its own page, and each can be installed alone.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed b7b1e4436671
- 2d ago First seen · 23 lines scan A 69f7b7367c92
fh-qp is a plugin published in the GitHub repository chrono-meta/forge-harness (14 stars, last pushed today), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-06.
Other plugins, from other repositories
ai-swift
AI-powered Swift / iOS / macOS release-readiness and quality toolkit - catches Xcode Cloud and TestFlight blockers before upload (XcodeGen pbxproj drift, static build numbers, missing ciscripts, macOS App Store entitlements/Info.plist, headless-CI keychain test failures, ad-hoc signing entitlement rejections, flaky-UI.
e2e-dashboard
Install a real-time Playwright E2E test dashboard (live SSE progress, 14 features) into any project.
mobile-app-testing
Test your web app on real iOS Simulator / Android emulator sessions via tapflow, alongside your existing Playwright suite.
verification
Evidence-based QA and verification: risk-based scenario discovery, an evidence rigor ladder with strict PASS/FAIL/BLOCKED verdicts, checklist-driven E2E with human gates, and competing-hypothesis debugging.
humanizer
Rewrite AI-sounding text so it reads naturally without changing what it says.
nextjs
Official Next.js skills: adopt and optimize Cache Components, adopt Partial Prefetching, and verify runtime behavior against a running dev server.