Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add PramodDutta/qaskillsnpx agentmods add plugins/pramoddutta/qaskills/qa-essentialsgit clone --depth 1 https://github.com/PramodDutta/qaskillsGrade A, and why
qa-essentials scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "qa-essentials",
"description": "QASkills.sh QA Essentials — 10 curated skills that turn your agent into a QA engineer: Claude Code QA, E2E (Playwright/Cypress), API testing, pytest, Jest, k6 performance, and an autonomous QA agent loop.",
"version": "1.0.0",
"author": { "name": "QASkills.sh", "email": "[email protected]" }
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 7 lines scan A d5eb3e8ffc83
qa-essentials is a plugin published in the GitHub repository PramodDutta/qaskills (214 stars, last pushed 2d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
peekdev
Let your AI coding agent debug what already happened in your real browser. peek records masked rrweb sessions of your real browser to a local store and exposes them (DOM history, console/network errors, the action before an error, session-to-Playwright repro) to coding agents over MCP — and, with per-origin consent…
peek
peek — local-first browser-session forensics + repro for AI coding agents.
pw
Production-grade Playwright testing toolkit. Generate tests from specs, fix flaky failures, migrate from Cypress/Selenium, sync with TestRail, run on BrowserStack. 55+ ready-to-use templates, 3 specialized agents, smart reporting that plugs into your existing workflow.
sorify
Automated E2E test generation for Sorify — explore a URL, generate Playwright test code, upload to Sorify, and run tests. Supports three granularity levels: small (page load check), medium (component layout check), fine (all condition axes with network mocks).
vibe-browser
Drive your real, logged-in Chrome from Claude Code. Navigate, click, type, screenshot and read pages in the browser you already use - including a browser on a different machine, with no inbound port open.
e2e-dashboard
Install a real-time Playwright E2E test dashboard (live SSE progress, 14 features) into any project.