Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/hundia/autospec/qa-reviewgit clone --depth 1 https://github.com/Hundia/autospecWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/rules/hundia/autospec/qa-review)<a href="https://agentmods.dev/rules/hundia/autospec/qa-review"><img src="https://agentmods.dev/badge/rules/hundia/autospec/qa-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00694 |
| Opus 5 | $0.00000 | $0.00347 |
| Sonnet 5 | $0.00000 | $0.00139 |
| Haiku 4.5 | $0.00000 | $0.00069 |
Grade A, and why
qa-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 93 lines — stays where its author put it; the contents beside it link to each section on GitHub.
QA Review Protocol
Verify completed work before marking tickets as ✅ Done.
Scale QA to Change Type
| Change Type | Verification Level |
|---|---|
| Docs/config only | Review accuracy — no build required |
| Bug fix | Reproduce → verify fix → run related tests |
| CLI change | npm run build + npm test in cli/ |
| Viewer change | npm run build in viewer/ + visual check |
| New feature | Full test suite + new test cases + integration check |
| Refactor | Full test suite — all existing tests must pass |
| Security fix | Full test suite + manual verification of the vulnerability |
Code Quality Checklist
- TypeScript strict mode — no
anytypes without justification - Zod schemas for all external input validation
- No hardcoded secrets, API keys, or credentials
- Error handling covers edge cases (null, undefined, empty arrays)
- No unused imports or dead code
- Follows repository → service → controller layering
- Component naming matches file naming conventions
Testing Checklist
- Existing tests still pass
- New tests written for new functionality
- Edge cases covered (empty input, large input, invalid input)
- Test descriptions are clear and descriptive
- No skipped tests without a tracking ticket
Functionality Checklist
- Feature matches the ticket description and acceptance criteria
- UI changes are visually correct (if applicable)
- No regressions in related features
- Error messages are user-friendly
- Loading and empty states handled
Security Checklist
- User input is validated before processing
- No SQL injection or XSS vectors
- API endpoints check authorization
- Sensitive data is not logged or exposed
- Dependencies are up to date (no known vulnerabilities)
Documentation Checklist
- Relevant
docs/files updated - Code comments explain non-obvious logic
- README or QUICKSTART updated if user-facing behavior changed
- API changes reflected in
specs/06-api-surface.md
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today First seen · 93 lines · 0 tokens per session scan A 903d9dca9362
qa-review is a cursor rule published in the GitHub repository Hundia/autospec (4 stars, last pushed 2mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 694 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other cursor rules, from other repositories
tdd
Final Verification: Always use: go test -v ./backend/api/handler/... | grep FAIL.
workflow
BDD-style workflow, UI screenshots in the PR, HTTP OpenAPI and config schema sync before lint, final checks.
agent-routing.pi-input-intercept
Codex 模型經 Pi machine dispatch 提出問題時的攔截、評估、代答或升級 protocol;觸及 spectra change / screenshot 情境時 path-scoped 載入.
mcpnuke-tests
Test conventions for mcpnuke — enforces TDD workflow.
testing-discipline
TDD, BDD, and testing best practices — stack-agnostic.
tdd
Test-driven development — red-green-refactor cycle.