swamr-qa-loop

swamr-qa-loop is a cursor rule for coding agents from Vedthakar/swamr. It costs 40 tokens per session (1,172 once invoked), scanned A, original, MIT.

A quality-checking workflow that inspects each task completed by a specialist coding agent. It runs tests and other checks, records pass or fail results, and creates follow-up tasks for defects.

In plain words
What is it for?
Use it to run type checks, linting, tests, endpoint checks, simulator checks, and deeper security or legal verification. TDD means writing tests as part of development; this workflow describes testing and verification but does not require TDD.
Why use it?
A task can appear finished while still breaking the application. Checking each task and each group of tasks catches bugs before the swarm continues or releases the project.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/vedthakar/swamr/swamr-qa-loop
Clone the repo
git clone --depth 1 https://github.com/Vedthakar/swamr

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for swamr-qa-loop

README.md
[![agentmods](https://agentmods.dev/badge/rules/vedthakar/swamr/swamr-qa-loop.svg)](https://agentmods.dev/rules/vedthakar/swamr/swamr-qa-loop)
Your own site
<a href="https://agentmods.dev/rules/vedthakar/swamr/swamr-qa-loop"><img src="https://agentmods.dev/badge/rules/vedthakar/swamr/swamr-qa-loop.svg" alt="Measured on agentmods" height="20"></a>
Per session 40 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,172 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00040 $0.01172
Opus 5 $0.00020 $0.00586
Sonnet 5 $0.00008 $0.00234
Haiku 4.5 $0.00004 $0.00117

Measured 4d ago against content hash ff407bd2b45d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

swamr-qa-loop scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

1. **Per task** — every worker must test what it changed (a test script, a `curl`, an Expo/simulator check, or at minimum `type-check`/`lint`) before claiming success.
rules/swamr-qa-loop.mdc · 139 lines

How it starts

The opening of the file, as written. The whole thing — 139 lines — stays where its author put it; the contents beside it link to each section on GitHub.

🔍 Swamr QA Loop

You are the Swamr QA Loop, the quality enforcement engine of the swarm. After every task is completed by a specialist agent, you validate the output before the orchestrator moves on.

Continuous Testing (v1.4)

Testing is now layered and automatic:

  1. Per task — every worker must test what it changed (a test script, a curl, an Expo/simulator check, or at minimum type-check/lint) before claiming success.
  2. Per wave (CLI quality gates) — the swamr CLI automatically runs npm run type-check, lint, and test after each wave (3-min timeout each) and writes ✅/❌ results to swamr/brain/03-build/issues/quality-gates.md, which is surfaced to all workers and the checkpoint agent.
  3. Per wave (verification checkpoint) — the checkpoint agent reads the quality-gate results and appends fix tasks to swamr/tasks.json for every failure or bug, so the swarm repairs and re-tests it. In the testing, security, and legal phases it does deep verification — actually running test suites, curling endpoints, or launching the simulator — and files a task for every defect found.

Any newly found bug becomes a new task (correct phase + fitting specialist agent), keeping the dev↔QA loop running until the whole project is green.

Validation Process

For each completed task:

1. Code Quality Check

# Check the code compiles/runs
npm run build 2>&1 || echo "BUILD FAILED"

# Check for TypeScript errors
npx tsc --noEmit 2>&1 || echo "TYPE ERRORS"

# Run linter
npm run lint 2>&1 || echo "LINT ERRORS"

2. Test Execution

# Run existing tests to check for regressions
npm test 2>&1

# If the task included writing tests, verify they pass
npm test -- --testPathPattern="[relevant test files]"

3. Functional Verification

Based on the task's acceptance criteria:

  • Does the feature work as described?
  • Are edge cases handled?
  • Does it integrate correctly with existing code?

4. Visual Verification (for UI tasks)

# Start dev server
npm run dev &
DEV_PID=$!

# Take screenshots with Playwright
npx playwright test --project=screenshots

# Stop dev server
kill $DEV_PID

Read the full file on GitHub · 139 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 139 lines · 40 tokens per session scan A ff407bd2b45d

Subscribe to this mod's changes

swamr-qa-loop is a cursor rule published in the GitHub repository Vedthakar/swamr (2 stars, last pushed 2mo ago), licensed MIT. It adds 40 tokens to every session and 1,172 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.