Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/agent-hellboy/mcp-runtime/qa-e2e-securitynpx skills add Agent-Hellboy/mcp-runtime --skill qa-e2e-securitygit clone --depth 1 https://github.com/Agent-Hellboy/mcp-runtimeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00116 | $0.04120 |
| Opus 5 | $0.00058 | $0.02060 |
| Sonnet 5 | $0.00023 | $0.00824 |
| Haiku 4.5 | $0.00012 | $0.00412 |
Grade A, and why
qa-e2e-security scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -sS -o /dev/null -w "anon=%{http_code}\n" \ How it starts
The opening of the file, as written. The whole thing — 329 lines — stays where its author put it; the contents beside it link to each section on GitHub.
QA — E2E Security (live cluster)
Overview
security-audit and security-audit-platform are static reviews — diff,
code paths, scanner output. This skill is the dynamic counterpart: it
fires real requests at the live cluster and confirms the security
invariants actually hold at runtime. It catches policy-materialization
regressions, header middleware regressions, and audit-event regressions that
static review and unit tests miss.
Threat profiles in scope:
- anonymous → user (no key, bad key, expired session)
- user → admin (UI key vs admin key vs ingest-only key)
- agent A → agent B (grant scoping by
humanID/agentID/serverRef) - low trust → high trust tool (consent gating)
- internal pod → secret (reach API/proxy/operator secrets unprivileged)
→ for cluster RBAC/PSS coverage, defer to
k8s-hardening-audit.
Regression evidence contract: for each touched security surface, capture at least one live allow path and one live deny path, plus audit/log/header evidence where that invariant applies. Static code review can explain a finding, but it cannot close this skill as passed.
Step 1 — Confirm precondition
kubectl config current-context | grep -qx kind-mcp-runtime \
|| { echo "Run qa-cluster-bringup first"; exit 1; }
./bin/mcp-runtime cluster doctor
Pull the three key types up front; never echo them into the report.
UI_KEY="$(kubectl get secret mcp-sentinel-secrets -n mcp-sentinel \
-o jsonpath='{.data.UI_API_KEY}' | base64 -d)"
test -n "$UI_KEY" || { echo "Failed to retrieve UI_KEY"; exit 1; }
INGEST_KEY="$(kubectl get secret mcp-sentinel-secrets -n mcp-sentinel \
-o jsonpath='{.data.INGEST_API_KEYS}' | base64 -d | cut -d, -f1)"
test -n "$INGEST_KEY" || { echo "Failed to retrieve INGEST_KEY"; exit 1; }
Step 2 — Choose mode
- head-only. Run the full backend + UI security matrix.
- git-range (
BASE=<merge-base>, defaultorigin/main). Trim by diff.
Sub-suites by changed paths:
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 329 lines · 116 tokens per session scan A a9e03fa8815e
qa-e2e-security is a skill published in the GitHub repository Agent-Hellboy/mcp-runtime (5 stars, last pushed 8d ago), licensed Apache-2.0. It adds 116 tokens to every session and 4,120 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
local-frontend-check
Smoke-test or verify UI behaviour on the local Jarvis Registry frontend running at http://localhost/gateway. Use for manual regression checks, bug-fix verification, and end-to-end confirmation of specific flows without running the automated test suite.
playwright-e2e-testing
Playwright modern end-to-end testing framework with cross-browser automation, auto-wait, and built-in test runner.
webmcp-e2e
WebMCP reverse connection gateway(pairing + static/remote モード)の E2E 結合確認を実行する。Manifold 起動 → デモページ → 拡張入り Chromium → ペアリング → tools/call 検証 → タブクローズ時エラー確認までを通し、スクリーンショット証跡を残す。remote モードでは自前 JWKS + JWT で identityKey ルーティングの分離も検証する。「webmcp の E2E」「reverse gateway の動作確認」「拡張の結合テスト」で使用。.
qa-use
E2E testing and browser automation with qa-use CLI. Use when the user needs to run tests, verify features, automate browser interactions, or debug test failures.
use-agent-browser-for-airi
Test AIRI display-model imports with agent-browser across stage-tamagotchi Electron, stage-web, and stage-pocket mobile web layouts. Use when uploading and verifying contributor-supplied Live2D ZIP, VRM, or MMD ZIP/PMX/PMD files through AIRI's model selector, including onboarding bypass, format-specific import…
test-conversion
Workflow for converting unit tests to browser tests for Project Bedrock. Invoke this when the user wants to remove complex Browser dependencies from tests.