Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/astordu/qoderharness/test3-test-matrix-buildernpx skills add astordu/qoderharness --skill test3-test-matrix-buildergit clone --depth 1 https://github.com/astordu/qoderharnessWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/astordu/qoderharness/test3-test-matrix-builder)<a href="https://agentmods.dev/skills/astordu/qoderharness/test3-test-matrix-builder"><img src="https://agentmods.dev/badge/skills/astordu/qoderharness/test3-test-matrix-builder.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00072 | $0.00442 |
| Opus 5 | $0.00036 | $0.00221 |
| Sonnet 5 | $0.00014 | $0.00088 |
| Haiku 4.5 | $0.00007 | $0.00044 |
Grade A, and why
test3-test-matrix-builder scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
测试矩阵 CSV 生成
生成该功能唯一的测试矩阵 CSV。这个 CSV 是全量测试地图和后续验证清单的基础。
输入
需要以下上下文:
- PRD 原文
- 需求意图表
- 验收条件表
如果缺少需求意图表,先调用 test1-prd-intent-extractor。如果缺少验收条件表,先调用 test2-acceptance-criteria-builder。
输出文件
只写一个 CSV:
.qoder/test-matrix/<feature-id>.csv
feature-id 优先使用 PRD 文件名去掉扩展名,例如:
.qoder/prd/blood-pressure-manual-entry.md
-> .qoder/test-matrix/blood-pressure-manual-entry.csv
如果 .qoder/test-matrix/ 不存在,创建它。
使用 /test-matrix-rules 读取测试矩阵规则表头说明.
规则
- 测试矩阵要全面,但不要把所有项都标记为本轮验证。
- 不要直接生成测试代码。
- 不要生成多个 CSV、JSON 或 Markdown 辅助文件。
- 范围外事项可以保留为
risk_type=范围控制、test_layer=Manual、priority=P0,用于提醒不要误测。 - 同一个 PRD 反复执行时,更新同一个 CSV,不创建副本。
下一步
完成后提示:
下一步建议调用 test4-validation-scope-selector:
基于测试矩阵 CSV,选择本轮最小可信验证集,并更新 selected_for_validation。
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 55 lines · 72 tokens per session scan A ffc8ba649491
test3-test-matrix-builder is a skill published in the GitHub repository astordu/qoderharness (21 stars, last pushed 9d ago), licensed MIT. It adds 72 tokens to every session and 442 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…