Borrowing it
Nothing to install: this file belongs to florian101010/awesome-agentic-AI-coding-template. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/florian101010/awesome-agentic-AI-coding-template/main/.agent/skills/qa-audit/SKILL.mdgit clone --depth 1 https://github.com/florian101010/awesome-agentic-AI-coding-templateWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/florian101010/awesome-agentic-ai-coding-template/qa-audit)<a href="https://agentmods.dev/skills/florian101010/awesome-agentic-ai-coding-template/qa-audit"><img src="https://agentmods.dev/badge/skills/florian101010/awesome-agentic-ai-coding-template/qa-audit.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00067 | $0.01114 |
| Opus 5 | $0.00034 | $0.00557 |
| Sonnet 5 | $0.00013 | $0.00223 |
| Haiku 4.5 | $0.00007 | $0.00111 |
Grade A, and why
qa-audit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 114 lines — stays where its author put it; the contents beside it link to each section on GitHub.
QA-Audit
Systematic full-scope quality audit for
[FILL: main-source-file]and its config ecosystem.
Overview
This skill performs a comprehensive code quality audit covering security, robustness, rule compliance, and documentation drift. It produces a structured report with findings classified by severity.
Scope Options
Ask user for scope before starting:
| Scope | Coverage |
|---|---|
| Source-only | Main source file |
| Config-included | Source + all config files |
| Full Scope Paranoid | Source + Config + Agent Rules + Docs (recommended, default) |
Key requirements:
- Read ALL source lines — no skipping
- Check ALL rule files listed below
- Report findings with exact line numbers and the specific rule violated
- Save report as
docs/QA-AUDIT-{YYYY-MM-DD}.md - No fixes until user approves — audit is read-only first
When to Use
- Periodic audits — after major features or before releases
- Security review — when checking for XSS, injection, or unsafe data flows
- Post-refactor verification — when code changed significantly
- Rule compliance check — when verifying code follows all project conventions
- Documentation drift detection — when code values may have changed without updating docs
- Pre-release quality gate — as part of the release-readiness workflow
The 9-Phase Process
| Phase | Focus | Output |
|---|---|---|
| 0 | Baseline — Run npm test and config/asset verification |
Green baseline confirmed |
| 1 | Source Full Read — Every line of the main source file | Zone-by-zone understanding |
| 2 | Rule Compliance — Compare code against ALL rule files | Rule violation findings |
| 3 | Config Verification — Schema conformity, cross-references | Schema/data integrity findings |
| 4 | Security Scan — innerHTML/XSS, forbidden APIs | Security findings |
| 5 | Edge-Case & Robustness — Race conditions, error propagation, guards | Robustness findings |
| 6 | Documentation Drift — Code IST vs. documented SOLL values | Drift findings |
| 7 | Classification & Report — Severity assignment, structured audit document | QA-AUDIT-{date}.md |
| 8 | Fix Planning — Risk per finding, fix order, verification plan | Fix roadmap |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 114 lines · 67 tokens per session scan A bd48b7b31ea3
qa-audit is a skill published in the GitHub repository florian101010/awesome-agentic-AI-coding-template (4 stars, last pushed 6mo ago), licensed MIT. It adds 67 tokens to every session and 1,114 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
analyzing-linux-system-artifacts
Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
api-fuzzing-bug-bounty
Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.
api-security-testing
API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
analyzing-windows-prefetch-with-python
Parse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.
analyzing-linux-elf-malware
Analyzes malicious Linux ELF (Executable and Linkable Format) binaries including botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure. Covers static analysis, dynamic tracing, and reverse engineering of x8664 and ARM ELF samples. Activates for requests involving…
analyzing-heap-spray-exploitation
Detect and analyze heap spray attacks in memory dumps using Volatility3 plugins to identify NOP sled patterns, shellcode landing zones, and suspicious large allocations in process virtual address space.