Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add GuitarAlchemist/ga --skill qa-architectgit clone --depth 1 https://github.com/GuitarAlchemist/gaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/guitaralchemist/ga/qa-architect)<a href="https://agentmods.dev/skills/guitaralchemist/ga/qa-architect"><img src="https://agentmods.dev/badge/skills/guitaralchemist/ga/qa-architect/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/guitaralchemist/ga/qa-architect"><img src="https://agentmods.dev/badge/skills/guitaralchemist/ga/qa-architect.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00045 | $0.01823 |
| Opus 5 | $0.00023 | $0.00911 |
| Sonnet 5 | $0.00009 | $0.00365 |
| Haiku 4.5 | $0.00005 | $0.00182 |
Grade A, and why
qa-architect scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 131 lines — stays where its author put it; the contents beside it link to each section on GitHub.
QA Architect Skill
This is the rubric for collaborating with Guitar Alchemist's senior QA agent. Read it before opening a PR, proposing a refactor, or shipping a metric-moving change. It is a checklist, not a narrative — follow it in order.
1. Who the QA Engineer Is
Two surfaces of the same role:
QAArchitectAgent—Common/GA.Business.ML/Agents/QAArchitectAgent.cs. Synchronous, in-process, callable from any C# code. Returns aQaVerdict.qa-architect-cycle.ixql—Demerzel/pipelines/qa-architect-cycle.ixql. Long-running, governance-grade, runs on PR open/sync and on a daily 06:00 UTC sweep. Persists verdicts tostate/quality/verdicts/.
They both speak the same protocol: the QaVerdict contract.
2. The Contract Is Not Optional
- Source of truth:
docs/contracts/2026-05-02-qa-verdict.contract.md(see alsoreferences/qa-verdict-contract.mdbundled with this skill). - JSON Schema:
docs/contracts/qa-verdict.schema.json. - Schema is draft v0.1.0, will freeze at v1.0.0 after a 2-sprint soak. Adding a new evidence kind, risk tier, or producer slug requires amending the contract markdown AND bumping the schema, not silently extending the JSON.
3. The 8 MCP Primitives
Available from the GaQaMcp MCP server. Treat them as your hands — call them rather than re-implementing.
| Tool | Call when… | Returns |
|---|---|---|
qa_assess_blast_radius |
Before designing a non-trivial change | blast_radius object: layers touched, one-way doors crossed, invariants at risk, score 0..1 |
qa_gap_analyze |
After writing code, before opening a PR | Array of followup candidates surfacing untested critical paths |
qa_propose_tests |
When adding new components or breaking out abstractions | Array of test stubs (path + body) grounded in repo patterns |
qa_verify_invariants |
Before merging changes that touch Core / Domain / Analysis / AI/ML | evidence{kind: contract_check} items, one per invariant |
qa_replay_adversarial |
Before merging changes to chord/voicing/embedding pipelines | evidence{kind: adversarial_replay} |
qa_score_quality_drift |
When changes may move a metric in state/quality/*.json |
evidence{kind: quality_snapshot} with delta + guardrail check |
qa_lookup_defect_memory |
Before designing — surfaces "we got burned by this before" | Array of past followups matching the touched components |
qa_emit_verdict |
At the end, to persist a verdict | Path of the persisted JSON + verdict_id |
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 131 lines · 45 tokens per session scan A eec2bf9125a4
qa-architect is a skill published in the GitHub repository GuitarAlchemist/ga (2 stars, last pushed today), licensed MIT. It adds 45 tokens to every session and 1,823 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
adversarial-reviewer
Adversarial code review that assumes bugs exist and hunts for them. Use when asked to review code, find bugs, audit for correctness, stress-test a PR, or when someone says "tear this apart" or "what's wrong with this". Give no benefit of the doubt — every line is guilty until proven innocent.
adk-go-self-review
Review an ADK Go change the way a maintainer will — a fresh-context pass over the whole diff, five lenses (correctness and tests, scope, simplicity, style, adk-python parity), and the mutation check that proves your tests pin the change. Use before opening a PR, before any later push that changes code, and when asked…
go-testing
Trigger: Go tests, go test coverage, Bubbletea teatest, golden files. Apply focused Go testing patterns.
semgrep-rule-variant-creator
Creates language variants of existing Semgrep rules. Use when porting a Semgrep rule to specified target languages. Takes an existing rule and target languages as input, produces independent rule+test directories for each language.
brooks-sweep
Full-sweep mode: runs a unified analysis across all quality dimensions — code decay, architecture, tech debt, and test quality — then applies fixes directly to the codebase. Safe changes are auto-applied; risky changes are confirmed before execution. Drawing on twelve classic engineering books. Triggers when: user…
include-test-files-that-assert-on-behavior-being-changed-in-decl
When delegating a task affected by this skill, include.